> Markdown version of [/jobs/ext/2866961-cyber-threat-hunter](https://www.wearedevelopers.com/jobs/ext/2866961-cyber-threat-hunter). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Threat Hunter - **Company:** Fiserv, Inc. - **Location:** United States - **Experience:** Expert - **Salary:** $128,000.0 - $216,000.0 - **Contract:** Temporary contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Cloud Computing, Cloud Computing Security, Cluster Analysis, Code Review, Cyber Security, Continuous Integration, Digital Forensics, Intrusion Detection and Prevention, Information Systems Security Architecture Professional, Python (Programming Language), Machine Learning, Microsoft Office, Reverse Engineering, Secure Coding, Systems Integration, Feature Engineering, Mitre Att&ck, Malware, Cyber Threat Analysis, Git, Information Technology, Cybercrime - **Published:** September 12, 2026 - **Apply:** https://www.dice.com/job-detail/23f5fd0d-e76c-4965-a462-9037d4936b96 ## About the Role * 8+ years of experience in detection engineering, proactive threat hunting, digital forensics and incident response, malware analysis, reverse engineering, threat research, red teaming, purple teaming, advanced security operations, or a combination of these domains. * 8+ years of experience building behavior-based detections across large-scale enterprise telemetry using correlation, sequence analysis, behavioral analytics, and operational detection logic. * 8+ years of experience using digital forensics and incident response methods across host, identity, cloud, and network investigations to validate suspicious activity and improve detection fidelity. * 8+ years of experience applying Python for data analysis, automation, feature engineering, and repeatable analytical workflows in cybersecurity use cases. * 6+ years of experience applying statistical modeling, machine learning methods, or comparable analytical techniques to security telemetry, including baselining, outlier detection, clustering, time-series analysis, behavioral scoring, or graph-based analysis. * Experience using AI-assisted development tools with validation, testing, reproducibility, and secure coding practices in analytics, automation, or detection development workflows. * Bachelor's degree or higher in Computer Science, Cybersecurity, Information Security, Engineering, Data Science or related field or equivalent combination of education, related experience and/or military experience. Experience that would be great to have: * Experience with Google SecOps or Chronicle detection content development, data modeling, and telemetry analysis. * Experience integrating security tools through application programming interfaces (APIs) and building internal services, signal pipelines, or workflow automation solutions. * Familiarity with detection-as-code practices, including Git, continuous integration and continuous delivery (CI/CD), testing, and code review. * Relevant certifications such as GIAC Reverse Engineering Malware (GREM), GIAC Certified Forensic Analyst (GCFA), GIAC Certified Incident Handler (GCIH), GIAC Certified Intrusion Analyst (GCIA), GIAC Reverse Engineering Malware (GREM), CompTIA CySA+, Certified Information Systems Security Professional (CISSP), Certified Threat Hunting Professional (CTHP), Certified Threat Intelligence Analyst (CTIA), Certified Cloud Security Professional (CCSP), or equivalent cybersecurity certification., You must currently possess valid and unrestricted U.S. work authorization to be considered for this role. Individuals with temporary visas including, but not limited to, F-1 (OPT, CPT, STEM), H-1B, H-2, or TN, or any candidate requiring sponsorship, now or in the future, will not be considered for this role. ## Description As a Cyber Threat Hunter, you will serve as a senior individual contributor within Cyber Security Operations, building behavior-based detection capabilities that identify adversary activity before incidents become material. You will turn enterprise telemetry into high-confidence signals and durable detections using inside-out intelligence, data science, and AI-enabled development workflows. You will partner closely with detection engineering, security operations, and incident response teams in a cloud environment, with a primary focus on proactive detection development and signal engineering. What you'll do: * Build and maintain behavior-based detections that identify adversary activity through sequences, relationships, and deviations across identity, endpoint, cloud, network, and application telemetry. * Translate attacker techniques, malware behaviors, and adversary tradecraft into testable, explainable, and durable detection logic using a detection-as-code approach. * Define telemetry, enrichment, and normalization requirements needed to improve signal quality, close coverage gaps, and support scalable detection outcomes in a cloud environment. * Apply statistical methods, machine learning techniques, and Python-based analytical workflows to develop behavioral models, engineering features, and improve precision detection and operational actionability. * Validate suspicious behaviors using digital forensics and incident response methods to distinguish malicious activity from benign anomalies, misconfigurations, and expected operational patterns. * Partner with security operations, incident response, and detection engineering teams to operationalize detections with triage guidance, severity rationale, playbook alignment, and MITRE ATT&CK classification and coverage reporting. * Use external threat intelligence as prioritization context while ensuring detections are grounded in observable behavior and telemetry within the enterprise environment. * Responsibilities listed are not intended to be all-inclusive and may be modified as necessary., This role is on-site Monday through Friday. Fiserv considers in-person collaboration to be an essential part of this role as in-person office experience helps you with your overall onboarding experience and leads to stronger productivity. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [How Much FAANG Companies Actually Pay Software Engineers in 2025](https://www.wearedevelopers.com/magazine/230-how-much-faang-companies-actually-pay-software-engineers-in-2025) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)