Advanced Threat Hunting

PwC India

Mumbai

On-site

INR 1,200,000 - 2,400,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

PwC India is seeking an experienced threat hunter to develop and execute hypothesis-driven campaigns across enterprise infrastructure. You will design MITRE ATT&CK-aligned frameworks and translate threat intel into actionable detections and runbooks.

The role requires hands-on expertise in threat hunting, log and network forensics, and mentoring SOC analysts. Collaboration with SOC, IR, and TI teams is essential to success.

Qualifications

  • Hands-on experience in advanced threat hunting and incident response.
  • Proven expertise in hypothesis-driven threat hunting methodologies.
  • Strong understanding of MITRE ATT&CK framework and threat actor TTPs.
  • Advanced proficiency with threat hunting tools like Splunk, Elasticsearch, Wireshark, Zeek, osquery.
  • Deep knowledge of Windows, Linux, and network forensics.
  • Experience with log analysis, packet analysis, and endpoint artifacts.

Responsibilities

  • Develop hypothesis-driven threat hunting campaigns across enterprise infrastructure.
  • Design threat hunting frameworks aligned with MITRE ATT&CK methodology.
  • Conduct deep forensic analysis using logs, network traffic, and system artifacts.
  • Build detection queries and signatures for identified threats and TTPs.
  • Collaborate with SOC, incident response, and threat intelligence teams.
  • Create threat hunting runbooks and operationalize findings.
  • Mentor SOC analysts on advanced hunting techniques and methodologies.
  • Deliver insights and recommendations to stakeholders.

Skills

Threat hunting
Incident response
MITRE ATT&CK knowledge
Log analysis
Forensics
Analytical thinking
Scripting (Python/PowerShell)

Tools

Splunk
Elasticsearch
Wireshark
Zeek
osquery

Job description

Key Responsibilities
  • Develop and execute hypothesis-driven threat hunting campaigns across enterprise infrastructure
  • Design threat hunting frameworks aligned with MITRE ATT&CK methodology
  • Formulate actionable hypotheses based on threat intelligence and attack vectors
  • Conduct deep forensic analysis using logs, network traffic, and system artifacts
  • Build detection queries and signatures for identified threats and TTPs (Tactics, Techniques, Procedures)
  • Collaborate with SOC, incident response, and threat intelligence teams
  • Create threat hunting runbooks and operationalize hunting findings
  • Analyze and profile attacker behaviors, attack chains, and persistence mechanisms
  • Deliver threat hunting insights and recommendations to stakeholders and leadership
  • Mentor and train SOC analysts on advanced hunting techniques and methodologies
  • Participate in incident investigations requiring specialized hunting skills
  • Maintain and update threat models based on emerging threats and industry trends
Required Qualifications
  • 3-7 years of hands-on experience in advanced threat hunting and incident response
  • Proven expertise in hypothesis-driven threat hunting methodologies
  • Strong understanding of MITRE ATT&CK framework and threat actor TTPs
  • Advanced proficiency with threat hunting tools (Splunk, Elasticsearch, Wireshark, Zeek, osquery)
  • Deep knowledge of Windows, Linux, and network-level forensics
  • Experience with log analysis, packet analysis, and endpoint artifacts
  • Understanding of attack chains, lateral movement, and data exfiltration techniques
  • Proficiency in query languages (SPL, KQL, YARA rules, regular expressions)
  • Strong analytical and investigative skills with attention to detail
Desired Skills
  • GIAC Certified Incident Handler (GCIH) or GIAC Certified Intrusion Analyst (GCIA)
  • Certified Threat Intelligence Professional (CTIP) or equivalent
  • Scripting proficiency (Python, PowerShell, Bash) for data processing and automation
  • Experience with threat intelligence platforms and frameworks
  • Knowledge of C2 frameworks, malware analysis, and reverse engineering
  • Hands-on experience with EDR platforms (CrowdStrike, Carbon Black, Defender)
  • Cloud infrastructure security hunting (AWS, Azure, GCP)
  • Threat modeling and risk assessment expertise
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Threat Hunting Specialist
Threat Hunting Specialist

Terralogic • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Threat Hunting Analyst
Threat Hunting Analyst

Network Intelligence India • Bengaluru

On-site
INR 800,000 - 1,500,000
Cyber Threat Hunter Professional
Cyber Threat Hunter Professional

Conduent • Navi Mumbai

On-site
INR 1,000,000 - 1,500,000
Senior Threat Hunter
Senior Threat Hunter

UST • Bengaluru

On-site
INR 1,800,000 - 2,800,000
Threat Hunter
Threat Hunter

JUARA IT SOLUTIONS • Chennai District

On-site
INR 900,000 - 1,300,000
Lead Threat Intelligence Analyst
Lead Threat Intelligence Analyst

Providence India • Hyderabad

On-site
INR 3,000,000 - 6,000,000
Senior Associate - Threat Hunting
Senior Associate - Threat Hunting

NPCI International • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Comprehensive medical, accidental, and life insurance
On-site medical center and mental wellness support
Inclusive parental leave
+3
Senior Cyber Threat Hunter [T500-28455]
Senior Cyber Threat Hunter [T500-28455]

ADM • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Threathunting Lead
Threathunting Lead

airtel • Gurugram District

On-site
INR 3,500,000 - 5,200,000
Threat Hunting Sr. Analyst
Threat Hunting Sr. Analyst

METRO Global Solution Center IN • Maharashtra

On-site
INR 1,200,000 - 1,800,000