Threat Hunting Consultant

Jobgether

India

Remote

CAD 152,000 - 180,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Remote work from India

Job summary

Jobgether and a Canada-based partner seek a Threat Hunting Consultant to strengthen enterprise security through proactive threat hunting, detection engineering, and incident response. You will investigate threats across endpoint, identity, network, and security analytics environments, leveraging Defender, Splunk, and threat intel to identify attacker activity.

Develop high-fidelity detections and automation with PowerShell/Python, translate threat intel into actionable detections, and mentor

Qualifications

  • 5+ years of threat hunting, detection engineering, incident response, or closely related security discipline.
  • Extensive hands-on experience with Microsoft Defender for Endpoint and Microsoft 365 Defender/XDR security operations.
  • Expert-level experience with Splunk Enterprise Security and advanced SPL for threat hunting, correlation, and investigations.
  • Experience with Splunk UBA or comparable behavioral analytics platforms.

Responsibilities

  • Conduct hypothesis-driven threat hunts across endpoints, identity, network, and analytics to uncover malicious activity.
  • Use Defender for Endpoint, Defender/XDR, Splunk ES, and related platforms to investigate activity and attacker behaviors.
  • Develop high-fidelity detection rules, correlation searches, and hunting queries with KQL and SPL.
  • Apply MITRE ATT&CK framework to guide hunting, detection, and defensive improvements.
  • Perform incident response, endpoint forensics, malware analysis, and technical investigations.

Skills

Threat hunting
Detection engineering
Incident response
Splunk
KQL
PowerShell
Python
MITRE ATT&CK
Windows internals
Active Directory/Azure AD

Tools

Splunk Enterprise Security
Splunk UBA
PowerShell
Python

Job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Threat Hunting Consultant based in Canada.

This role offers the opportunity to strengthen enterprise security through proactive threat hunting, advanced detection engineering, and incident response. You will investigate sophisticated threats across endpoint, identity, network, and security analytics environments. The position combines hands-on technical investigation with the development of high-fidelity detections and defensive capabilities. You will leverage Microsoft Defender, Splunk, behavioral analytics, and threat intelligence to identify and disrupt attacker activity. Your work will help reduce false positives, improve detection coverage, and strengthen incident response readiness. You will collaborate with security teams while contributing expertise, documentation, training, and mentoring in a security-focused environment.

Accountabilities
  • Conduct hypothesis-driven threat hunts across endpoint, identity, network, and security analytics environments to uncover malicious activity and previously undetected threats.
  • Use Microsoft Defender for Endpoint, Microsoft 365 Defender/XDR, Splunk Enterprise Security, Splunk UBA, and related platforms to investigate suspicious activity and identify attacker behaviors.
  • Develop and refine high-fidelity detection rules, correlation searches, and threat-hunting queries using KQL and SPL while minimizing false positives.
  • Apply the MITRE ATT&CK framework and current attacker TTPs to guide threat-hunting activities, detection coverage, and defensive improvements.
  • Perform incident response, endpoint forensics, malware analysis, and technical investigations to determine the scope, impact, and root cause of security incidents.
  • Translate threat intelligence into actionable detection logic, hunting hypotheses, response procedures, and other defensive measures.
  • Analyze Windows systems, processes, Active Directory, Azure AD, Kerberos, NTLM, network protocols, traffic patterns, and common attack vectors during investigations.
  • Develop and improve incident response playbooks and automation using PowerShell and/or Python to increase investigation and response efficiency.
  • Document findings, investigative procedures, detection logic, and security recommendations while communicating technical insights clearly to stakeholders.
  • Support security capability development through knowledge sharing, training, mentoring, and continuous improvement of threat detection and response practices.
Requirements
  • 5+ years of relevant experience in threat hunting, detection engineering, incident response, cybersecurity operations, or a closely related security discipline.
  • Extensive hands-on experience with Microsoft Defender for Endpoint and strong knowledge of Microsoft 365 Defender/XDR security operations.
  • Expert-level experience with Splunk Enterprise Security, including advanced SPL for threat hunting, correlation, and security investigations.
  • Experience with Splunk UBA or comparable behavioral analytics platforms.
  • Advanced proficiency in Kusto Query Language (KQL) and strong ability to develop sophisticated hunting and detection queries.
  • Proven experience conducting hypothesis-driven threat hunts and identifying sophisticated attacker behaviors and TTPs.
  • Strong understanding of the MITRE ATT&CK framework and practical knowledge of modern attack techniques.
  • Demonstrated ability to develop high-fidelity detection rules with strong detection coverage and low false-positive rates.
  • Hands-on experience with incident response, endpoint forensics, malware analysis, and security investigations.
  • Knowledge of NIST and SANS incident response frameworks and experience developing or maintaining response playbooks.
  • Strong understanding of Windows internals, processes, security architecture, Active Directory, Azure AD, Kerberos, and NTLM.
  • Knowledge of network protocols, traffic analysis, common attack vectors, and network-based indicators of compromise.
  • Scripting and automation experience using PowerShell and/or Python.
  • Strong analytical, problem-solving, documentation, communication, training, and mentoring skills.
Benefits
  • Annual salary range of $110,000-$130,000.
  • Full-time opportunity focused on advanced cybersecurity, threat hunting, and detection engineering.
  • Remote work environment with flexibility to collaborate from India.
  • Opportunity to work with leading security technologies including Microsoft Defender, Splunk Enterprise Security, and behavioral analytics platforms.
  • Exposure to complex security investigations, enterprise-scale threat detection, incident response, and security automation.
  • Opportunities to contribute to security strategy, knowledge sharing, training, and technical mentoring.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Specialist – Attack Surface Reduction
Information Security Specialist – Attack Surface Reduction

Jobtailor • Toronto

On-site
CAD 120,000 - 160,000
Incident Response Senior Consultant
Incident Response Senior Consultant

Jobgether • Canada

Remote
CAD 100,000 - 165,000
Remote work opportunity
Equity opportunities
Professional development
Threat Analyst 3
Threat Analyst 3

Sophos Group • Canada

On-site
CAD 74,000 - 123,000
Threat hunting practise Leader
Threat hunting practise Leader

National Bank of Canada • Montreal (administrative region)

Hybrid
CAD 80,000 - 120,000
Personalized training programs
Flexible working environment
Coaching and mentoring support
Security Analyst
Security Analyst

Fluid - Solutions de Talents/Workforce Solutions • Montreal (administrative region)

On-site
CAD 89,000 - 123,000
Cyber Use Case Developer
Cyber Use Case Developer

United States Digital Space LLC • Toronto

Hybrid
CAD 65,000 - 105,000
Senior Associate, Information Security
Senior Associate, Information Security

Publicis Groupe Holdings B.V • Toronto

On-site
CAD 100,000 - 120,000
Cybersecurity - Cyber Managed Services (Security Operations Analyst) - Consultant
Cybersecurity - Cyber Managed Services (Security Operations Analyst) - Consultant

EY • Dieppe

On-site
CAD 59,000 - 89,000
Microsoft Defender Lead — Security Architect & Threat Hunter
Microsoft Defender Lead — Security Architect & Threat Hunter

Mnp Llp • Burlington

Hybrid
CAD 70,000 - 85,000
MyRewards@MNP
Senior Information Security Analyst
Senior Information Security Analyst

IKO North America • Mississauga

On-site
CAD 106,000 - 120,000
Competitive compensation
Health care
Challenging workplace
+1