Threat Hunter

Lintasarta

Jakarta Pusat

On-site

IDR 40,000,000 - 70,000,000

Full time

44 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Lintasarta is seeking a senior threat hunter to generate proactive, data-driven hypotheses, scrutinize telemetry across endpoints, cloud, and network, and build scalable analytics pipelines to detect subtle anomalies. You will map attacker techniques to MITRE ATT&CK, develop automated detection logic (SIEM rules, EDR watchlists, YARA/Sigma), and conduct post-incident analyses to drive permanent hardening.

Collaborate with security architecture and engineering to define log-ingestion policies,

Qualifications

  • 5–7+ years in cybersecurity roles.
  • 2–3 years threat-hunting in enterprise environments.

Responsibilities

  • Hypothesis generation: proactive data-driven threat hunting based on attacker behaviors and real-world threats.
  • Stealth adversary detection across endpoints, cloud, and network telemetry to isolate APTs and insider threats.
  • Data aggregation: build large-scale analytics pipelines and profile baselines to detect anomalies.
  • Operationalizing threat intel: ingest IoBs and map tactics to MITRE ATT&CK in detection logic.
  • Content development: translate discoveries into SIEM rules, EDR watchlists, and YARA/Sigma rules.
  • Root-cause analysis: post-incident forensics to identify architectural flaws and hardening mitigations.

Skills

Python
PowerShell
Go
SQL

Tools

Splunk SPL
KQL
Velociraptor
KAPE
Sigma
YARA
Jupyter

Job description


  • Hypothesis Generation: Develop and execute proactive, data-driven threat hunting hypotheses based on real-world attacker behaviors, emerging zero-days, and structural infrastructure risks.

  • Stealth Adversary Detection: Scrutinize telemetry data across endpoints, cloud microservices, and network traffic to isolate advanced persistent threats (APTs), living-off-the-land attacks, and insider threats.

  • Data Aggregation: Build, structure, and refine large-scale data analytics pipelines, profiling normal environmental baselines to catch subtle behavioral anomalies

  • Operationalizing Threat Intel: Analyze tactical threat intelligence, ingest Indicators of Behavior (IoBs), and map advanced persistent threat actor tactics directly to the MITRE ATT&CK framework.

  • Content Development: Translate successful threat hunting discoveries into long-term automated detection engineering logic (SIEM rules, EDR watchlists, YARA/Sigma rules).

  • Root-Cause Analysis: Conduct deep post-incident forensics on critical network events, uncovering structural architectural flaws to recommend permanent hardening mitigations.



Strategic Leadership & Knowledge Share


  • Architectural Advisory: Partner directly with security architecture, engineering, and infrastructure teams to design comprehensive log-ingestion policies and visibility maps.

  • Tier Elevation: Conduct technical knowledge-sharing workshops, table-top exercises, and write analytical documentation to upskill Tier-1 and Tier-2 analysts.



Technical Skills & Tools

Advanced Forensic Analytics & Data Science



  • Advanced SIEM & Data Lakes: Mastery of complex log manipulation, correlation, and statistical behavioral mapping using Splunk (SPL), Microsoft Sentinel (KQL), or custom Jupyter Notebook integrations.

  • Telemetry Extraction: Deep technical expertise pulling artifact footprints from memory spaces, master file tables (MFT), event logs, and kernel structures via tools like Velociraptor or KAPE.

  • Scripting & Tool Development: High proficiency in Python, PowerShell, Go, or SQL to query enterprise telemetry data, parse massive log sets, and automate hunting routines via APIs.

  • Cloud & Hybrid Expertise: Expert knowledge tracking identity perimeters and service-principal compromises across distributed AWS, Azure, or GCP environments.

  • Behavioral Detection Engineering: Mastery using standardized signature and rule syntaxes, specifically Sigma (for log detection) and YARA (for file/memory analysis).


Infrastructure & Behavioral Profiling



Experience & Qualifications


  • Total Security Experience: Minimum of 5–7+ years of dedicated technical experience in specialized cybersecurity domains, such as Digital Forensics and Incident Response (DFIR), Penetration Testing, or Advanced SOC operations.

  • Hunting Track Record: At least 2–3 years of proven, documented experience specifically conceptualizing and executing structured threat hunts in enterprise environments.



Preferred Professional Certifications


  • Advanced Cyber Defense:

  • GIAC Certified Forensic Analyst (GCFA)

  • GIAC Advanced Smartphone Forensics / Network Forensics (GNFA)

  • Offensive Security Certified Professional (OSCP)

  • eLearnSecurity Certified Threat Hunter (ECTHP)


Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT CYBERSECURITY
IT CYBERSECURITY

PT Dharma Satya Nusantara Tbk • Jakarta Timur

On-site
IDR 240,000,000 - 360,000,000
Threat Hunter & Incident Response Engineer
Threat Hunter & Incident Response Engineer

PT Cemerlang Tunggal Intikarsa (CTI Group Jakarta) • Jakarta Utara

On-site
IDR 400,000,000 - 700,000,000
Cyber Threat Intelligence Analyst
Cyber Threat Intelligence Analyst

Packet Systems Indonesia • Jakarta Pusat

On-site
IDR 180,000,000 - 360,000,000
Threat Hunter & Incident Response Engineer
Threat Hunter & Incident Response Engineer

Jedi Solutions • Jakarta Utara

On-site
IDR 200,000,000 - 500,000,000
Offensive Security Manager
Offensive Security Manager

INDODAX • Jakarta Selatan

On-site
Security Researcher
Security Researcher

PT ITSEC Asia Tbk • Jakarta Pusat

On-site
IDR 200,000,000 - 260,000,000
Manager, Defensive Security Operation
Manager, Defensive Security Operation

bank saqu • Indonesia

On-site
IDR 2,500,000,000 - 4,500,000,000
Platform Engineer
Platform Engineer

Lintasarta • Jakarta Pusat

On-site
IDR 884,799,000 - 1,946,558,000
Senior Threat Hunter & Detection Engineering Lead
Senior Threat Hunter & Detection Engineering Lead

Lintasarta • Jakarta Pusat

On-site
IDR 40,000,000 - 70,000,000
TC - SOC Cybersecurity Consultant Manager
TC - SOC Cybersecurity Consultant Manager

EY • Daerah Khusus Ibukota Jakarta

On-site