FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in threat hunting and incident response, utilizing the MITRE ATT&CK framework to analyze and document adversary behaviors. Proficient in leveraging SIEM and EDR tools for effective detection and validation of security controls in collaboration with blue teams.
Highest-signal resume keywords
Threat HuntingSIEM ExperienceEDR/XDR ToolsMITRE ATT&CK FrameworkStrong Communication Skills
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Threat HuntingIncident ResponseLog AnalysisQuery LanguagesScripting Languages
Soft Skills
Written CommunicationVerbal CommunicationIndependent Operation
Tools & Technologies
SplunkMicrosoft SentinelCrowdStrike FalconMicrosoft Defender for EndpointZeek
Certifications & Qualifications
Top Secret ClearanceSCI Eligibility
Industry Keywords
Adversary TTPsRed Team MethodologyPurple Team EngagementsOperational SecurityCustomer-Facing Roles
Tech Stack
Tools & technologiesCloudPythonSplunk
About the role
Key responsibilities & impact- Conduct hypothesis-driven and intelligence-led threat hunts across endpoints, networks, and cloud telemetry
- Analyze logs, alerts, and historical data for indicators of compromise, anomalous behavior, and adversary TTPs mapped to MITRE ATT&CK
- Document hunt coverage, methodology, findings, detection recommendations, and confirmed or suspected compromise
- Escalate immediately when active adversary activity is found
- Deliver threat hunt summaries and determine whether customer environments are clear before red team assessments
- Partner with blue teams during purple team engagements to detect, tune, and validate controls against red team TTPs in real time
- Brief technical and non-technical stakeholders on hunt results and purple team detection outcomes
- Serve as a Trusted Agent during red team assessments while maintaining strict confidentiality and operational security
Requirements
What you’ll need- 3–5+ years of experience in threat hunting, SOC/detection engineering, incident response, or a closely related defensive security role
- Hands-on experience working with a major SIEM and EDR platform
- Working knowledge of the MITRE ATT&CK framework and mapping observed activity to adversary TTPs
- Understanding of common adversary tradecraft and red team testing methodology
- Strong written and verbal communication skills for clear, customer-facing findings and an “all clear” determination
- Ability to operate independently in remote, customer-facing roles
- U.S. citizenship, with eligibility to obtain and maintain a U.S. government security clearance
- Active Top Secret with SCI eligibility
- SIEM platforms such as Splunk, Microsoft Sentinel, or Elastic
- EDR/XDR tools such as CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne, or Carbon Black
- Network detection and traffic analysis tools such as Zeek, Suricata, and full packet capture
- Log aggregation and correlation across endpoint, network, cloud, and identity sources
- Query and scripting languages such as KQL, SPL, and Python
- Familiarity with red team tooling and tradecraft such as Cobalt Strike, Havoc, and C2 traffic patterns
Benefits
Comp & perks- Employer-paid health insurance premiums, including medical, dental, and vision coverage, for employees and their families
- Employer-paid short- and long-term disability insurance and basic life and AD&D insurance
- 401(k) plan with a 4% employer contribution
- Professional-development reimbursement options for training, certifications, and education
- Flexible and remote-work policies for most positions
- Flexible paid time off and holiday schedule
