Jobs and Careers
EM

Threat Hunting Analyst

EMW, Inc.
Belgiumfull_timeVerifiedPosted 4 Apr 2023

About the role

As a Cyber Security Threat Hunting Analyst, the incumbent will work alongside a team of Security Analysts to proactively detect cyber security attacks against NATO networks. They will research and react to the latest threats, using industry‐leading tools to discover new and ongoing attacks.

Main responsibilities:

  • Provide subject matter expertise supporting the end‐to‐end threat hunting process;
  • Develop hypotheses to be used in a threat hunt;
  • Create security tool content such as searches, reports and dashboards to facilitate threat hunting;
  • Perform in‐depth analysis of suspicious activity to deliver conclusions and recommendations;
  • Review and develop logging configurations to enable a comprehensive threat hunting capability;
  • Develop and document threat‐hunting procedures;
  • Share the results of threat hunts via presentations and technical reports.

Requirements

Mandatory:

  • NATO Secret Clearance
  • Expert level in at least three of the following areas and a high level of experience in
    several of the other areas;
  • Cybersecurity threat hunting.
  • MITRE ATT&CK Framework;
  • Security Incidents Event Management products (SIEM) – e.g. Splunk;
  • Splunk Processing Language;
  • Network Based Intrusion Detection Systems (NIDS) – e.g. SourceFire, Palo Alto
    Network Threat Prevention;
  • Host Based Intrusion Detection Systems (HIDS);
  • Sysmon;
  • Full Packet Capture systems – e.g. Niksun, RSA/NetWitness;
  • Computer security tools (Vulnerability Assessment, Anti‐virus, Protocol Analysis,
    Anti‐Virus, Protocol Analysis, Anti‐Spyware, etc);
  • Proficiency in Intrusion/Incident Detection and Handling;
  • Comprehensive knowledge of the principles of computer and communications
    security, networking, and the vulnerabilities of modern operating systems and
    applications.

Desirable:

  • a. Industry leading certification in the area of Cybersecurity such as GCFA, GCIA,
    GNFA;
  • Knowledge and experience in Splunk Enterprise Security suite;
  • A good understanding of Security, Orchestrations, Automation and Response
    (SOAR) concepts and their benefits to the protection of CIS infrastructures;
  • Knowledge and experience in threat hunting in corporate/government level
    environment;
  • Strong knowledge of malware families and network attack vectors;
  • Experience in analysis of various threat actor groups, attack patterns and tactics,
    techniques, and procedures (TTPs), deep analysis of threats across the enterprise
    by combining security rules, content, policy and relevant datasets;
  • Ability to analyse attack vectors against a particular system to determine attack
    surface.

Normal office environment with standard working hours, but may exceptionally be
required to work non‐standard hours in support of a major Cyber Incident, or on a
shift system for a limited period of time due to urgent operational needs.

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

EMW, Inc.

View company profile →