Senior Cybersecurity Threat Hunter
Posted 4ds ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Senior Cybersecurity Threat Hunter leading proactive threat detection at Uni Systems. Managing hunting campaigns, telemetry analysis, detection engineering, incident response support, and threat-informed security improvements.
Responsibilities:
- Lead and manage the threat hunting program, including campaign planning, prioritization, execution, and reporting.
- Conduct threat research, develop hunting hypotheses, and identify detection gaps to improve security monitoring.
- Analyze security telemetry from SIEM, EDR, data lakes, and other sources to identify advanced threats.
- Develop and enhance threat detection use cases, detection models, and engineering frameworks (e.g., OpenTIDE).
- Design, automate, and maintain threat hunting workflows, playbooks, integrations, and IoC retro-hunting capabilities.
- Support incident response investigations, purple team exercises, and validation of new detection capabilities.
- Collaborate with Incident Response, Threat Detection, Threat Intelligence, Malware Analysis, Red/Purple Teams, and external partners (e.g., CERT-EU).
- Prepare executive briefings, campaign reports, and investigation summaries for senior management.
- Mentor and train junior threat hunters while promoting threat-informed detection practices.
- Continuously improve detection coverage by incorporating lessons learned from incidents, red teaming, and threat intelligence.
Requirements:
- Master's Degree in Computer Science, with a focus on Cybersecurity.
- Minimum 2 years of experience leading Threat Hunting activities in a SOC/CSOC or equivalent environment.
- Proven experience in operationalising threat intelligence to support proactive hunting and detection engineering.
- Proven experience in developing and improving detection coverage to convert intelligence-driven priorities into timely and relevant detection use cases aligned with CSOC operational needs.
- Hands-on experience with OpenTIDE or an equivalent detection content management platform.
- Strong practical experience with SIEM platforms, particularly Splunk Enterprise Security and Risk-Based Alerting, or equivalent technologies, for detection engineering, alerting, and use case development.
- Strong practical experience with EDR solutions.
- Ability to produce clear, structured, and actionable reporting, including threat assessments and strategic or operational reports, for technical and non-technical audiences.
- Strong coordination skills with internal teams, business representatives, and external partners.












