Jobs and Careers
AM

Principal Threat Hunter, Cyber Security (remote)

AmerisourceBergen
Washington, United StatesRemotefull_timeVerifiedPosted 6 Dec 2024
💰 $186,230/yr($121,000/yr$186,230/yr)

About the role

Our team members are at the heart of everything we do. At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential to us being able to deliver on that purpose. If you want to make a difference at the center of health, come join our innovative company and help us improve the lives of people and animals everywhere. Apply today!

Job Details

The Principal Threat Hunter is a technical leader in the Cencora Security Operations Center who applies their knowledge of adversarial tactics and techniques and their experience with security controls, infrastructure, and networking to proactively investigate potential cyber threats.  They will use their findings to improve detection, response, and security controls.

PRIMARY DUTIES AND RESPONSIBILITIES:

  • Conduct threat hunting to identify, classify, prioritize, and report on cyber threats following industry best practices.

  • Conduct research on emerging security threats; Provide correlation and trending of cyber incident activity.

  • Craft methodologies for monitoring , detection, and analytics for SIEM and other platforms.

  • Provide security gap analysis and effectiveness assessments of security platform technologies such as SIEM, SOAR, XDR, EDR.

  • Formulates methodologies to monitor for as well as respond to security related events.

  • Identification of and correlation with other data sources to enhance security event detection, monitoring and response capabilities.

  • Oversees the response to information security incidents, investigation, countermeasures, and recovery.

  • Analysis of security incidents for further enhancement of alerting schema.

  • Provides security briefings to advise on critical issues that may affect the enterprise.

SKILLD & EXPERIENCE:

  • Exceptional written and verbal communication skills with the ability to clearly convey highly complex technical topics and findings to others.

  • Expert level understanding of security controls including system-level controls, network controls, and security operations, across Endpoint, Cloud, SaaS, and Identity.

  • Advanced knowledge of Endpoint Detection and Response (EDR) capabilities and multiple EDR products.

  • Foundational knowledge of Digital Forensics and Incident Response (DFIR) processes.

  • Experience creating SIEM correlation logic, performing data analysis, managing data intake, and conducting security threat analytics on real-time and historical log data.

  • Ability to create processes around analyzing and investigating alerts and threats for anomalous, suspicious, or malicious activity.

  • Ability to create processes and methodologies to support proactively hunting for potential cyber threats.

  • Knowledge of regular expressions and at least one common scripting language (Python, Powershell, etc).

  • Experience mentoring others as they advance their technical skills

  • Ten (10) ore more years of working in the cybersecurity industry (Enterprise level)

  • Eight (8) or more years of directly-related or relevant experience, preferably in information security.

  • Bachelor’s Degree in Computer Science, Information Technology or any other related discipline or equivalent related experience.

Preferred Certifications:

  • Azure Security Engineer Certification

  • Certified Cloud Security Professional (CCSP)

  • Certification in Information Security Strategy Management (CISM)

  • Certified Information Systems Security Professional (CISSP)

  • CompTIA Security + Certification

  • Systems Security Certified Practitioner (SSCP)

Behavioral Skills:

  • Conflict Resolution

  • Creativity & Innovation

  • Decision Making

  • Assertiveness

  • Influencing Skills

  • Planning

  • Presentation Skills

  • Risk-taking

Technical Skills:

  • Threat Hunting

  • Network Solutions and Systems

  • Cybersecurity

  • Root Cause Analysis

  • Information Security Strategy Standards (SOX, ISO 27001/27002, COBIT, ITIL, NIST, PCI)

  • Advanced Encryption

  • Application Architecture

  • Identity and Access Management

  • IT Risk Management

Tools Knowledge:

  • Microsoft Office Suite

  • Programming and Development Languages - JavaScript, HTML/CSS, Python, SQL

  • Security Tools - SIEM, ED

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

AmerisourceBergen

View company profile →