Threat Hunting Consultant

Remote • Posted 1 day ago • Updated 1 day ago
Full Time
No Travel Required
Remote
$110,000 - $140,000/yr
Company Branding Image
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Microsoft Defender
  • Splunk
  • Kusto Query language

Summary

Job Title :: Threat Hunting Consultant

Location :: Remote 

Type ::Fulltime role

 

Microsoft Security Stack Expertise

  • Extensive hands-on experience with Microsoft Defender for Endpoint (MDE)
  • Proficiency with Microsoft 365 Defender (XDR) unified security operations
  • Advanced knowledge of Kusto Query Language (KQL) for threat hunting and detection
  • Deep understanding of MDE investigation capabilities, automated response features, and integration architecture

 

SIEM and Analytics

  • Expert-level Splunk Enterprise Security experience
  • Proficiency in Splunk Processing Language (SPL) for complex correlation and hunting queries
  • Experience with Splunk User Behavior Analytics (UBA) or similar behavioral detection platforms
  • Knowledge of SIEM architecture, data onboarding, and optimization techniques

 

Threat Hunting and Detection Engineering

  • Demonstrated experience conducting hypothesis-driven threat hunts
  • Strong understanding of MITRE ATT&CK framework and its practical application
  • Ability to translate threat intelligence and attack research into actionable hunting queries
  • Experience developing high-fidelity detection rules with low false positive rates
  • Knowledge of adversary tactics, techniques, and procedures (TTPs) across multiple threat actor groups

 

Incident Response

  • Proven track record in hands-on incident response and investigation
  • Expertise in endpoint forensics and malware analysis
  • Familiarity with incident response frameworks (NIST, SANS) and playbook development
  • Experience with containment, eradication, and recovery procedures for complex security incidents
  • Understanding of forensic evidence preservation and chain of custody requirements

 

Technical Foundations

  • Deep understanding of Windows internals, process behaviors, and security architecture
  • Knowledge of network protocols, traffic analysis, and common attack vectors
  • Familiarity with authentication protocols (Active Directory, Azure AD, Kerberos, NTLM)
  • Understanding of scripting and automation (PowerShell, Python, or similar)

 

Knowledge Transfer and Teaching Ability

  • Proven ability to explain complex technical concepts to varied technical audiences
  • Experience developing and delivering technical training or mentorship programs
  • Patience and commitment to building team capability, not just completing tasks
  • Ability to adapt teaching style to different learning preferences and skill levels

 

Communication and Collabo ration

  • Excellent written communication skills for documentation and reporting
  • Strong verbal communication skills for training delivery and incident collaboration
  • Ability to work effectively with cross-functional teams (IR, detection engineering, IT operations)
  • Comfort operating in a fully remote environment with distributed team members

 

Problem Solving and Initiative

  • Self-directed work style with ability to identify priorities independently
  • Creative problem-solving approach to novel security challenges
  • Intellectual curiosity and continuous learning mindset
  • Ability to translate theoretical threat research into practical defensive measures
  • Minimum 5-7 years of experience in cybersecurity with focus on detection, threat hunting, and/or incident response
  • At least 2 years of hands-on experience with Microsoft Defender for Endpoint in an enterprise environment
  • Demonstrated experience conducting threat hunts that led to actionable security improvements
  • Previous experience supporting or leading security tool migrations or implementations (highly valued)
  • Certifications (Preferred)

 

Highly Valued:

  • GIAC Cyber Threat Intelligence (GCTI)
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Forensic Analyst (GCFA)
  • Certified Threat Intelligence Analyst (CTIA)

 

Relevant:

  • Microsoft Certified: Security Operations Analyst Associate (SC-200)
  • Splunk Enterprise Security Certified Admin
  • CISSP, CISM, or equivalent security management certification
  • Offensive Security certifications (OSCP, OSCE) demonstrating adversarial perspective

 

 Knowledge Transfer and Teaching Ability

  • Proven ability to explain complex technical concepts to varied technical audiences
  • Experience developing and delivering technical training or mentorship programs
  • Patience and commitment to building team capability, not just completing tasks
  • Ability to adapt teaching style to different learning preferences and skill levels

 

Communication and Collaboration

  • Excellent written communication skills for documentation and reporting
  • Strong verbal communication skills for training delivery and incident collaboration
  • A bility to work effectively with cross-functional teams (IR, detection engineering, IT operations)
  • Comfort operating in a fully remote environment with distributed team members

 

Problem Solving and Initiative

  • Self-directed work style with ability to identify priorities independently
  • Creative problem-solving approach to novel security challenges
  • Intellectual curiosity and continuous learning mindset
  • Ability to translate theoretical threat research into practical defensive measures
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91097129
  • Position Id: 9062323
  • Posted 1 day ago

Company Info

About Stanley David and Associates

We strive to add value and work as true partner with our clients

Stanley David And Associates is a recruitment specialist in the area of IT and Engineering and we stay firmly in our area of expertise, doing what we love.

We know the players and the companies and invest a lot of time getting to know candidates and clients in equal measure. This ensures a swift, cost effective and perfect placement whether it s permanent or interim.

In addition we have a reputation for having the best understanding of the market landscape, for sourcing great candidates

-We have a Global Footprint with offices in 3 countries USA, UK and India.

-SDNA Global have built up an incredible reputation within the IT strategic hiring.

-We work with Tier1 and Tier 2 IT Outsourcing companies for Leadership hiring needs in UK, Europe, USA and Indian geos.

-Each SDNA member has over 5 years of experience in Talent Acquisition

-We have successfully closed roles in countries UK, USA, Germany, Sweden, Dubai, France, Netherlands, Switzerland, Austria, Hungry, Spain, Italy, Norway, Denmark, Nigeria and South Africa

-Telecom, Media and Hi-tech

-Health care and Life Sciences

-Energy and Utilities

-CPG, Retail and Transport

-Banking and Financial Services


About_Company_OneAbout_Company_Two
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

It looks like there aren't any Similar Jobs for this job yet.

Search all similar jobs