
Threat Hunting Specialist
1 week ago
Job Description :
• Proactively hunt for advanced threats within the network and systems using various tools and techniques
• Use both Attack Based Hunting and Data Based Hunting to identify and analyze potential threats
• Stay up to date with the emerging threats and the tactics, techniques, and procedures (TTPs) used by threat actors
• Use various data transformation techniques to facilitate effective hunting
• Dissect and simulate attacks that would help in conceptualizing and executing the hunts
• Contribute to the hunting knowledge management i.e., document details about the hunting expeditions, common behaviors, explained anomalies, friendly intelligence, etc.
• Collaborate within/outside the team regarding the identified anomalies and develop and implement tactics for the detection and prevention of incidents
• Create and maintain custom threat-hunting queries, scripts, and dashboards
• Assist in converting successful hunting techniques into automated detection to the extent feasible
• Evaluate the hunting evidence sources and identify improvement areas when needed
• Perform host-based and network-based analysis to support investigations and incident response
• Document, report, and present critical information about the investigation/procedures performed
• Actively participate in the establishment of policies and procedures, training of personnel, and maintenance of analysis and hunting toolset
• Provide recommendations for improving security posture based on threat-hunting insights
• Contribute to and/or participate in Cyber Maturity Assessment activities like purple team exercises, table-top exercises, etc.
• Share knowledge and ideas with other team members
Minimum Criteria :
• Bachelor's Degree in Information Systems, Computer Science, or related field or equivalent or an equivalent number of years of experience
• 5+ years of experience in Threat Hunting
• The successful applicant must possess one or more current, applicable professional/technical certifications, such as Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified Security Compliance Specialist (CSCS), Certified Information Privacy Professional (CIPP), Certified Information Systems Security Professional (CISSP), Certified Internal Auditor (CIA), GPEN, GWAPT, SANS GCFA/GCFE/GSEC/GCIA/GCIH/GREM/GNFA, EnCE, CHFI, CEH, ECIH
• Knowledge of Cyber Security management practices, network, and application vulnerability assessments, change control, business continuity planning, data privacy, and risk assessment practices
• Proficiency with log aggregators/SIEM platforms and search query languages
• Proficiency with general analysis tools like awk, sed, PowerShell, grep, sort, uniq, Python, Excel
• Experience with network packets/traffic analysis using tools like Wireshark, tcpdump, Zeek, tshark, SiLK, etc.
• Proficiency with EnCase or any other forensic tool such as FTK, X-Ways, etc.
• Experience hunting threats using SIEM and other detection platforms
• Proficiency with Windows and *nix OS platforms
• Experience in Incident Investigation and reporting relevant facts
• Experience in memory analysis using tools like Volatility, Rekall, etc.
• Experience using platforms/distributions like SIFT, Remnux, FLARE, etc.
• Offensive security and scripting skills are a plus
• Knowledge of TCP/IP communications and how common protocols (SMTP, HTTP, POP3, IMAP, etc.) and applications work at the network
• Ability to demonstrate analytical expertise, close attention to detail, excellent critical thinking, logic, and solution orientation and to learn and adapt quickly
-
(3 Days Left) SOC L3
3 weeks ago
Hyderabad, India Locuz Full timeJob Description - Around 8-10 years working experience in Global SOC - Must have experience in any SIEM Management tool Splunk, QRADAR, HP Arc sight, - Triage Specialist - Separating the wheat from the chaff. - Vulnerability Management tools like Tenable, Rapid 7, Qualys, Nmap, Brupsuite etc.. - Experience in conducting VA/PT of Infrastructure and Web...
-
Bengaluru, Karnataka, India Triune Infomatics Inc Full time ₹ 20,00,000 - ₹ 25,00,000 per yearRole: Senior Cybersecurity SOC Engineer – Threat Hunting & Incident ResponseWorking Hours: Monday to Friday, 9 AM – 5 PM PST (U.S. Business Hours)Reporting To: Security Operations (SecOps) Leader – USAAbout the Role:We are seeking an elite Senior Cybersecurity SOC Engineer—a hands-on security expert with deep technical knowledge and proven experience...
-
Bengaluru, India Triune Infomatics Inc Full timeRole: Senior Cybersecurity SOC Engineer – Threat Hunting & Incident Response Working Hours: Monday to Friday, 9 AM – 5 PM PST (U. S. Business Hours)Reporting To: Security Operations (Sec Ops) Leader – USAAbout the Role: We are seeking an elite Senior Cybersecurity SOC Engineer—a hands-on security expert with deep technical knowledge and proven...
-
Bengaluru, India Triune Infomatics Inc Full timeRole: Senior Cybersecurity SOC Engineer – Threat Hunting & Incident Response Working Hours: Monday to Friday, 9 AM – 5 PM PST (U.S. Business Hours) Reporting To: Security Operations (SecOps) Leader – USA About the Role: We are seeking an elite Senior Cybersecurity SOC Engineer—a hands-on security expert with deep technical knowledge and proven...
-
Bengaluru, India Triune Infomatics Inc Full timeRole: Senior Cybersecurity SOC Engineer – Threat Hunting & Incident Response Working Hours: Monday to Friday, 9 AM – 5 PM PST (U.S. Business Hours) Reporting To: Security Operations (SecOps) Leader – USA About the Role: We are seeking an elite Senior Cybersecurity SOC Engineer—a hands-on security expert with deep technical knowledge and proven...
-
Bengaluru, India Triune Infomatics Inc Full timeRole: Senior Cybersecurity SOC Engineer – Threat Hunting & Incident Response Working Hours: Monday to Friday, 9 AM – 5 PM PST (U.S. Business Hours)Reporting To: Security Operations (SecOps) Leader – USAAbout the Role: We are seeking an elite Senior Cybersecurity SOC Engineer—a hands-on security expert with deep technical knowledge and proven...
-
Bengaluru, India Triune Infomatics Inc Full timeRole: Senior Cybersecurity SOC Engineer – Threat Hunting & Incident Response Working Hours: Monday to Friday, 9 AM – 5 PM PST (U.S. Business Hours)Reporting To: Security Operations (SecOps) Leader – USAAbout the Role: We are seeking an elite Senior Cybersecurity SOC Engineer—a hands-on security expert with deep technical knowledge and proven...
-
Bengaluru, India Triune Infomatics Inc Full timeRole: Senior Cybersecurity SOC Engineer – Threat Hunting & Incident Response Working Hours: Monday to Friday, 9 AM – 5 PM PST (U.S. Business Hours)Reporting To: Security Operations (SecOps) Leader – USAAbout the Role: We are seeking an elite Senior Cybersecurity SOC Engineer—a hands-on security expert with deep technical knowledge and proven...
-
Bengaluru, India Triune Infomatics Inc Full timeRole: Senior Cybersecurity SOC Engineer – Threat Hunting & Incident Response Working Hours: Monday to Friday, 9 AM – 5 PM PST (U.S. Business Hours) Reporting To: Security Operations (SecOps) Leader – USA About the Role: We are seeking an elite Senior Cybersecurity SOC Engineer—a hands-on security expert with deep technical knowledge and proven...
-
Threat hunter
3 weeks ago
Bengaluru, India Hinduja Global Solutions (HGS) Full timeJob Description As a Threat Hunter, you will be responsible for proactively identifying, analysing, and mitigating potential threats across our environments. You will lead threat hunts, leverage data from multiple sources, and apply advanced techniques to detect suspicious behaviour and uncover threats. Collaborating with cross-functional teams, youll refine...