This role focuses on advanced threat hunting and detection engineering within the Microsoft Security Stack and Splunk. Responsibilities include conducting hypothesis-driven hunts, developing high-fidelity detection rules, and performing incident response. Key requirements include extensive experience with Microsoft Defender for Endpoint, Splunk Enterprise Security, and KQL/SPL, alongside a strong understanding of threat intelligence and adversary TTPs.
Key Highlights
Key Responsibilities
Technical Skills Required
Nice to Have
Job Description
Job Description
Microsoft Security Stack Expertise
• Extensive hands-on experience with Microsoft Defender for Endpoint (MDE)
• Proficiency with Microsoft 365 Defender (XDR) unified security operations
• Advanced knowledge of Kusto Query Language (KQL) for threat hunting and detection
• Deep understanding of MDE investigation capabilities, automated response features, and integration architecture
SIEM and Analytics
• Expert-level Splunk Enterprise Security experience
• Proficiency in Splunk Processing Language (SPL) for complex correlation and hunting queries
• Experience with Splunk User Behavior Analytics (UBA) or similar behavioral detection platforms
• Knowledge of SIEM architecture, data onboarding, and optimization techniques
Threat Hunting and Detection Engineering
• Demonstrated experience conducting hypothesis-driven threat hunts
• Strong understanding of MITRE ATT&CK framework and its practical application
• Ability to translate threat intelligence and attack research into actionable hunting queries
• Experience developing high-fidelity detection rules with low false positive rates
• Knowledge of adversary tactics, techniques, and procedures (TTPs) across multiple threat actor groups
Incident Response
• Proven track record in hands-on incident response and investigation
• Expertise in endpoint forensics and malware analysis
• Familiarity with incident response frameworks (NIST, SANS) and playbook development
• Experience with containment, eradication, and recovery procedures for complex security incidents
• Understanding of forensic evidence preservation and chain of custody requirements
Technical Foundations
• Deep understanding of Windows internals, process behaviors, and security architecture
• Knowledge of network protocols, traffic analysis, and common attack vectors
Interested in remote work opportunities in IT & Network Engineering? Discover IT & Network Engineering Remote Jobs featuring exclusive positions from top companies that offer flexible work arrangements.
• Familiarity with authentication protocols (Active Directory, Azure AD, Kerberos, NTLM)
• Understanding of scripting and automation (PowerShell, Python, or similar)
Knowledge Transfer and Teaching Ability
• Proven ability to explain complex technical concepts to varied technical audiences
• Experience developing and delivering technical training or mentorship programs
• Patience and commitment to building team capability, not just completing tasks
• Ability to adapt teaching style to different learning preferences and skill levels
Communication and Collabo ration
• Excellent written communication skills for documentation and reporting
• Strong verbal communication skills for training delivery and incident collaboration
• Ability to work effectively with cross-functional teams (IR, detection engineering, IT operations)
• Comfort operating in a fully remote environment with distributed team members
Problem Solving and Initiative
• Self-directed work style with ability to identify priorities independently
• Creative problem-solving approach to novel security challenges
• Intellectual curiosity and continuous learning mindset
• Ability to translate theoretical threat research into practical defensive measures
•
• Minimum 5-7 years of experience in cybersecurity with focus on detection, threat hunting, and/or incident response
• At least 2 years of hands-on experience with Microsoft Defender for Endpoint in an enterprise environment
• Demonstrated experience conducting threat hunts that led to actionable security improvements
• Previous experience supporting or leading security tool migrations or implementations (highly valued)
• Certifications (Preferred)
Highly Valued:
Browse our curated collection of remote jobs across all categories and industries, featuring positions from top companies worldwide.
• GIAC Cyber Threat Intelligence (GCTI)
• GIAC Certified Incident Handler (GCIH)
• GIAC Certified Forensic Analyst (GCFA)
• Certified Threat Intelligence Analyst (CTIA)
• Relevant:
• Microsoft Certified: Security Operations Analyst Associate (SC-200)
• Splunk Enterprise Security Certified Admin
• CISSP, CISM, or equivalent security management certification
• Offensive Security certifications (OSCP, OSCE) demonstrating adversarial perspective
Knowledge Transfer and Teaching Ability
• Proven ability to explain complex technical concepts to varied technical audiences
• Experience developing and delivering technical training or mentorship programs
• Patience and commitment to building team capability, not just completing tasks
• Ability to adapt teaching style to different learning preferences and skill levels
Communication and Collaboration
• Excellent written communication skills for documentation and reporting
• Strong verbal communication skills for training delivery and incident collaboration
• A bility to work effectively with cross-functional teams (IR, detection engineering, IT operations)
• Comfort operating in a fully remote environment with distributed team members
Problem Solving and Initiative
• Self-directed work style with ability to identify priorities independently
• Creative problem-solving approach to novel security challenges
• Intellectual curiosity and continuous learning mindset
• Ability to translate theoretical threat research into practical defensive measures
Similar Jobs
Explore other opportunities that match your interests