Jobs and Careers
EM
Threat Hunting Analyst
EMW, Inc.Belgiumfull_timeVerifiedPosted 4 Apr 2023
About the role
As a Cyber Security Threat Hunting Analyst, the incumbent will work alongside a team of Security Analysts to proactively detect cyber security attacks against NATO networks. They will research and react to the latest threats, using industry‐leading tools to discover new and ongoing attacks.
Main responsibilities:
- Provide subject matter expertise supporting the end‐to‐end threat hunting process;
- Develop hypotheses to be used in a threat hunt;
- Create security tool content such as searches, reports and dashboards to facilitate threat hunting;
- Perform in‐depth analysis of suspicious activity to deliver conclusions and recommendations;
- Review and develop logging configurations to enable a comprehensive threat hunting capability;
- Develop and document threat‐hunting procedures;
- Share the results of threat hunts via presentations and technical reports.
Requirements
Mandatory:
- NATO Secret Clearance
- Expert level in at least three of the following areas and a high level of experience in
several of the other areas; - Cybersecurity threat hunting.
- MITRE ATT&CK Framework;
- Security Incidents Event Management products (SIEM) – e.g. Splunk;
- Splunk Processing Language;
- Network Based Intrusion Detection Systems (NIDS) – e.g. SourceFire, Palo Alto
Network Threat Prevention; - Host Based Intrusion Detection Systems (HIDS);
- Sysmon;
- Full Packet Capture systems – e.g. Niksun, RSA/NetWitness;
- Computer security tools (Vulnerability Assessment, Anti‐virus, Protocol Analysis,
Anti‐Virus, Protocol Analysis, Anti‐Spyware, etc); - Proficiency in Intrusion/Incident Detection and Handling;
- Comprehensive knowledge of the principles of computer and communications
security, networking, and the vulnerabilities of modern operating systems and
applications.
Desirable:
- a. Industry leading certification in the area of Cybersecurity such as GCFA, GCIA,
GNFA; - Knowledge and experience in Splunk Enterprise Security suite;
- A good understanding of Security, Orchestrations, Automation and Response
(SOAR) concepts and their benefits to the protection of CIS infrastructures; - Knowledge and experience in threat hunting in corporate/government level
environment; - Strong knowledge of malware families and network attack vectors;
- Experience in analysis of various threat actor groups, attack patterns and tactics,
techniques, and procedures (TTPs), deep analysis of threats across the enterprise
by combining security rules, content, policy and relevant datasets; - Ability to analyse attack vectors against a particular system to determine attack
surface.
Normal office environment with standard working hours, but may exceptionally be
required to work non‐standard hours in support of a major Cyber Incident, or on a
shift system for a limited period of time due to urgent operational needs.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s