Security Analysis Threat Hunter - Plano, TX Hybrid
Listed on 2026-08-05
-
IT/Tech
Cybersecurity, Security Management & Operations
Security Analysis Threat Hunter
NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.
We are currently seeking a Security Analysis Threat Hunter - Plano, TX Hybrid to join our team in Plano, Texas (US-TX), United States (US).
The Threat Hunting function is responsible for identifying and validating suspicious or malicious activity. Ownership of vulnerability remediation tracking and patch management remains with the Vulnerability Management teams. Threat Hunters focus on detection, validation, and enablement of defensive controls.
This role focuses on hypothesis-driven, intelligence-led, and MITRE ATT&CK–aligned threat hunting. The specialist works closely with SOC, SIEM, Vulnerability Management, and Incident Response teams to improve detection coverage, reduce attacker dwell time, and continuously enhance NTT DATA's managed security services capabilities.
This position will be on-site at the client site 4 days per week. Only local candidates will be considered.
Key Responsibilities- Conduct hypothesis-driven and tactic-based threat hunts aligned to the MITRE ATT&CK framework.
- Identify low-and-slow, post-compromise attacker behavior not detected through automated alerts.
- Ingest and operationalize internal and external threat intelligence into hunting hypotheses.
- Develop and execute advanced threat hunting queries across SIEM, EDR, and security analytics platforms.
- Collaborate with SOC, SIEM, and Incident Response teams to escalate confirmed threats and support containment.
- Identify telemetry gaps and work with engineering teams to improve visibility and logging.
- Feed validated hunt results into detection engineering, threat briefs, and use-case improvements.
- Participate in threat hunt working sessions, operational reviews, and customer-facing discussions as required.
- SIEM platforms and log analytics tools
- Endpoint Detection and Response (EDR/XDR) solutions
- MITRE ATT&CK Navigator and DETT&CT
- Threat hunting notebooks, scripts, and automation frameworks
- Internal and open-source threat intelligence feeds
- 10+ years' experience in Cyber Security
- Strong understanding of adversary tactics, techniques, and procedures (TTPs).
- Hands-on experience performing structured threat hunts in enterprise environments.
- Proficiency with SIEM query languages and endpoint telemetry analysis.
- Ability to translate threat intelligence into actionable security detections.
- Strong written and verbal communication skills for technical and executive audiences.
- GIAC Certified Threat Intelligence (GCTI)
- GIAC Certified Incident Handler (GCIH)
- CompTIA CySA+
- Certified Ethical Hacker (CEH)
- Number of proactive threat hunts executed per reporting period
- High-confidence threats identified without prior alerts
- Reduction in attacker dwell time through proactive discovery
- Percentage of hunt findings operationalized into detection rules
- Coverage improvement against MITRE ATT&CK techniques
- Mean time to escalate verified threats to Incident Response
- Quality and clarity of threat hunt reports and recommendations
NTT DATA provides a reasonable range of compensation for U.S.
-based positions. The starting pay range for this role is $106,575 – $177,625. Actual compensation will depend on a number of factors, including the candidate's relevant experience, technical skills, and other qualifications.
This position may also be eligible for incentive compensation based on individual and/or company performance.
This position is eligible for company benefits including medical, dental, and vision insurance with an employer contribution, flexible spending or health savings account, life and AD&D insurance, short and long term disability coverage, paid time off, employee assistance, participation in a 401k program with company match, and additional voluntary or legally-required benefits.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).