Jobs and Careers
AN
Threat Hunter (US Remote)
AnomaliUnited StatesRemotefull_timeVerifiedPosted 11 Apr 2023
About the role
Company Description
Anomali delivers earlier detection and identification of adversaries in your organization’s network by making it possible to correlate tens of millions of threat indicators against your real time network activity logs and up to a year or more of forensic log data. Anomali’s approach enables detection at every point along the kill chain, making it possible to mitigate threats before any material damage to your organization has occurred. Responsibilities
• Collaborate in a cross functional team (engineering, sales, customer support etc.) to perform threat hunting duties in a new environment• Leveraging solid knowledge of Threat Intelligence, Threat Models, TTPs and other malicious/non-malicious indicator to create, maintain and periodically evaluate procedures, playbooks, and hunt techniques • Plan and execute iterative searches on customer systems, logs, and network to detect threats including the advanced ones• Identify any anomalous/malicious behavior using cyber threat hunt plans and techniques and identify any defensive gaps in the customer environment to showcase Anomali platform value to prospective customers• Leverage behavior detection knowledge and skills to detect threat
QualificationsSpecific Experience needed to be successful in this role:
• Bachelor’s Degree or additional 3 years of relevant work experience in lieu of degree • 5+ years of experience with data hunting/manipulation/presentation• Solid expertise in network and host-based analysis and investigations• Expertise with various security logs (EDR, Firewall, email gateway, web proxy etc.), common network protocols (http, dns, tcp, udb etc.)• Experience in planning and executing threat hunts• Understanding of complex Enterprise networks (routing, switching, firewalls, proxies, etc.)• Understanding of Windows, Linux and MacOS operating systems and their security events/logs etc.• Ability to write database queries, aggregate results and hunt for the information through scripting/programming as needed.• Proficient with scripting languages such as Python or PowerShell• Familiarity with SIEM tools• Security certification preferred such as CISSP, CCSP, SSCP, etc.
Equal Opportunities MonitoringIt is our policy to ensure that all eligible persons have equal opportunity for employment and advancement on the basis of their ability, qualifications and aptitude. We select those suitable for appointment solely on the basis of merit without regard to an individual's disability, race, color, religion, sex, sexual orientation, gender identity, national origin, age, or status as a protected veteran. Monitoring is carried out to ensure that our equal opportunity policy is effectively implemented.
If you are interested in applying for employment with Anomali and need special assistance or accommodation to apply for a posted position, contact our Recruiting team at recruiting@anomali.com.
Anomali delivers earlier detection and identification of adversaries in your organization’s network by making it possible to correlate tens of millions of threat indicators against your real time network activity logs and up to a year or more of forensic log data. Anomali’s approach enables detection at every point along the kill chain, making it possible to mitigate threats before any material damage to your organization has occurred. Responsibilities
• Collaborate in a cross functional team (engineering, sales, customer support etc.) to perform threat hunting duties in a new environment• Leveraging solid knowledge of Threat Intelligence, Threat Models, TTPs and other malicious/non-malicious indicator to create, maintain and periodically evaluate procedures, playbooks, and hunt techniques • Plan and execute iterative searches on customer systems, logs, and network to detect threats including the advanced ones• Identify any anomalous/malicious behavior using cyber threat hunt plans and techniques and identify any defensive gaps in the customer environment to showcase Anomali platform value to prospective customers• Leverage behavior detection knowledge and skills to detect threat
QualificationsSpecific Experience needed to be successful in this role:
• Bachelor’s Degree or additional 3 years of relevant work experience in lieu of degree • 5+ years of experience with data hunting/manipulation/presentation• Solid expertise in network and host-based analysis and investigations• Expertise with various security logs (EDR, Firewall, email gateway, web proxy etc.), common network protocols (http, dns, tcp, udb etc.)• Experience in planning and executing threat hunts• Understanding of complex Enterprise networks (routing, switching, firewalls, proxies, etc.)• Understanding of Windows, Linux and MacOS operating systems and their security events/logs etc.• Ability to write database queries, aggregate results and hunt for the information through scripting/programming as needed.• Proficient with scripting languages such as Python or PowerShell• Familiarity with SIEM tools• Security certification preferred such as CISSP, CCSP, SSCP, etc.
Equal Opportunities MonitoringIt is our policy to ensure that all eligible persons have equal opportunity for employment and advancement on the basis of their ability, qualifications and aptitude. We select those suitable for appointment solely on the basis of merit without regard to an individual's disability, race, color, religion, sex, sexual orientation, gender identity, national origin, age, or status as a protected veteran. Monitoring is carried out to ensure that our equal opportunity policy is effectively implemented.
If you are interested in applying for employment with Anomali and need special assistance or accommodation to apply for a posted position, contact our Recruiting team at recruiting@anomali.com.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s