Search by job, company or skills

Cyber Threat Hunter & Incident Response Specialist

3-5 Years
Early Applicant
  • Posted 11 days ago
  • Be among the first 10 applicants

Job Description

We are looking for a hands-on Cyber Threat Hunter with strong incident response experience to join a growing security operations function. This role sits at the intersection of proactive threat detection and reactive incident handling - you'll be hunting for adversaries that evade automated defences, and leading the charge when something is actually found.

What You'll Do

  • Conduct proactive, hypothesis-driven threat hunts across endpoints, network traffic, and cloud environments to uncover adversary activity that bypasses existing detection controls
  • Develop and refine hunting hypotheses based on threat intelligence, MITRE ATT&CK mappings, and emerging attacker tradecraft
  • Lead end-to-end incident response for confirmed security events - triage, containment, eradication, and recovery
  • Perform root cause analysis and produce clear, actionable post-incident reports for technical and non-technical stakeholders
  • Build and tune detection use cases, correlation rules, and hunting queries to close visibility gaps identified during hunts and investigations
  • Analyse malware, forensic artefacts, and attacker techniques to understand scope, impact, and persistence mechanisms
  • Collaborate with SOC analysts, threat intelligence, and engineering teams to strengthen detection coverage and reduce dwell time
  • Maintain and evolve playbooks, runbooks, and standard operating procedures for both hunting and incident response
  • Contribute to purple team exercises, validating detection efficacy against simulated adversary behaviour
  • Stay current on emerging threat actor groups, TTPs, and tooling relevant to the organisation's risk profile

What You'll Bring

  • Proven experience in threat hunting, digital forensics, and incident response (DFIR)
  • Strong working knowledge of the MITRE ATT&CK framework and adversary emulation concepts
  • Hands-on experience with EDR, SIEM, and network detection and response tooling
  • Familiarity with scripting or query languages (e.g. Python, KQL, or similar) for hunt automation and log analysis
  • Solid understanding of Windows, Linux, and cloud environments from a security operations perspective
  • Experience handling live incidents under pressure, with clear and calm stakeholder communication
  • A curious, adversarial mindset - comfortable thinking like an attacker to find what defences miss

More Info

Job Type:
Industry:
Function:
Employment Type:

Job ID: 151318635