Position Overview:
Arctiq is seeking a Threat Hunter to join our advanced security team within a fast-paced MSSP environment. You will proactively identify cyber threats across a variety of client environments by combining threat intelligence, behavioral analytics, and expert intuition. This role requires a deep understanding of attacker techniques, endpoint/network telemetry, and experience working across diverse technology stacks. You will play a critical role in enhancing threat detection capabilities and advising clients on how to improve their security posture.
Core Responsibilities:
- Perform proactive threat hunting across multi-tenant client environments using SIEM, EDR, NDR, and other telemetry sources.
- Drive proactive threat hunting by modeling attacker behavior and testing hypotheses against client data using threat intel and contextual baselines.
- Analyze indicators of compromise (IOCs) and behavior patterns to uncover stealthy threats.
- Investigate anomalies surfaced through tools or analyst escalations and provide deep-dive analysis.
- Create and tune detection content (SIEM rules, correlation logic, signatures) to improve threat visibility.
- Document hunt processes, findings, and incident recommendations for internal stakeholders and clients.
- Assist in incident response efforts including containment, eradication, and recovery.
- Recommend security control improvements based on observed threats and hunting outcomes.
- Partner across internal security teams to enhance detection strategies and drive continuous improvement of the MSSP threat detection framework.
- Engage with clients during onboarding, security reviews, or post-incident briefings.
- Maintain and enhance security solutions such as firewalls, IDS/IPS, DLP, vulnerability scanners, PAM, and endpoint protection tools for clients.
- Monitor the evolving threat landscape and incorporate the latest intelligence into proactive threat hunting efforts.
Qualifications:
- Bachelor's degree/Diploma in Computer Science, Cybersecurity, Information Systems, or a related field or equivalent practical experience.
- 3+ years of hands-on experience in threat hunting, incident response, SOC analysis, or threat intelligence.
- Solid understanding of Windows and Linux operating systems and authentication protocols.
- Familiarity with cloud security platforms (AWS, Azure, GCP).
- Strong grasp of security frameworks (MITRE ATT&CK, NIST, etc.).
- Proficiency with EDR and SIEM tools (e.g., CrowdStrike, SentinelOne, Splunk, QRadar).
- Knowledge of networking fundamentals (protocols, firewalls, routing, etc.)
- Experience with malware analysis, packet capture analysis, and host/network forensics.
- Skilled in scripting or automation (Python, PowerShell, etc.) for hunt support and data enrichment.
- Customer-focused mindset with the ability to communicate effectively and confidently with technical and non-technical stakeholders.
- Strong analytical, troubleshooting, and problem-solving skills.
- High attention to detail, discretion, and integrity in handling sensitive client data.
- Ability to manage multiple incidents and prioritize tasks under pressure.
- Self-starter with a passion for continuous learning and cybersecurity excellence.
- Hands-on incident response or SOC experience in a service provider environment.
- Relevant certifications such as GCIH, GCFA, GCIA, Security+, CEH, or CISSP.
Benefits:
- Competitive salary and performance-based incentives
- Outstanding health, dental, and vision insurance plans
- Retirement savings plan with employer matching
- Flexible work schedule and remote work options
- Professional development and training opportunities
- Collaborative and inclusive work culture with opportunities for career growth