Senior Threat Hunting And Incident Response Engineer

Snowbit by Coralogix

Gurugram District

On-site

INR 2,500,000 - 6,000,000

Full time

34 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Snowbit by Coralogix is seeking a Senior Threat Hunting & Incident Response Engineer to lead proactive hunts and log-based incident analysis across customer environments. You will contribute to detection engineering, reduce alert noise, and build agentic tooling to scale hunting across tenants.

The role emphasizes MITRE ATT&CK alignment, cross-tenant data challenges, and hands-on building of scalable detection and automation. Based in Gurugram, it offers office-based work near you.

Qualifications

  • 1.4–8 years in threat hunting, detection engineering, SOC analysis or DFIR.
  • At least two years in proactive hunting or detection content, not just triage.
  • Fluency in a log query language and multi-stage aggregations.
  • Experience shipping an agent, MCP server, or automation workflow.
  • Familiarity with MITRE ATT&CK as an analytic framework.
  • Proven incident analysis: timeline reconstruction and scoping.
  • Strong written communication and customer-facing reporting.
  • Ability to work across tenants with variable data quality.
  • This is a work-from-office role in Gurugram.

Responsibilities

  • Proactive threat hunting across cloud, identity, endpoints and network telemetry.
  • Translate threat intel and ATT&CK techniques into testable hunt hypotheses.
  • Build a reusable hunt library and environment-specific adaptations.
  • Write, tune and validate detection rules with clear guidance.
  • Perform log-based analysis during incidents and define evidence packages.
  • Turn hunts into agentic workflows and extend the orchestration layer.
  • Produce clear customer-facing analysis and feed gaps into improvements.
  • Mentor analysts on query technique and evidence handling.

Skills

Threat hunting
Detection engineering
Incident analysis
Written communication
Analytic discipline
Cross-tenant collaboration
AI-assisted tooling
MITRE ATT&CK knowledge
Cloud / Kubernetes experience

Tools

Dataprime
KQL
SPL
Lucene
SQL
MCP server
LLM-driven enrichment

Job description

Job Description:

Job Description

Snowbit is a cybersecurity technology innovator with a vision to empower organizations across the globe to quickly, efficiently, and cost-effectively ready themselves to address omnipresent cyber risk. Built off years of Israeli cybersecurity experience, Snowbit is looking to offer the broadest managed detection and response offering available today. Snowbit is part of the Coralogix group, with Coralogix rebuilding the path to observability by offloading the burden of indexing and providing deep insights, at an infinite scale, for less than half the cost.

Snowbit is looking for an experienced Senior Threat Hunting & Incident Response Engineer to join our Managed Detection and Response (MDR) team. This role requires expertise in incident response, threat hunting, with a strong emphasis on cloud environments and Kubernetes. You will lead efforts to protect our customers from advanced cyber threats while contributing to the continuous improvement of Snowbit's methodologies, processes, and technology stack.

Role snapshot

We are hiring a senior engineer to run proactive threat hunts and deliver log-based incident analysis across our customers Coralogix environments. The role sits in the Threat Detection & Response (TDR) team and exists because hunt coverage is constrained by analyst hours, not by data. We are closing that gap by building agentic hunting capability, so this hire both hunts and builds the systems that hunt.

About the team

TDRs scope is threat hunting, incident response support and threat intelligence. We own detection engineering and proactive hunting rather than queue-driven alert triage. This is a build-and-investigate role, where the work is forming the hypothesis, proving or disproving it in the data, and turning what we learn into durable detection logic.

We work across multiple customer Coralogix tenants, each with its own log sources, naming conventions and data quality. A hunt written once has to be adapted, validated and re-run per environment, which is where most of the craft lives.


Requirements
What youll do

The role splits roughly 40% proactive hunting, 25% detection engineering, 20% incident analysis support and reporting, and 15% building the agentic tooling that makes the first three scale. That mix shifts during active customer incidents.

