> Markdown version of [/jobs/ext/472613-senior-engineer-threat-hunting](https://www.wearedevelopers.com/jobs/ext/472613-senior-engineer-threat-hunting). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Engineer - Threat Hunting - **Company:** Cboe Exchange, Inc. - **Location:** Chicago, IL, United States - **Experience:** Expert - **Salary:** $130,900.0 - $169,400.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Software as a Service, Cloud Computing Security, Cyber Security, Linux, Intrusion Detection and Prevention, Log Analysis, Microsoft Security Essentials, Security Information and Event Management, Information Technology, Cybercrime - **Published:** June 5, 2026 - **Apply:** https://cboe.wd1.myworkdayjobs.com/External_Career_CBOE/job/Chicago-IL/Senior-Engineer---Threat-Hunting_R-4467 ## About the Role * 5-8+ years of experience in cybersecurity operations, detection engineering, threat hunting, or offensive security * Deep expertise in attacker tradecraft, adversary behaviors, and defensive detection techniques across multiple domains * Strong hands-on experience with SIEM, EDR, cloud security platforms, and large-scale log analytics (Google SecOps, Defender XDR, Crowdstrike) * A proven ability to solve ambiguous, systemic, cross-organizational security problems with minimal direction * Experience balancing hands-on execution with strategic influence, knowing when to build directly and when to enable others * The ability to operate with near-complete autonomy, setting technical direction rather than receiving it * Strong communication skills, including the ability to explain complex technical risk to senior security and technology leaders * Bachelor's degree or equivalent practical experience * Proficiency in scripting and automation for security operations. You'll really stand out with: * Bachelor's Degree in Cybersecurity or Computer Science * System Administration experience in Windows or Linux * Proven ability to script and automate tasks * Specific experience with Google Secops SIEM, the Microsoft Security Stack, or ProofPoint Email Security Services * CISSP, CASP or other related security certifications ## Description The Senior Engineer Threat Hunting will be a senior individual contributor within Cboe's Security Operations organization, responsible for defining, advancing, and executing the enterprise approach to detection engineering, threat hunting, and adversary emulation. This role focuses on building and maturing detection capabilities across platforms such as SIEM, EDR, identity, cloud, and SaaS environments, ensuring detections are resilient, scalable, and aligned to real-world adversary behavior. The Senior Engineer Threat Hunting will lead complex, hypothesis-driven threat hunts, partner closely with stakeholders to design and execute adversary emulation scenarios, and translate findings into durable detections, improved telemetry, and architectural enhancements. This individual will also serve as a technical lead during the most complex or high-severity security incidents, shaping investigative approach and long-term defensive improvements. In this role you'll be responsible for: * Owning the enterprise detection engineering capability end-to-end, including standards, patterns, quality bars, and long-term technical direction * Designing, implementing, and reviewing high-fidelity detections across endpoint, identity, cloud, network, and SaaS environments * Leading complex, hypothesis-driven threat hunts that address ambiguous, cross-organizational risk and novel attacker behavior * Translating threat hunting outcomes into robust detections, improved telemetry, or architectural changes rather than one-off findings * Partnering with internal stakeholders to design and execute adversary emulation scenarios that validate real-world detection and response effectiveness * Identifying systemic detection and response gaps and driving remediation across engineering, operations, and architecture teams * Acting as the technical lead during highest-severity incidents, guiding investigative approach and defensive improvements * Influencing security strategy, roadmaps, and investment decisions by translating technical findings into business and risk context * Provide expert recommendations and best practices to security managers, technical managers, and stakeholders including legal and regulatory teams. * Mentoring senior engineers and analysts and setting the technical bar for excellence across detection, hunting, and adversary emulation * Stay current with industry trends, security standards, and best practices to ensure our systems remain secure against evolving threats., At Cboe, we are committed to providing a competitive, transparent, and market-informed total rewards program. The anticipated base salary range for this role is $130,900-$169,400, with actual compensation determined by job-related factors such as skills, relevant experience, education, internal alignment, and location. This role may also be eligible for annual incentive compensation and, where applicable, participation in Cboe's long-term equity programs. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Progressive Delivery in Kubernetes](https://www.wearedevelopers.com/videos/949-progressive-delivery-in-kubernetes) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Leveraging Large Language Models for Legacy Code Translation: Challenges and Solutions](https://www.wearedevelopers.com/videos/1157-leveraging-large-language-models-for-legacy-code-translation-challenges-and-solutions) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)