> Markdown version of [/jobs/ext/3136067-cyber-security-threat-management-senior-associate](https://www.wearedevelopers.com/jobs/ext/3136067-cyber-security-threat-management-senior-associate). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Threat Management Senior Associate - **Company:** The Depository Trust & Clearing Corporation - **Location:** Tampa, FL, United States - **Experience:** Expert - **Contract:** Temporary contract - **Skills:** Microsoft Windows, Application Programming Interfaces (APIs), Amazon Web Services, Data Analysis, Microsoft Azure, Bash Shell, Cloud Computing, Apache Lucene, Cyber Security, Continuous Integration, Cron, Query Languages, Linux, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), CURL, Log Analysis, OAuth, Parsing, Windows PowerShell, Azure Active Directory, Red Team (Cyber Security), Kusto Query Language, Security Information and Event Management, Data Logging, Okta, Mitre Att&ck, Azure Security Center, Containerization, Kubernetes, Cybercrime, Microsoft Sentinel, Purple Team (Cyber Security), Kibana, Splunk, SentinelOne Expertise - **Published:** September 29, 2026 - **Apply:** https://ebxr.fa.us2.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX_1/requisitions/preview/214620 ## About the Role 3-6 years in Threat Hunting, Detection Engineering, Incident Response, or SOC investigations in a production environment (financial services/fintech experience is a plus but not required). Demonstrated experience running hypothesis-driven hunts and documenting outcomes in a way that supports repeatability and measurement. Strong log analysis skills and comfort working across multiple telemetry sources (endpoint, identity, network, cloud). Practical detection and query experience in one or more: KQL (Microsoft Sentinel / Defender) Splunk SPL Elastic/Kibana (EQL/KQL/Lucene) Chronicle/Google SecOps query language or equivalent Solid operating system fundamentals: Windows internals basics (process ancestry, services, scheduled tasks, registry persistence) Linux fundamentals (systemd, cron, auth logs, process/network inspection) Familiarity with attacker tradecraft and investigative methods aligned to MITRE ATT&CK; ability to map raw evidence to techniques without forcing it. Ability to communicate clearly-writeups that separate observation from inference, quantify confidence, and identify next steps. Proven ability to prioritize: know when you have enough evidence to escalate vs. when to keep iterating. Preferred Qualifications Experience hunting across cloud + containerized environments (AWS/Azure/GCP; Kubernetes; CI/CD telemetry). Experience developing or tuning detections using Sigma, YARA, EDR custom detections, or SIEM correlation rules. Familiarity with NIST CSF / NIST 800-61 incident response concepts and how hunting feeds detection/response maturity. Experience with SOAR automation, enrichment pipelines, and case management workflows. Certifications (any of the following are valued): GCFA, GCIH, GCIA OSCP (useful signal for investigative depth; not required) CISSP (helpful for program maturity context; not required) Comfortable scripting for analysis and automation (Python, PowerShell, Bash) and using tools like jq, osquery, CyberChef. Tools & Technologies You won't need every item day one-but you should be comfortable learning quickly and working across a modern stack. EDR/XDR: Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne (or equivalent) SIEM / Analytics: Microsoft Sentinel (KQL), Splunk (SPL), Elastic (EQL/KQL), Chronicle/Google SecOps Cloud & Identity: Azure/AWS logs, Entra ID/Azure AD, Okta (or equivalent), CloudTrail/Activity Logs, IAM telemetry Containers: Kubernetes audit logs, container runtime signals, registry, and CI/CD telemetry Detection Content: Sigma, YARA, ATT&CK mappings, custom IOAs, correlation rules Workflow: Case management, runbooks/playbooks, SOAR tooling, structured reporting, and metrics ## Description As a Threat Hunt Senior Associate, you will execute hypothesis-driven hunts across endpoint, identity, network, and cloud telemetry; track and document hunt activity end-to-end; and translate findings into actionable improvements, detections, response playbooks, hardening tasks, and prioritized engineering work. This role is hands-on and requires a practitioner mindset: you'll spend your time asking better questions of the data, validating what "normal" looks like in complex systems, and proving or disproving attacker behaviors using repeatable methods. You'll also provide surge support to incident response during investigations where hunt techniques accelerate containment and root cause analysis. This is a mid-level role for someone who can operate independently on scoped hunts, communicate clearly, and contribute to a sustained, measurable hunting program. Key