Jobs and Careers
HE

Threat Hunter Cybersecurity

Hearst
New York City, United Statesfull_timeVerifiedPosted 29 Feb 2024
💰 $165,000/yr($137,000/yr$165,000/yr)

About the role

Hearst Technology, Inc, Information Security Office seeks a Threat Hunter for their Enterprise Vulnerability and Threat Management Team. The Threat Hunter is responsible for strengthening Hearst’s cyber security posture through research, threat simulations, threat hunting, and offensive security engagements.  The scope of the position’s responsibilities includes analyzing and correlating large data sets to uncover novel threats and attack techniques that may be present within multiple environments. This role will help reduce the attack surface at Hearst through identifying, prioritizing, and partnering with various departments for timely vulnerability remediation. 

Hearst is a leading global, diversified media, information, and services company with over 360 businesses. Its major interests include ownership in cable television networks; global financial services leader Fitch Group; Hearst Health; Hearst Transportation; 33 television stations; 24 daily and 42 weekly newspapers; more than 300 magazines around the world; digital services businesses; and investments in emerging digital entertainment companies. 

Team: The Cybersecurity foundation is multi-faceted and focuses on driving value. Our mission is to establish an integrated program that ensures the overall effectiveness of capabilities that impact information security across business units globally.

Job Description/Key Responsibilities: 

  • Utilize Threat Intelligence and Threat Models to create threat hypotheses
  • Plan and scope Threat Hunt Missions to verify threat hypotheses
  • Proactively and iteratively search through systems and networks to detect advanced threats
  • Prepare and report risk analysis and threat findings to appropriate stakeholders
  • Recommend and assist with development of new security content as the result of hunt missions to include signatures, alerts, workflows, and automation.
  • Ability to analyze the environment from a threat actor's perspective, including the skill to conduct prioritized identification of vulnerable assets, and then devise techniques to detect potential attack activity.
  • Identifies security risks, threats, misconfigurations and vulnerabilities of existing networks, systems, applications and develops solutions to remediate identified threats.
  • Analyzes identified malicious network and system log activity to determine weaknesses exploited, exploitation methods, effects on system and information
  • Tracking and documenting hunting activities and providing updates to leadership through executive summaries and in-depth technical reports
  • High performance skillset which not only understands the threat spaces as it relates to risks, but also able to meet the technical challenge of communicating this out to our teams
  • 5+ years of direct experience performing threat hunting in an active corporate environment.
  • Experience consuming and analyzing Cyber Threat Intelligence for actionable takeaways
  • Experience explaining threat hunt objectives in plain English and able to communicate associated risk.
  • Reporting gaps in a meaningful way that addresses a business risk as well as providing technical solutions to the operations teams in remediation is key
  • Relevant experience required.  
  • Other duties as assigned

Skills or experience required:

  • This is not a beginner level position and requires comfort and experience with manual security work, low level functionality, web application functionality, IT security, and vulnerability and threat management.
  • Minimum 5 years of experience in the practice of threat hunting

Technical Skills 

  • Demonstrated experience planning and executing threat hunt missions
  • Comfort operating in terminal environments
  • Ability to analyze an architectural document and strategically probe accordingly
  • Working knowledge of common (HTTP, DNS, SMB, etc.) networking protocols
  • Familiar with operation of both Windows and Linux based systems
  • Proficient with cross platform scripting languages such as Python or Golang, also PowerShell
  • Experience working with various technologies and platforms such as AWS, Azure, O365, GCP, containers, etc.
  • Understanding of current cyber threat landscape, the different tactics commonly used by adversaries and how one would investigate, contain, and recover against their attacks

Desired Skills

  • Strong work ethic with attention to detail
  • Demonstrated analytical abilities
  • Attention to detail, verbal and written communication, initiative, and motivation to learn
  • Strong written/oral communication skills required along with desire and ability to communicate with business leaders through a

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Hearst

View company profile →