Proactive threat hunting
  • Develop and run hypothesis-driven hunts across cloud, identity, endpoint and network telemetry in customer Coralogix tenants.
  • Translate threat intelligence, MITRE ATT&CK techniques and post-incident lessons into testable hunt hypotheses with defined data requirements and success criteria.
  • Build and maintain a reusable hunt library so a hunt proven in one environment can be re-run in another with known adaptations.
  • Establish baselines for normal behaviour per environment and identify the deviations worth escalating.
Detection engineering
  • Write, tune and validate detection rules and alert definitions, with documented logic, expected false-positive profile and response guidance.
  • Measure detection coverage against ATT&CK and close the gaps that matter most for each customers threat profile.
  • Reduce alert noise by improving rule precision rather than raising thresholds, and evidence the improvement.
Incident response support
  • Perform log-based analysis during customer incidents: reconstruct timelines, scope affected identities and assets, and establish what the evidence does and does not support.
  • Identify indicators of compromise and pivot across data sources to find related activity.
  • Hand the customers IR team a defensible evidence package and clear, prioritised recommendations.
Building agentic threat hunting
  • Turn manual hunts into agentic ones: encode a hypothesis, its queries, its pivots and its scoring into a workflow that runs repeatedly across tenants without an analyst driving each step.
  • Build and extend the orchestration layer (specialist agents per log source, a correlation layer that links findings across identity, cloud and network telemetry, and a customer context layer that keeps each tenants baselines distinct).
  • Connect models to security data through MCP servers and clients, and package repeatable procedures as reusable skills the whole team can run.
  • Define the human checkpoints: what an agent may do unattended, what requires analyst verification before it reaches a customer, and how every finding traces back to source evidence.
  • Evaluate the system over time (false positives, unsupported conclusions, query and prompt drift) and improve it against that evidence rather than impressions.
Reporting and enablement
  • Produce customer-facing analysis reports in clear, non-sensational language that distinguishes confirmed findings from assessments.
  • Feed detection and logging gaps found during hunts back into onboarding and coverage recommendations.
  • Mentor less experienced analysts on query technique, evidence handling and analytic rigour.
What youll need
  • 1.4 – 8 years in threat hunting, detection engineering, SOC analysis or DFIR, with at least two spent on proactive hunting or detection content rather than queue triage alone.
  • 2.Fluency in a log query language - Dataprime, KQL, SPL, Lucene, SQL or equivalent. You should be able to write multi-stage aggregations, joins and time-window correlations without reaching for a template.
  • 3.You build with AI, not just alongside it. You have shipped something real (an agent, an MCP server or client, a tool-calling workflow, an LLM-driven enrichment or triage pipeline) and you can explain where it worked, where it failed and how you knew the difference. If you have automated a hunt or an investigation this way, lead with it.
  • 4.Working command of MITRE ATT&CK as an analytic tool: mapping observed behaviour to techniques, and reasoning about coverage gaps, not just tagging rules after the fact.
  • 5.Demonstrable incident analysis experience: timeline reconstruction, scoping, pivoting across sources, and separating what the evidence proves from what it suggests.
  • 6.Written communication that stands up to customer scrutiny. You will write reports read by security leaders and sometimes by auditors. Clarity, accurate hedging and no unearned certainty.
  • 7.Analytic discipline, you state your confidence level, you note what would disprove your hypothesis, you verify AI-generated conclusions against source data, and you are comfortable concluding that nothing was found.
  • 8.Comfort working across multiple tenants with inconsistent data quality, partial log coverage and no ability to change the source systems.
  • 9.This is a work from Office role in Gurugram.
Cultural Fit

We're seeking candidates who are hungry, humble, and smart. Coralogix fosters a culture of innovation and continuous learning, where team members are encouraged to challenge the status quo and contribute to our shared mission. If you thrive in dynamic environments and are eager to shape the future of observability solutions, we'd love to hear from you.

Coralogix is an equal opportunity employer and encourages applicants from all backgrounds to apply.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Threat Hunting & Incident Response Engineer
Senior Threat Hunting & Incident Response Engineer

Coralogix • Gurugram District

On-site
INR 1,800,000 - 3,200,000
Senior Threat Hunting & Incident Response Engineer
Senior Threat Hunting & Incident Response Engineer

Coralogix, inc. • Gurugram District

On-site
INR 900,000 - 1,300,000
PARTNER CONSULTANT - Threat hunting
PARTNER CONSULTANT - Threat hunting

Happiest Minds Technologies • Dadri

On-site
INR 3,000,000 - 5,000,000
Threat Hunter
Threat Hunter

JUARA IT SOLUTIONS • Chennai District

On-site
INR 900,000 - 1,300,000
Senior Threat Hunter
Senior Threat Hunter

Palo Alto Networks • Bengaluru

On-site
INR 2,800,000 - 4,200,000
Disability accommodations
Global team collaboration
Senior Associate - Threat Hunting
Senior Associate - Threat Hunting

NPCI • Hyderabad

On-site
INR 900,000 - 1,300,000
Threat Hunting Analyst
Threat Hunting Analyst

Network Intelligence India • Bengaluru

On-site
INR 800,000 - 1,500,000
Senior Associate Threat Intelligence
Senior Associate Threat Intelligence

NPCI • Hyderabad

On-site
INR 900,000 - 1,500,000
Insurance & Wellness program
Relocation & Mobility benefits
Home loan support
Senior Cybersecurity Incident Response Specialist
Senior Cybersecurity Incident Response Specialist

Metmox • Hyderabad

On-site
INR 2,400,000 - 3,800,000
Sr SUPPORT ENGINEER - Cyber Security
Sr SUPPORT ENGINEER - Cyber Security

Happiest Minds Technologies • Dadri

On-site
INR 800,000 - 1,500,000