Microsoft Security Stack Expertise
- Extensive hands-on experience with Microsoft Defender for Endpoint (MDE)
- Proficiency with Microsoft 365 Defender (XDR) unified security operations
- Advanced knowledge of Kusto Query Language (KQL) for threat hunting and detection
- Deep understanding of MDE investigation capabilities, automated response features, and integration architecture
SIEM and Analytics
- Expert-level Splunk Enterprise Security experience
- Proficiency in Splunk Processing Language (SPL) for complex correlation and hunting queries
- Experience with Splunk User Behavior Analytics (UBA) or similar behavioral detection platforms
- Knowledge of SIEM architecture, data onboarding, and optimization techniques
Threat Hunting and Detection Engineering
- Demonstrated experience conducting hypothesis-driven threat hunts
- Strong understanding of MITRE ATT&CK framework and its practical application
- Ability to translate threat intelligence and attack research into actionable hunting queries
- Experience developing high-fidelity detection rules with low false positive rates
- Knowledge of adversary tactics, techniques, and procedures (TTPs) across multiple threat actor groups
Incident Response
- Proven track record in hands-on incident response and investigation
- Expertise in endpoint forensics and malware analysis
- Familiarity with incident response frameworks (NIST, SANS) and playbook development
- Experience with containment, eradication, and recovery procedures for complex security incidents
- Understanding of forensic evidence preservation and chain of custody requirements
Technical Foundations
- Deep understanding of Windows internals, process behaviors, and security architecture
- Knowledge of network protocols, traffic analysis, and common attack vectors
- Familiarity with authentication protocols (Active Directory, Azure AD, Kerberos, NTLM)
- Understanding of scripting and automation (PowerShell, Python, or similar)
Knowledge Transfer and Teaching Ability
- Proven ability to explain complex technical concepts to varied technical audiences
- Experience developing and delivering technical training or mentorship programs
- Patience and commitment to building team capability, not just completing tasks
- Ability to adapt teaching style to different learning preferences and skill levels
Communication and Collabo ration
- Excellent written communication skills for documentation and reporting
- Strong verbal communication skills for training delivery and incident collaboration
- Ability to work effectively with cross-functional teams (IR, detection engineering, IT operations)
- Comfort operating in a fully remote environment with distributed team members
Problem Solving and Initiative
- Self-directed work style with ability to identify priorities independently
- Creative problem-solving approach to novel security challenges
- Intellectual curiosity and continuous learning mindset
- Ability to translate theoretical threat research into practical defensive measures
- • Minimum 5-7 years of experience in cybersecurity with focus on detection, threat hunting, and/or incident response
- At least 2 years of hands-on experience with Microsoft Defender for Endpoint in an enterprise environment
- Demonstrated experience conducting threat hunts that led to actionable security improvements
- Previous experience supporting or leading security tool migrations or implementations (highly valued)
- Certifications (Preferred)
Highly Valued:
- GIAC Cyber Threat Intelligence (GCTI)
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Forensic Analyst (GCFA)
- Certified Threat Intelligence Analyst (CTIA)
- Relevant:
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- Splunk Enterprise Security Certified Admin
- CISSP, CISM, or equivalent security management certification
- Offensive Security certifications (OSCP, OSCE) demonstrating adversarial perspective
Knowledge Transfer and Teaching Ability
- Proven ability to explain complex technical concepts to varied technical audiences
- Experience developing and delivering technical training or mentorship programs
- Patience and commitment to building team capability, not just completing tasks
- Ability to adapt teaching style to different learning preferences and skill levels
Communication and Collaboration
- Excellent written communication skills for documentation and reporting
- Strong verbal communication skills for training delivery and incident collaboration
- A bility to work effectively with cross-functional teams (IR, detection engineering, IT operations)
- Comfort operating in a fully remote environment with distributed team members
Problem Solving and Initiative
- Self-directed work style with ability to identify priorities independently
- Creative problem-solving approach to novel security challenges
- Intellectual curiosity and continuous learning mindset
- Ability to translate theoretical threat research into practical defensive measures
Location: Remote
Salary Range: $110,000 - $150,000 a year
#LI-CM2