Threat Hunting Consultant
Offre en anglaisConduct hypothesis-driven threat hunts across endpoint, identity, and network environments to uncover malicious activity. Develop high-fidelity detection rules and improve incident response playbooks using KQL, SPL, and automation scripts.
- Télétravail
- Canada, India
- Publié 26 août 2026
- 1 poste
D’autres postes auxquels postuler directement
Des possibilités semblables publiées par des employeurs qui recrutent sur Jobs.ca, sans formulaire externe.
Résumé du poste
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Threat Hunting Consultant based in Canada. This role offers the opportunity to strengthen enterprise security through proactive threat hunting, advanced detection engineering, and incident response. You will investigate sophisticated threats across endpoint, identity, network, and security analytics environments. The position combines hands-on technical investigation with the development of high-fidelity detections and defensive capabilities. You will leverage Microsoft Defender, Splunk, behavioral analytics, and threat intelligence to identify and disrupt attacker activity. Your work will help reduce false positives, improve detection coverage, and strengthen incident response readiness. You will collaborate with security teams while contributing expertise, documentation, training, and mentoring in a security-focused environment. Accountabilities Conduct hypothesis-driven threat hunts across endpoint, identity, network, and security analytics environments to uncover malicious activity and previously undetected threats. Use Microsoft Defender for Endpoint, Microsoft 365 Defender/XDR, Splunk Enterprise Security, Splunk UBA, and related platforms to investigate suspicious activity and identify attacker behaviors. Develop and refine high-fidelity detection rules, correlation searches, and threat-hunting queries using KQL and SPL while minimizing false positives. Apply the MITRE ATT&CK framework and current attacker TTPs to guide threat-hunting activities, detection coverage, and defensive improvements. Perform incident response, endpoint forensics, malware analysis, and technical investigations to determine the scope, impact, and root cause of security incidents. Translate threat intelligence into actionable detection logic, hunting hypotheses, response procedures, and other defensive measures. Analyze Windows systems, processes, Active Directory, Azure AD, Kerberos, NTLM, network protocols, traffic patterns, and common attack vectors during investigations. Develop and improve incident response playbooks and automation using PowerShell and/or Python to increase investigation and response efficiency. Document findings, investigative procedures, detection logic, and security recommendations while communicating technical insights clearly to stakeholders. Support security capability development through knowledge sharing, training, mentoring, and continuous improvement of threat detection and response practices. Requirements 5+ years of relevant experience in threat hunting, detection engineering, incident response, cybersecurity operations, or a closely related security discipline. Extensive hands-on experience with Microsoft Defender for Endpoint and strong knowledge of Microsoft 365 Defender/XDR security operations. Expert-level experience with Splunk Enterprise Security, including advanced SPL for threat hunting, correlation, and security investigations. Experience with Splunk UBA or comparable behavioral analytics platforms. Advanced proficiency in Kusto Query Language (KQL) and strong ability to develop sophisticated hunting and detection queries. Proven experience conducting hypothesis-driven threat hunts and identifying sophisticated attacker behaviors and TTPs. Strong understanding of the MITRE ATT&CK framework and practical knowledge of modern attack techniques. Demonstrated ability to develop high-fidelity detection rules with strong detection coverage and low false-positive rates. Hands-on experience with incident response, endpoint forensics, malware analysis, and security investigations. Knowledge of NIST and SANS incident response frameworks and experience developing or maintaining response playbooks. Strong understanding of Windows internals, processes, security architecture, Active Directory, Azure AD, Kerberos, and NTLM. Knowledge of network protocols, traffic analysis, common attack vectors, and network-based indicators of compromise. Scripting and automation experience using PowerShell and/or Python. Strong analytical, problem-solving, documentation, communication, training, and mentoring skills. Benefits Annual salary range of $110,000–$130,000. Full-time opportunity focused on advanced cybersecurity, threat hunting, and detection engineering. Remote work environment with flexibility to collaborate from India. Opportunity to work with leading security technologies including Microsoft Defender, Splunk Enterprise Security, and behavioral analytics platforms. Exposure to complex security investigations, enterprise-scale threat detection, incident response, and security automation. Opportunities to contribute to security strategy, knowledge sharing, training, and technical mentoring. How Jobgether Works We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Ce que vous ferez
Conduct hypothesis-driven threat hunts across endpoint, identity, and network environments to uncover malicious activity. Develop high-fidelity detection rules and improve incident response playbooks using KQL, SPL, and automation scripts.
Exigences
Requires 5+ years of experience in threat hunting or incident response with expert-level proficiency in Microsoft Defender and Splunk. Must have strong knowledge of the MITRE ATT&CK framework, Windows internals, and scripting in PowerShell or Python.
Avantages
• Remote work environment • Exposure to leading security technologies • Opportunities for security strategy contribution • Knowledge sharing and technical mentoring
Compétences indiquées
- PythonSouhaitée
Autres compétences pertinentes
Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.
- Threat Hunting
- Detection Engineering
- Incident Response
- Microsoft Defender for Endpoint
- Splunk Enterprise Security
- KQL
- SPL
- MITRE ATT&CK
- Endpoint Forensics
- Malware Analysis
- PowerShell
- Python
- Active Directory
- Azure AD
- Network Traffic Analysis
- Behavioral Analytics
Domaines d’emploi
- Security & Safety
- Technology
- Consulting
- Software
- Data & Analytics
Renseignements supplémentaires
- Expérience minimale
- 5+ ans
- Langue de l’offre
- anglais
- Heures de travail
- 40 heures par semaine
- Niveau d’expérience
- Mid-Senior level
- Mode de candidature
- La candidature directe est offerte