Cyber Threat Hunter
Listed on 2026-06-23
-
IT/Tech
Cybersecurity
Cyber Threat Hunter
About your role:
As a Cyber Threat Hunter, you will serve as a senior individual contributor within Cyber Security Operations, building behavior-based detection capabilities that identify adversary activity before incidents become material. You will turn enterprise telemetry into high-confidence signals and durable detections using inside-out intelligence, data science, and AI-enabled development workflows. You will partner closely with detection engineering, security operations, and incident response teams in a cloud environment, with a primary focus on proactive detection development and signal engineering.
Whatyou'll do:
- Build and maintain behavior-based detections that identify adversary activity through sequences, relationships, and deviations across identity, endpoint, cloud, network, and application telemetry.
- Translate attacker techniques, malware behaviors, and adversary tradecraft into testable, explainable, and durable detection logic using a detection-as-code approach.
- Define telemetry, enrichment, and normalization requirements needed to improve signal quality, close coverage gaps, and support scalable detection outcomes in a cloud environment.
- Apply statistical methods, machine learning techniques, and Python-based analytical workflows to develop behavioral models, engineering features, and improve precision detection and operational actionability.
- Validate suspicious behaviors using digital forensics and incident response methods to distinguish malicious activity from benign anomalies, misconfigurations, and expected operational patterns.
- Partner with security operations, incident response, and detection engineering teams to operationalize detections with triage guidance, severity rationale, playbook alignment, and MITRE ATT&CK classification and coverage reporting.
- Use external threat intelligence as prioritization context while ensuring detections are grounded in observable behavior and telemetry within the enterprise environment.
- Responsibilities listed are not intended to be all-inclusive and may be modified as necessary.
- 8+ years of experience in detection engineering, proactive threat hunting, digital forensics and incident response, malware analysis, reverse engineering, threat research, red teaming, purple teaming, advanced security operations, or a combination of these domains.
- 8+ years of experience building behavior-based detections across large-scale enterprise telemetry using correlation, sequence analysis, behavioral analytics, and operational detection logic.
- 8+ years of experience using digital forensics and incident response methods across host, identity, cloud, and network investigations to validate suspicious activity and improve detection fidelity.
- 8+ years of experience applying Python for data analysis, automation, feature engineering, and repeatable analytical workflows in cybersecurity use cases.
- 6+ years of experience applying statistical modeling, machine learning methods, or comparable analytical techniques to security telemetry, including baselining, outlier detection, clustering, time-series analysis, behavioral scoring, or graph-based analysis.
- Experience using AI-assisted development tools with validation, testing, reproducibility, and secure coding practices in analytics, automation, or detection development workflows.
- Bachelor's degree or higher in Computer Science, Cybersecurity, Information Security, Engineering, Data Science or related field or equivalent combination of education, related experience and/or military experience.
- Experience with Google Sec Ops or Chronicle detection content development, data modeling, and telemetry analysis.
- Experience integrating security tools through application programming interfaces (APIs) and building internal services, signal pipelines, or workflow automation solutions.
- Familiarity with detection-as-code practices, including Git, continuous integration and continuous delivery (CI/CD), testing, and code review.
- Relevant certifications such as GIAC Reverse Engineering Malware (GREM), GIAC Certified Forensic Analyst (GCFA), GIAC Certified Incident Handler (GCIH), GIAC Certified Intrusion Analyst (GCIA), CompTIA CySA+, Certified Information Systems Security Professional (CISSP), Certified Threat Hunting Professional (CTHP), Certified Threat Intelligence Analyst (CTIA), Certified Cloud Security Professional (CCSP), or equivalent cybersecurity certification.
How you'll work:
This role is on-site Monday through Friday. Fiserv considers in-person collaboration to be an essential part of this role as in-person office experience helps you with your overall onboarding experience and leads to stronger productivity.
Sponsorship:You must currently possess valid and unrestricted U.S. work authorization to be considered for this role. Individuals with temporary visas including, but not limited to, F-1 (OPT, CPT, STEM), H-1B, H-2, or TN, or any candidate requiring…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).