Tata Consultancy Services

Threat Hunting Consultant

Tata Consultancy Services$110K — $150K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years in cybersecurity focusing on detection, threat hunting, and incident response
  • 2 years hands-on experience with Microsoft Defender for Endpoint in an enterprise environment
  • Proven experience with threat hunts leading to actionable security outcomes
  • Experience in supporting or leading security tool migrations or implementations is a plus
  • Certifications preferred: GIAC Cyber Threat Intelligence, GIAC Certified Incident Handler, Certified Threat Intelligence Analyst, etc.

Responsibilities

  • Conduct hypothesis-driven threat hunts to identify vulnerabilities
  • Develop and implement high-fidelity detection rules to minimize false positives
  • Lead incident response efforts, including malware analysis and forensics
  • Create and maintain incident response playbooks based on established frameworks
  • Translate threat intelligence into actionable security measures

Benefits

  • Remote work flexibility
  • Opportunities for continuous learning and development
  • Access to resources for career advancement
  • Collaborative team environment across multiple functions
  • Exposure to industry-leading security technologies
Full Job Description
Microsoft Security Stack Expertise
• Extensive hands-on experience with Microsoft Defender for Endpoint (MDE)
• Proficiency with Microsoft 365 Defender (XDR) unified security operations
• Advanced knowledge of Kusto Query Language (KQL) for threat hunting and detection
• Deep understanding of MDE investigation capabilities, automated response features, and integration architecture

SIEM and Analytics
• Expert-level Splunk Enterprise Security experience
• Proficiency in Splunk Processing Language (SPL) for complex correlation and hunting queries
• Experience with Splunk User Behavior Analytics (UBA) or similar behavioral detection platforms
• Knowledge of SIEM architecture, data onboarding, and optimization techniques

Threat Hunting and Detection Engineering
• Demonstrated experience conducting hypothesis-driven threat hunts
• Strong understanding of MITRE ATT&CK framework and its practical application
• Ability to translate threat intelligence and attack research into actionable hunting queries
• Experience developing high-fidelity detection rules with low false positive rates
• Knowledge of adversary tactics, techniques, and procedures (TTPs) across multiple threat actor groups

Incident Response
• Proven track record in hands-on incident response and investigation
• Expertise in endpoint forensics and malware analysis
• Familiarity with incident response frameworks (NIST, SANS) and playbook development
• Experience with containment, eradication, and recovery procedures for complex security incidents
• Understanding of forensic evidence preservation and chain of custody requirements

Technical Foundations
• Deep understanding of Windows internals, process behaviors, and security architecture
• Knowledge of network protocols, traffic analysis, and common attack vectors
• Familiarity with authentication protocols (Active Directory, Azure AD, Kerberos, NTLM)
• Understanding of scripting and automation (PowerShell, Python, or similar)

Knowledge Transfer and Teaching Ability
• Proven ability to explain complex technical concepts to varied technical audiences
• Experience developing and delivering technical training or mentorship programs
• Patience and commitment to building team capability, not just completing tasks
• Ability to adapt teaching style to different learning preferences and skill levels

Communication and Collabo ration
• Excellent written communication skills for documentation and reporting
• Strong verbal communication skills for training delivery and incident collaboration
• Ability to work effectively with cross-functional teams (IR, detection engineering, IT operations)
• Comfort operating in a fully remote environment with distributed team members

Problem Solving and Initiative
• Self-directed work style with ability to identify priorities independently
• Creative problem-solving approach to novel security challenges
• Intellectual curiosity and continuous learning mindset
• Ability to translate theoretical threat research into practical defensive measures

• Minimum 5-7 years of experience in cybersecurity with focus on detection, threat hunting, and/or incident response
• At least 2 years of hands-on experience with Microsoft Defender for Endpoint in an enterprise environment
• Demonstrated experience conducting threat hunts that led to actionable security improvements
• Previous experience supporting or leading security tool migrations or implementations (highly valued)
• Certifications (Preferred)

Highly Valued:
• GIAC Cyber Threat Intelligence (GCTI)
• GIAC Certified Incident Handler (GCIH)
• GIAC Certified Forensic Analyst (GCFA)
• Certified Threat Intelligence Analyst (CTIA)
• Relevant:
• Microsoft Certified: Security Operations Analyst Associate (SC-200)
• Splunk Enterprise Security Certified Admin
• CISSP, CISM, or equivalent security management certification
• Offensive Security certifications (OSCP, OSCE) demonstrating adversarial perspective

Knowledge Transfer and Teaching Ability
• Proven ability to explain complex technical concepts to varied technical audiences
• Experience developing and delivering technical training or mentorship programs
• Patience and commitment to building team capability, not just completing tasks
• Ability to adapt teaching style to different learning preferences and skill levels

Communication and Collaboration
• Excellent written communication skills for documentation and reporting
• Strong verbal communication skills for training delivery and incident collaboration
• A bility to work effectively with cross-functional teams (IR, detection engineering, IT operations)
• Comfort operating in a fully remote environment with distributed team members

Problem Solving and Initiative
• Self-directed work style with ability to identify priorities independently
• Creative problem-solving approach to novel security challenges
• Intellectual curiosity and continuous learning mindset
• Ability to translate theoretical threat research into practical defensive measures

Location: Remote

Salary Range: $110,000 - $150,000 a year

#LI-CM2

About Tata Consultancy Services

Tata Consultancy Services (TCS) is an Indian multinational information technology (IT) services and consulting company, headquartered in Mumbai, Maharashtra, India. It is a subsidiary of Tata Group and operates in 149 locations across 46 countries. TCS is the largest Indian company by market capitalization and is ranked 11th on the Forbes Global 2000 list of the world's biggest public companies. TCS is also the second-largest IT services company in the world by revenue and the largest employer of women in India. The company provides services in areas including IT, consulting, and business solutions.
Learn more about Tata Consultancy Services
Size
469,261 employees
Industry

Similar Jobs

More Jobs at Tata Consultancy Services

  • Tata Consultancy Services
    SAP BTP Solution Architect
    $224K — $303K *
    San Francisco, CA 94112 (San Francisco County)
    Enterprise Technology
    In-Person
  • Tata Consultancy Services
    SAP Vertex Consultant - Senior SME
    $150K — $160K *
    Charlotte, NC 28269 (Mecklenburg County)
    Enterprise Technology
    In-Person
  • Tata Consultancy Services
    Delivery Manager
    $90K — $120K *
    Toronto, ON M3C 0E3
    Finance & Insurance
    In-Person
  • Tata Consultancy Services
    DR Coordinator
    $100K — $110K *
    Newark, NJ 07104 (Essex County)
    Information Technology
    In-Person
  • Tata Consultancy Services
    Sailpoint SME
    $110K — $150K *
    Iselin, NJ 08830 (Middlesex County)
    Information Technology
    In-Person

More Information Technology Jobs

Find similar Threat Hunting Consultant jobs: