> Markdown version of [/jobs/ext/1009472-security-engineer-ii-threat-hunter](https://www.wearedevelopers.com/jobs/ext/1009472-security-engineer-ii-threat-hunter). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer II (Threat Hunter) - **Company:** Propertyvalue Ross Stores - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $108,800.0 - $204,550.0 - **Contract:** Permanent contract - **Skills:** Data Analysis, Big Data, Computer Telephony Integration, Intelligence Analysis, Python (Programming Language), Open Source Intelligence, Security Software, Security Information and Event Management, SQL Databases, Scripting, Mitre Att&ck, Malware, Cyber Threat Analysis, Cybercrime, Cyber Warfare, Vulnerability Analysis - **Published:** June 9, 2026 - **Apply:** https://www.dice.com/job-detail/af3c1a28-904d-44c4-abe6-f5a26792271d ## About the Role People Building Effective Teams Developing Talent Collaboration Self Leading by Example Communicates Effectively Ensures Accountability and Execution Manages Conflict Business Business Acumen Plans, Aligns and Prioritizes Organizational Agility With particular emphasis on the following specific position-related competencies: Analysis and Judgment Drive for Results Technical Competence Interpersonal Effectiveness, Minimum of 8+ years of experience in cybersecurity, with at least 5+ years focused on threat intelligence analysis and cyber threat hunting. Proven experience leading or mentoring CTI analysts. Strong expertise in threat intelligence platforms (TIPs), SIEM tools, and endpoint detection technologies. Proficiency in collecting, analyzing, and disseminating threat intelligence from OSINT, internal sources, and commercial threat feeds. Hands-on experience with automated workflows, playbook development, and advanced threat hunting techniques. Deep understanding of attack methodologies, APTs, malware, ransomware, and other cyber threats. Familiarity with the MITRE ATT&CK framework and indicators of compromise (IoCs). Ability to synthesize complex data and produce actionable, clear intelligence for both technical and non-technical audiences. Strong communication skills for reporting and briefing leadership on emerging threats. Security certifications such as CISSP, GCTI, or equivalent are highly preferred. Experience working in large enterprise environments with complex infrastructures and multiple overlapping tools. Excellent reporting and communication skills with the ability to present technical findings to varied audiences. Proficiency in scripting languages such as Python and SQL for data analysis and automation. Knowledge of STIX/TAXII protocols for automated sharing and ingestion of structured threat intelligence data across systems. Strong understanding of dark web marketplaces, threat actor infrastructures, ransomware groups, and emerging cybercriminal tactics, techniques, and procedures (TTPs). PHYSICAL REQUIREMENTS/ADA: Job requires ability to work in an office environment, primarily on a computer. Requires sitting, standing, walking, hearing, talking on the telephone, attending in-person meetings, typing, and working with paper/files, etc. Consistent timeliness and regular attendance. Vision requirements: Ability to see information in print and/or electronically. This position may be performed remotely anywhere within the United States. #LI-Remote ## Description The Security Engineer II position is responsible for proactive threat hunting and cyber threat intelligence analysis to identify emerging threats, mitigate risks, and strengthen the organization's overall security posture. This role requires advanced technical expertise in cybersecurity tools, threat detection technologies, and Cyber threat intelligence analysis. The associate will collect, analyze, and disseminate cyber threat intelligence, leveraging data from OSINT (Open-Source Intelligence), Threat Intelligence platforms, and other sources, including SIEM and endpoint detection systems, to detect advanced persistent threats (APTs), malware, and other malicious activities. The position also requires experience working in complex environments, applying structured analysis processes, and collaborating with cross-functional teams to ensure the effective identification and mitigation of cyber threats., Proactively hunt for advanced persistent threats (APTs), malware, and other malicious activities across networks, systems, and applications. Identify hidden threats that evade traditional security measures. Synthesize large volumes of data from multiple sources to develop clear, actionable intelligence. Create detailed threat intelligence reports for technical teams and senior leadership. Proactively hunt for advanced persistent threats (APTs), malware, and other malicious activities across networks, systems, and applications. Identify hidden threats that evade traditional security measures. Create, optimize, and automate detection rules and enrichment logic using scripting languages like Python and SQL. Respond to escalation requests either via the Helpdesk, NOC, junior analysts or other IT representatives. Contribute to monthly Cyber Defense dashboard with relevant performance indicators and security threat assessments. Develop and implement automated workflows and playbooks to streamline threat detection, analysis, and response processes, ensuring quick and effective mitigation of identified threats. Mapping adversary behaviors using the MITRE ATT&CK framework to understand attack vectors and predict potential threats. 24x7 on call duties apply on rotation and escalation ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Alibaba Big Data and Machine Learning Technology](https://www.wearedevelopers.com/videos/37-alibaba-big-data-and-machine-learning-technology) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [PySpark - Combining Machine Learning & Big Data](https://www.wearedevelopers.com/videos/44-pyspark-combining-machine-learning-big-data) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)