Cnsltng Dir, Threat Hunter
CNA InsuranceAbout the role
You have a clear vision of where your career can go. And we have the leadership to help you get there. At CNA, we strive to create a culture in which people know they matter and are part of something important, ensuring the abilities of all employees are used to their fullest potential.
Threat Hunter, Consulting Director is a senior-level individual contributor focused on proactively searching adversarial activity in the network with the goal of discovering threats prior to an adversary completing its mission. This role utilizes advanced skills to perform enterprise forensics including operating system artifact analysis, log analysis, network traffic analysis, and the MITRE ATT&CK framework. This position is responsible for developing innovative and creative detection tactics and techniques that protect client data and corporate assets from diverse threats. The role is a key member of a highly technical team operating in a rapidly changing environment.JOB DESCRIPTION:
Essential Duties & Responsibilities
Performs a combination of duties in accordance with departmental guidelines:
Leads and conducts real-time and historical analysis using the full security suite including Endpoint Protection, SIEM, Firewall, EDR, IDS, Email Gateway, Web Content Filtering, and Identity Management technologies.
Conducts incident response triage analysis on suspected hosts to determine potential attacks and scope.
Conducts threat hunting operations based on the latest threat intelligence.
Creates strategies for enterprise-wide hunts based on triage findings and intelligence efforts.
Maintains awareness of emerging attack tactics, techniques, and procedures.
Collaborates with SOC, Threat Intelligence, Incident Response, and Enterprise Security teams.
Identifies visibility gaps and recommends improvements.
Manages day-to-day SOC monitoring, investigations, response, and intelligence activities.
Coordinates escalation for advanced forensics and malware reverse engineering.
Communicates security incidents clearly to business and non-technical stakeholders.
May perform additional duties as assigned.
Reporting Relationship
Typically AVP or above
Skills, Knowledge & Abilities
In-depth knowledge of SIEM, IDS/IPS, web proxies, DLP, CASB, DNS security, DDoS protection, and firewalls.
Advanced experience with forensic tools for OS artifact, memory, and network analysis.
Strong understanding of malware, reverse engineering principles, and network protocols.
Demonstrated ability to build, execute, and lead enterprise threat hunting programs.
Ability to work collaboratively in high-pressure incident response environments.
Demonstrated ability to apply artificial intelligence and machine-learning techniques to threat hunting, including use of LLMs, UEBA, and statistical models to surface anomalous behavior, enrich low-signal telemetry, and accelerate hypothesis-driven hunts across large enterprise datasets.
Experience evaluating, tuning, and operationalizing AI-enabled security capabilities (e.g., AI-assisted SIEM, EDR/XDR, and detection engineering workflows), with an understanding of model limitations, bias, false-positive risk, and the need for analytically defensible outcomes suitable for executive, legal, and regulatory review.
Education & Experience
Bachelor’s degree in Computer Science or related discipline, or equivalent experience.
Typically a minimum of 10 years of experience in cyber monitoring, threat hunting, incident response, forensics,
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s