Responsibilities Hunt Execution & Documentation (Core) Execute hypothesis-based threat hunts mapped to MITRE ATT&CK tactics/techniques, focusing on realistic adversary behaviors (credential access, persistence, lateral movement, defense evasion, and cloud abuse). Use behavioral analytics and anomaly detection to identify suspicious patterns across endpoint + identity + cloud + network telemetry, then validate with deeper artifact review. Perform, track, and record hunt activity in a structured way: hypotheses, datasets queried, query versions, findings (positive/negative), evidence, confidence, and follow-up actions. Maintain clean, audit-ready hunt notes that allow another analyst to reproduce your work and understand decisions made under uncertainty. Investigative Workflows & Telemetry Correlation Correlate logs across EDR/XDR, SIEM, cloud control plane logs, identity logs, and container/Kubernetes telemetry to build a coherent narrative from partial signals. Investigate attacker tradecraft such as: Credential theft and replay (token theft, OAuth abuse, suspicious refresh patterns) "Living off the land" execution (PowerShell, WMI, LOLBins on Windows; bash/curl/wget/systemd on Linux) Persistence mechanisms (scheduled tasks/cron, service modifications, registry run keys, launch agents) Command-and-control behaviors and egress anomalies (beaconing, domain fronting indicators, unusual TLS fingerprints where available) Cloud and Kubernetes abuse (suspicious role assumptions, unusual API call sequences, kubeconfig access, container escape precursors) Triage and deepen suspicious signals into defensible findings: timeline, scope, impact, root cause, and containment recommendations. Detection Engineering & Continuous Improvement Translate hunt results into durable controls: new detections, tuning improvements, telemetry onboarding, or gaps to address (instrumentation, logging coverage, parsing, enrichment). Draft and iterate detection logic (e.g., Sigma/YARA, SIEM analytics rules, EDR custom IOAs) with measurable success criteria: false-positive rate, time-to-detect improvements, and coverage mapped to ATT&CK. Partner with SOAR/automation engineers to operationalize repetitive enrichment and triage steps into playbooks. Purple Teaming & Adversary Simulation Collaborate with Red Team / Purple Team efforts to validate detection coverage, refine alerts, and ensure hunts align to current and relevant TTPs. Help design and execute controlled simulations (atomic tests, adversary emulation plans), then close the loop by updating detections, documentation, and response procedures. Incident Support (When Needed) Provide incident surge support: rapid scoping queries, hunting for related activity, identifying patient-zero candidates, and strengthening containment decisions with evidence. Contribute to post-incident reviews by identifying detection gaps, improving playbooks, and capturing lessons learned as backlog items., Run multiple scoped hunts end-to-end and document them to a reproducible standard (hypothesis * data sources * queries * findings * actions). Demonstrate strong signal-to-noise judgment: reduce false positives through evidence-based tuning, not guesswork. Produce at least a few measurable outcomes-new detections, improved parsers/enrichment, or closed telemetry gaps-that improve detection coverage. Build credibility with IR and engineering partners by bringing clear findings, not speculation, and by turning results into tractable follow-up work. By 6-12 months, you will: Consistently deliver ATT&CK-mapped hunt outcomes and contribute to a backlog that meaningfully improves coverage and response speed. Help mature the hunt program's operational rigor: tracking, metrics, documentation quality, and repeatable hunt playbooks. Be trusted to lead hunts on complex topics (cloud identity abuse, Kubernetes attack paths, cross-domain lateral movement) and mentor junior analysts informally through your writeups and methods. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [From clicks to cribs - How to find your dream home with web scraping](https://www.wearedevelopers.com/videos/767-from-clicks-to-cribs-how-to-find-your-dream-home-with-web-scraping) - [Don’t Insert Crazy! On cURL and AI Slop - Daniel Stenberg](https://www.wearedevelopers.com/videos/1796-don-t-insert-crazy-on-curl-and-ai-slop-daniel-stenberg) - [Capture the Flag 101](https://www.wearedevelopers.com/videos/416-capture-the-flag-101) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Is your backend a hodgepodge of queues, event stores and cron jobs? Durable Execution to the Rescue.](https://www.wearedevelopers.com/videos/744-is-your-backend-a-hodgepodge-of-queues-event-stores-and-cron-jobs-durable-execution-to-the-rescue) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)