Jobs and Careers
US

Cyber Threat Hunter - Senior

USAA
San Antonio, United Statesfull_timeVerifiedPosted 2 Sept 2025
💰 $243,340/yr($127,310/yr$243,340/yr)

About the role

Why USAA?

At USAA, our mission is to empower our members to achieve financial security through highly competitive products, exceptional service and trusted advice. We seek to be the #1 choice for the military community and their families.

Embrace a fulfilling career at USAA, where our core values – honesty, integrity, loyalty and service – define how we treat each other and our members. Be part of what truly makes us special and impactful.

The Opportunity

If you make it on our team, you'll be part of a cutting edge unit probing USAA's defenses and supporting our members by securing their information from attackers. Our Cyber Threat Hunt team supports our Cyber Threat Operations Center and our members by fusing open-source intelligence, attacker TTPs and endless curiosity to validate our security stack on multiple levels. You will be challenged daily, both supporting and being supported by internal and external collaborative teams.

We offer a flexible work environment that requires an individual to be in the office 4 days per week. This position can be based in one of the following locations: San Antonio, TX, Plano, TX, Phoenix, AZ, Colorado Springs, CO, Charlotte, NC. Relocation assistance is not available for this position.

What you'll do:

  • Leads peers and team members in the execution of the Information Security domain activities while anticipating efforts that will impact their team.
  • Researches and analyzes the latest information security vulnerabilities, threats, exploits, trends and intelligence. Shares intelligence with peer teams.
  • Conducts advanced vulnerability management, security configuration assessments, and/or penetration testing operations and manages the resulting findings.
  • Develops analysts through training and knowledge sharing activities.
  • Monitors internal and external networks, systems, and applications for advanced security anomalies and events (e.g. suspicious behavior, attacks, and security breaches). Trains analysts in incident detection and response.
  • Responds to cyber incidents, performing detailed analysis using complex security tools to determine root cause and impact by using a broad range of demonstrated experience (e.g. forensics, networking, servers, coding, etc.) to determine a malicious actor's tactics, techniques, and procedures. Trains new analysts in incident detection and response.
  • Utilizes discoveries from the incident response process to make significant and/or complex improvements to the existing detection capabilities, operational processes and security controls.
  • Prepares and delivers written and/or verbal briefs with recommendations to senior leadership on latest threats, alerts, incidents, and improvements.
  • Provides insight on issues and serves as a mentor and coach to peers and team members for assigned area of responsibility.
  • Ensures risks associated with business activities are effectively identified, measured, monitored, and controlled in accordance with risk and compliance policies and procedures.

What you have:

  • Bachelor’s degree: OR 4 years of related experience (in addition to the minimum years of experience required) may be substituted in lieu of degree.
  • 6 years of related experience in Information Security, Cybersecurity and/or Information Technology with a security focus to include accountability for complex tasks and/or projects.
  • 4 years of related experience in one of the following domains: Security and Risk Management, Asset Security, Security Architecture and Engineering, Communications and Network Security, Identity and Access Management, Security Assessment and Testing, Security Operations, Software Development Security.
  • Advanced level of business acumen in the areas of business operations, risk management, industry practices and emerging trends.
  • Knowledge of attacker tools/tactics/procedures and applying them to access management, governance, threat hunting, investigations, and incident response.
  • Knowledge of defense-in-depth principles and security architecture.
  • Demonstrated experience with threat hunting, incident response, and detection engineering experience in Mac, Linux and Windows environments.

What sets you apart:

  • Experience with emulating adversary tactics and techniques to identify weaknesses in our defenses and improve our security posture, using the MITRE ATT&CK framework
  • PowerShell or Python scripting and API integration skills.
  • Experience with Linux forensics and security.
  • Knowledge of offensive tooling and tactics.
  • Experience performing comprehensive incident and pre-incident investigations, identifying the scope, impact, and root cause of security anomalies.<

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

USAA

View company profile →