What you'll be doing: The Verizon Cybersecurity organization securely enables the enterprise by protecting assets, data, and critical infrastructure across Verizon networks and global operational environments. Verizon Cybersecurity integrates advanced threat intelligence, governance, cutting-edge security technologies, and proactive threat hunting operations to embed resilience into all technology systems and services.
As a Distinguished Threat Hunter and operational lead, you will play a pivotal role in defending Verizon against advanced, persistent, and emerging cyber threats. In this high-impact role, you will architect and execute sophisticated threat hunting strategies, identify anomalous behavior, and leverage deep data analytics to strengthen defense controls. Beyond hands-on technical hunting, you will serve as a technical lead - mentoring and directing both senior threat hunters, junior staff, advising leadership, establishing operational methodologies and briefing executive leadership on threat landscapes and high-priority investigations.
The ideal candidate is a collaborative leader with a strong track record of cross-functional engagement and a commitment to driving team success.
Key Responsibilities:
- Lead and execute complex, high-priority hunt missions using threat intelligence, multi-source telemetry, and adversary behavior analysis to surface unknown threats, insider risks, and advanced persistent threats (APTs).
- Analyze threat actor Tactics, Techniques, and Procedures (TTPs) aligned to the MITRE ATT&CK framework, translating findings into proactive defense strategies and novel detection logic.
- Provide expert technical direction and investigative leadership during major cyber security incidents and high-risk investigations.
- Direct the mentorship and professional development of team members, offering technical guidance to both junior analysts and experienced threat hunters.
- Synthesize investigative findings and threat telemetry into high-level strategic summaries and operational metrics for executive leadership and key stakeholders.
- Continuously mature hunting methodologies, detection capabilities, and automated workflows across SIEM, EDR, and data lake platforms.
- Partner closely with Threat Intelligence, Incident Response, SOC, and Security Engineering teams to bridge gaps between threat detection, response, and remediation.
- Develop custom detection rules across multiple technologies (including YARA, SIGMA, KQL, and AQL) and network/host-based Indicators of Compromise (IOCs) and Indicators of Attack (IOAs).
- Maintain operational readiness to respond to urgent security events or critical incidents off-hours, as business needs dictate.
What we're looking for:
You’ll need to have:
- Bachelor’s degree or eight or more years of relevant work experience required, demonstrated through one or a combination of job-related work experience, military experience, or specialized training or education (non-collegiate).
- Six or more years of specialized experience in threat hunting, incident response, or advanced threat analytics.
- Experience investigating network protocol anomalies and analyzing telemetry from network edge appliances (e.g., firewalls, VPNs, routers, and proxies).
- Proven experience mentoring, leading, or directing technical security staff and managing hunt engagements.
- Advanced proficiency with SIEM tools (e.g., Splunk), query languages (KQL, AQL), Regular Expressions, and scripting/automation (Python, PowerShell, Bash, or Go).
Even better if you have one or more of the following:
- Demonstrated success leading operations within a high-tempo Security Operations environment (SOC, IR, Threat Intel, Malware Analysis, or Threat Hunting).
- Experience supporting cyber defense in telecommunications, critical infrastructure, or large enterprise networks.
- Deep technical knowledge of operating system internals, forensics, and data structures across Windows, Linux/Unix, and macOS platforms.
- Deep technical knowledge of network architecture, packet analysis, and adversary tactics targeting network infrastructure.
- Exceptional executive presentation and communication skills, with the ability to convey complex threat dynamics to non-technical executive leadership.
- Advanced industry certifications (e.g., CISSP, GCIH, GCFA, GCFE, GREM, OSCP, or equivalent).
If this role sounds like a fit for you, we encourage you to apply even if you don’t meet every “even better” qualification listed above.
In this remote role, you'll work from home with occasional in-person trainings and meetings.
Scheduled Weekly Hours40