Government Careers
  • Senior Threat Hunter / Detection Engineer (34)

  • VeriiPro
  • all cities, Nevada 34 United States View Map

Summary

Roles & ResponsibilitiesConduct hypothesis-driven threat hunts across endpoints, identities, networks, and security data sources.Leverage Microsoft Defender for Endpoint (MDE) and Microsoft 365 Defender (XDR) for threat investigation, hunting, and automated response.Develop advanced Kusto Query Language (KQL) queries for threat hunting and detection.Use Splunk Enterprise Security and SPL to perform complex security investigations, correlation, and threat hunting.Develop and tune high-fidelity detection rules while minimizing false positives.Apply the MITRE ATT&CK framework to threat hunting, detection engineering, and adversary analysis.Translate threat intelligence and attack research into actionable detection and hunting use cases.Investigate security incidents using endpoint forensics, malware analysis, and security analytics.Support containment, eradication, and recovery activities for complex incidents.Develop and maintain incident response playbooks, procedures, and technical documentation.Preserve forensic evidence and follow appropriate evidence-handling and chain-of-custody practices.Analyze Windows systems, processes, authentication activity, network traffic, and common attack vectors.Develop scripts and automation using PowerShell, Python, or similar technologies.Collaborate with incident response, detection engineering, IT operations, and other security teams.Provide technical training, mentoring, and knowledge transfer to security teams.Develop training materials and explain complex security concepts to audiences with varying technical skill levels.Identify opportunities to improve security tools, processes, detections, and threat-hunting capabilities.Support security tool implementations, migrations, and optimization initiatives.Required Skills5–7+ years of cybersecurity experience with a focus on threat hunting, detection engineering, and/or incident response.At least 2 years of hands-on enterprise experience with Microsoft Defender for Endpoint (MDE).Strong experience with Microsoft 365 Defender/XDR and MDE investigation capabilities.Advanced KQL skills for threat hunting and detection development.Expert-level experience with Splunk Enterprise Security and strong SPL skills.Experience with Splunk UBA or similar behavioral analytics platforms.Strong knowledge of MITRE ATT&CK, adversary TTPs, and threat intelligence.Demonstrated experience conducting threat hunts that resulted in actionable security improvements.Hands-on experience with incident response, endpoint forensics, and malware analysis.Strong understanding of Windows internals, Active Directory, Azure AD, Kerberos, and NTLM.Knowledge of network protocols, traffic analysis, and common attack techniques.Experience with scripting or automation using PowerShell, Python, or similar languages.Strong analytical, problem-solving, documentation, and communication skills.Ability to work independently and collaborate effectively with distributed, cross-functional teams.Preferred SkillsExperience supporting or leading security tool migrations or implementations.Experience with Splunk UBA, SIEM architecture, data onboarding, and platform optimization.Knowledge of NIST and SANS incident response frameworks.Experience developing incident response playbooks and security procedures.Experience with detection engineering and reducing false positives.Strong technical training, mentoring, and knowledge-transfer experience.Ability to translate threat research into practical defensive controls and security improvements.Experience working in a fully remote and distributed team environment.

Job Description

Roles & ResponsibilitiesConduct hypothesis-driven threat hunts across endpoints, identities, networks, and security data sources.Leverage Microsoft Defender for Endpoint (MDE) and Microsoft 365 Defender (XDR) for threat investigation, hunting, and automated response.Develop advanced Kusto Query Language (KQL) queries for threat hunting and detection.Use Splunk Enterprise Security and SPL to perform complex security investigations, correlation, and threat hunting.Develop and tune high-fidelity detection rules while minimizing false positives.Apply the MITRE ATT&CK framework to threat hunting, detection engineering, and adversary analysis.Translate threat intelligence and attack research into actionable detection and hunting use cases.Investigate security incidents using endpoint forensics, malware analysis, and security analytics.Support containment, eradication, and recovery activities for complex incidents.Develop and maintain incident response playbooks, procedures, and technical documentation.Preserve forensic evidence and follow appropriate evidence-handling and chain-of-custody practices.Analyze Windows systems, processes, authentication activity, network traffic, and common attack vectors.Develop scripts and automation using PowerShell, Python, or similar technologies.Collaborate with incident response, detection engineering, IT operations, and other security teams.Provide technical training, mentoring, and knowledge transfer to security teams.Develop training materials and explain complex security concepts to audiences with varying technical skill levels.Identify opportunities to improve security tools, processes, detections, and threat-hunting capabilities.Support security tool implementations, migrations, and optimization initiatives.Required Skills5–7+ years of cybersecurity experience with a focus on threat hunting, detection engineering, and/or incident response.At least 2 years of hands-on enterprise experience with Microsoft Defender for Endpoint (MDE).Strong experience with Microsoft 365 Defender/XDR and MDE investigation capabilities.Advanced KQL skills for threat hunting and detection development.Expert-level experience with Splunk Enterprise Security and strong SPL skills.Experience with Splunk UBA or similar behavioral analytics platforms.Strong knowledge of MITRE ATT&CK, adversary TTPs, and threat intelligence.Demonstrated experience conducting threat hunts that resulted in actionable security improvements.Hands-on experience with incident response, endpoint forensics, and malware analysis.Strong understanding of Windows internals, Active Directory, Azure AD, Kerberos, and NTLM.Knowledge of network protocols, traffic analysis, and common attack techniques.Experience with scripting or automation using PowerShell, Python, or similar languages.Strong analytical, problem-solving, documentation, and communication skills.Ability to work independently and collaborate effectively with distributed, cross-functional teams.Preferred SkillsExperience supporting or leading security tool migrations or implementations.Experience with Splunk UBA, SIEM architecture, data onboarding, and platform optimization.Knowledge of NIST and SANS incident response frameworks.Experience developing incident response playbooks and security procedures.Experience with detection engineering and reducing false positives.Strong technical training, mentoring, and knowledge-transfer experience.Ability to translate threat research into practical defensive controls and security improvements.Experience working in a fully remote and distributed team environment.

Government Careers

Government Careers

Government jobs offer stability, competitive benefits, and the chance to make a meaningful impact on your community and country.

Whether you’re starting your career or seeking new opportunities, these roles provide pathways for growth, security, and service.

Explore positions across a wide range of fields and take the first step toward a rewarding future in public service.

Show more

MORE JOBS