Role description
Senior Threat Hunter
CyberProof is a cyber security services and platform company whose mission is to help our customers react faster and smarter - and stay ahead of security threats, by creating secure digital ecosystems. CyberProof automates processes to detect and prioritize threats early and respond rapidly and decisively.
CyberProof is part of the UST Global family. Some of the world's largest enterprises trust us to create and maintain secure digital ecosystems using our comprehensive cyber security platform and mitigation services.
CyberProof is looking for a talented Senior Threat Hunter with strong expertise in development (Jupyter Notebook, Python) who will be part of our growing managed services group, which monitors, investigates, and resolves security incidents, violations, and suspicious activities. This role is ideal for someone who approaches threat hunting not only as an investigation, but also should be able to develop customized tools, data enrichment and automated frameworks.
The candidate will be responsible for developing, optimizing, and maintaining custom Jupyter based hunting environments that enable scalable, repeatable, and automated investigations across large telemetry datasets.
Responsibilities:
1) Continuously research latest threat trends, APT campaigns, and emerging TTPs to develop hypothesis-driven hunt packages mapped to MITRE ATT&CK.
2) Proactively drive hunting and analysis against the available dataset from various sources including, network, endpoint, and cloud environments to look for indicators of security breaches.
3) Develop advanced Jupyter Notebook frameworks that supports hunt execution, data enrichment and validation.
4) Develop reusable Python modules and APIs that extend Jupyter s capabilities for hunting automation in large scale, enrichment and result processing.
5) Build and maintain data pipelines and automation logic to integrate threat hunting workflows with multiple telemetry and threat intel sources.
6) Automate and schedule hunting notebooks through Azure ML pipelines, jobs, or equivalent orchestration frameworks, ensuring regular execution of hunting tasks.
7) Implement data validation, normalization, and correlation layers to ensure hunting accuracy.
8) Create structured reporting and visualization components using python libraries like pandas, jinja2.
9) Collaborate closely with the Use Case Management, Threat Intelligence and Detection Engineering teams to identify detection gaps observed during hunts.
10) Generate weekly, monthly, and ad-hoc threat hunting reports summarizing hypotheses, observations, and notable findings.
Requirements:
1) Bachelor s degree in Cybersecurity, Information Technology, Computer Science, or a related field (or equivalent experience).
2) Proven experience of 5+ years as Cyber Threat Hunter, Detection Engineering, or Incident Response, including high skills in forensics and investigation of network, endpoint and cloud logs.
3) Deep and proven knowledge and understanding of TTPs, attack frameworks (e.g., MITRE ATT&CK), and advanced threat actors.
4) Experience with security applications such as datalake, SIEM tools and EDR platforms.
5) Deep and proven knowledge of operating systems essentials including Linux/Unix and Windows.
6) Experience analyzing network traffic, packet captures, and log data.
7) Proven skills on Hunting on Cloud assets - AWS, GCP, Azure.
8) Proven ability to design, develop and maintain threat hunting notebooks along with analyzing and identifying anomalies from the hunt outcome.
9) Strong understanding of Python libraries commonly used in data science, such as Pandas, and MsticPY.
10) Advantageous to have in-depth knowledge of Jupyter Notebooks and experience in utilizing them for data analysis, visualization, and prototyping.
11) Understanding modern software development lifecycles and CI/CD pipeline technologies to effectively hunt for threats and analyze security risks within automated environments.
12) Experience building tooling or automation layers around detection content validation, rule deployment, or telemetry analysis pipelines.
13) Critical thinking, problem-solving skills and innovative way of thinking.
14) Excellent communication skills to explain technical findings to both technical and non-technical audiences.
15) Excellent organization, time management, and attention to detail.
16) Prior experience integrating Jupyter workflows with Cybereason, Sentinel, Defender, Crowdstrike,or other telemetry sources is a plus.
Relevant certification (e.g., GIAC GCIH, GCFA, GREM, OSCP, CEH) is an advantage.
Skills
threat hunting,threat intelligence,mitre att&ck,malware analysis,security governance,
About UST
UST is a global digital transformation solutions provider. For more than 20 years, UST has worked side by side with the world’s best companies to make a real impact through transformation. Powered by technology, inspired by people and led by purpose, UST partners with their clients from design to operation. With deep domain expertise and a future-proof philosophy, UST embeds innovation and agility into their clients’ organizations. With over 30,000 employees in 30 countries, UST builds for boundless impact—touching billions of lives in the process.