L3 Threat Hunter – Proactive Breach Detection
Management Solutions International (MSI)
Doha, Doha Municipality, Qatar · 정규직
가장 먼저 지원하세요
- 경험
- 5년 이상
- 샐러리
- —
- 채용 공고
- 1
- 게시됨
- 9시간전
- 작업 모드
- 사무실에서
- 교육
- Bachelor's degree in Cybersecurity or related field preferred
- 재개하다
- 신청 시 필수 사항
당신이 일하게 될 곳
직무 설명
Role Overview
We seek an experienced L3 Threat Hunter to join a Cyber Defense team focused on proactively detecting advanced cyber threats. This role involves hypothesis-driven threat investigations, analysis of attacker behaviors, and enhancing detection systems within enterprise infrastructures.
Primary Responsibilities
- Proactively hunt for threats across endpoints, networks, cloud platforms, and SIEM systems to uncover hidden or emerging malicious activity.
- Lead complex investigations into advanced persistent threats, insider threats, malware behavior, lateral movements, and privilege escalations.
- Aggregate and correlate data from SIEM, EDR/XDR, IDS/IPS, firewalls, and threat intelligence sources.
- Create and automate workflows, detection scenarios, and response playbooks utilizing scripting and automation tools.
- Act as the main threat hunter during security events, supporting incident response.
- Conduct forensic analysis on endpoints, memory, logs, and network artifacts.
- Collaborate with SOC, Digital Forensics, Red Team, and Detection Engineering to boost detection effectiveness and minimize dwell time.
- Analyze attacker tactics, techniques, and procedures using frameworks like MITRE ATT&CK to craft actionable detections.
- Run threat simulations to test and validate detection logic against adversary techniques.
- Deliver detailed technical investigation reports along with executive summaries and remediation advice.
- Continuously advance hunting methods, detection content, and monitoring approaches.
Required Experience and Skills
- At least 5 years of hands-on cybersecurity experience specializing in threat hunting.
- Proven capability to lead independent threat hunting engagements.
- Experience as a primary threat hunter in incident response investigations.
- Familiarity with enterprise SOC operations and sophisticated cyber defense environments.
- Proficient with SIEM platforms like Splunk, Microsoft Sentinel, QRadar, ArcSight, or Elastic.
- Skilled with EDR/XDR technologies such as CrowdStrike, Microsoft Defender, Carbon Black, or SentinelOne.
- Knowledge of IDS/IPS systems and threat intelligence platforms.
- Expertise in digital forensics and log analysis.
- Strong understanding of threat hunting approaches, data correlation, anomaly detection, malware analysis basics, Windows/Linux attack vectors, network traffic analysis, and the MITRE ATT&CK framework.
- Experienced in scripting and automation with Python, PowerShell, Bash, or similar languages.
- Exposure to Red Team or Penetration Testing activities is highly valued.
Preferred Qualifications
- Bachelor’s degree in Cybersecurity, Computer Science, Information Security, or related discipline is preferred.
- Excellent analytical, investigative, and report-writing abilities.
- Ability to perform effectively under pressure in security operation centers.
Mandatory Certifications
- Certified eCTHP, eCIR, GMON, GCFA, OSCP, or TH-200 credentials are required.
Screening Evidence
- Submission of threat hunting case studies or examples of investigations conducted.
- Proof of SIEM and EDR deployment and utilization.
- Samples of automation or scripting supporting detection and hunting tasks.
- Incident investigation or digital forensic reports.
- Demonstrated ownership of threat hunting beyond typical SOC monitoring functions.