Threat Hunter (SKY-001-01)

Sabree Software Services, Inc.

• $110K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3-6 years of experience in cyber security roles such as analyst or incident responder.
  • Strong proficiency in hypothesis-based threat hunting (HMM-4) and the Mitre ATT&CK framework.
  • Hands-on experience with SIEM platforms, EDR solutions, and network traffic analysis tools.
  • Deep understanding of cloud environments like AWS and Azure.
  • Exceptional problem-solving and analytical skills, especially under pressure.
  • Relevant industry certifications (e.g., GCIH, CTIA, CThH) and knowledge of network protocols.

Responsibilities

  • Conduct proactive threat hunting using the HMM-4 approach and Mitre ATT&CK framework.
  • Develop and refine hypotheses for targeted threat hunts based on threat intelligence and internal data.
  • Collaborate with teams to collect and analyze security event data from various sources.
  • Utilize advanced tools to identify indicators of compromise (IOCs) and anomalies.
  • Perform in-depth analysis of identified threats and recommend mitigation strategies.
  • Document investigative objectives and progress, producing detailed reports on findings.
  • Stay updated on the latest cyber threats and security technologies through continuous learning.

Benefits

  • Opportunities for continuous learning and professional development.
  • Collaborative work environment with cross-functional teams.
  • Access to cutting-edge tools and technologies.
  • Engagement with the latest cyber security trends and techniques.
Full Job Description
Job Description

As a Cyber Threat Hunter, you will be responsible for proactively detecting, investigating, and mitigating cyber threats within our large enterprise environment. Your primary focus will be on hypothesis-based threat hunting utilizing the HMM-4 approach and leveraging the Mitre ATT&CK framework. You will collaborate closely with cross-functional teams, including endpoint, network, offensive, threat intelligence, cloud, and data science experts, to identify, analyze, and respond to emerging threats. Key responsibilities include:

  • Conduct proactive threat hunting using the HMM-4 approach and Mitre ATT&CK framework.
  • Develop and refine hypotheses for targeted threat hunts based on threat intelligence, internal data, and analysis of attacker tactics, techniques, and procedures (TTPs).
  • Collaborate with internal teams to collect and analyze security event data from various sources, such as logs, alerts, network traffic, and endpoint telemetry.
  • Utilize cutting-edge tools and technologies to identify indicators of compromise (IOCs) and anomalies that may indicate potential threats.
  • Perform in-depth analysis of identified threats, assess their impact, and recommend appropriate mitigation and response strategies.
  • Document investigative objectives and progress throughout threat hunt. Produce detailed reports and provide clear and concise communication on findings, to include root cause analysis and recommendations for remediation and risk mitigation. Propose enhanced detections where possible defensive gaps are identified.
  • Stay up to date with the latest cyber threats, attack techniques, and security technologies through continuous learning and knowledge sharing.


Required Skills

  • Minimum of 3 years of experience as a cyber security analyst, incident responder, or other closely related cyber security discipline. 4-6 years of experience desired.
  • Professional Experience: Minimum of 3 years of experience as a cyber security analyst, incident responder, or other closely related cyber security discipline. 4-6 years of experience desired
  • Methodological Expertise: Strong proficiency in hypothesis-based hunting (HMM-4), the Mitre ATT&CK matrix, and mapping adversary TTPs to observed activities.
  • Technical Toolset: Hands-on proficiency with SIEM platforms, EDR solutions, network traffic analysis tools, and a deep understanding of cloud environments (AWS, Azure, etc.).
  • Analytical & Communication Skills: Exceptional problem-solving skills in high-pressure situations, with the ability to translate complex technical findings for both technical and non-technical audiences.
  • Education & Certification: Relevant industry certifications (e.g., GCIH, CTIA, or CThH) and a solid foundation in network protocols and endpoint security.

Similar Jobs

More Jobs at Sabree Software Services, Inc.

More Information Technology Jobs

Find similar Threat Hunter (SKY-001-01) jobs: