Senior Python Engineer - Threat Hunter (Specialist I - Information Security)
Role details
Job location
Tech stack
Job description
The successful candidate will have strong software development experience, complemented by hands-on exposure to threat hunting or cybersecurity investigations, particularly in enterprise and cloud environments., * Design, develop, and maintain Python-based tools and automation frameworks to support threat hunting and security investigations
-
Build and standardise Jupyter Notebook-based hunting workflows, including data enrichment, validation, automation, and reporting
-
Develop reusable Python libraries, modules, APIs, and command-line tools to enable scalable hunt execution
-
Engineer data pipelines to ingest, transform, and analyse large volumes of security telemetry
-
Perform hypothesis-driven threat hunting and targeted investigations across endpoint, network, identity, and cloud data
-
Orchestrate and schedule automated hunting workflows using pipeline or orchestration platforms
-
Collaborate with Threat Intelligence and Detection Engineering teams to translate hunting outcomes into operational detections
-
Document methodologies, findings, and recommendations in clear, structured technical reports
Requirements
Do you have experience in Software development?, Python / Software Engineering:
-
Strong experience as a Python developer or software engineer, with a focus on automation, tooling, or data processing
-
Proven ability to write production-quality Python code following standard engineering best practices
-
Experience working with structured data formats such as JSON, CSV, and Parquet
-
Familiarity with Python data and analytics libraries (e.g., Pandas, NumPy)
-
Experience with version control systems (Git) and standard development workflows
Threat Hunting / Security:
-
Hands-on experience supporting threat hunting, security investigations, or detection engineering activities
-
Working knowledge of adversary techniques and the ability to apply frameworks such as MITRE ATT&CK
-
Experience analysing security telemetry from endpoint, network, and cloud environments
-
Exposure to hunting or investigation activities in Azure, AWS, or GCP environments
Desirable Skills:
-
Experience integrating with security platforms such as Microsoft Sentinel/Defender, Cybereason, or CrowdStrike
-
Experience with notebook automation, templating, or report generation
-
Familiarity with CI/CD pipelines and DevOps practices
-
Relevant security certifications (GIAC, OSCP, CEH, or equivalent), threat intelligence,incident response,mitre att&ck,penetration testing