Senior Threat Hunting & Incident Response Engineer

Coralogix

Gurugram District

On-site

INR 1,800,000 - 3,200,000

Full time

11 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Snowbit, part of the Coralogix group, seeks a Senior Threat Hunting & Incident Response Engineer for its MDR team. The role emphasizes cloud environments and Kubernetes, leading proactive hunts and enhancing detection logic across multi-tenant environments.

You will build agentic tooling, perform log-based analysis during incidents, and mentor analysts while translating MITRE ATT&CK techniques into practical hunts.

Qualifications

  • 4-8 years in threat hunting or DFIR, with proactive hunting or detection content experience.
  • Fluency in log query languages (Dataprime, KQL, SPL, Lucene, SQL) and ability to multi-stage aggregations.
  • Experience mapping to MITRE ATT&CK and identifying coverage gaps.
  • Strong incident analysis skills: timelines, scope, evidence evaluation.
  • Excellent written communication and ability to produce customer-facing reports.

Responsibilities

  • Proactive threat hunting across cloud, identity, endpoint and network telemetry.
  • Write, tune and validate detection rules with clear logic and response guidance.
  • Perform log-based incident analysis, reconstruct timelines and identify IOCs.
  • Build agentic hunting workflows and extend orchestration layers for repeatable hunts.
  • Produce customer-facing analysis and mentor junior analysts.

Skills

Threat hunting
Incident response
Cloud security
Kubernetes
MITRE ATT&CK
Log analysis

Tools

Dataprime
KQL
SPL
Lucene
SQL

Job description

Job Description

Snowbit is a cybersecurity technology innovator with a vision to empower organizations across the globe to quickly, efficiently, and cost-effectively ready themselves to address omnipresent cyber risk. Built off years of Israeli cybersecurity experience, Snowbit is looking to offer the broadest managed detection and response offering available today. Snowbit is part of the Coralogix group, with Coralogix rebuilding the path to observability by offloading the burden of indexing and providing deep insights, at an infinite scale, for less than half the cost.

About The Position

Snowbit is a cybersecurity technology innovator with a vision to empower organizations across the globe to quickly, efficiently, and cost-effectively ready themselves to address omnipresent cyber risk. Built off years of Israeli cybersecurity experience, Snowbit is looking to offer the broadest managed detection and response offering available today. Snowbit is part of the Coralogix group, with Coralogix rebuilding the path to observability by offloading the burden of indexing and providing deep insights, at an infinite scale, for less than half the cost.

Snowbit

Snowbit is looking for an experienced Senior Threat Hunting & Incident Response Engineer to join our Managed Detection and Response (MDR) team. This role requires expertise in incident response, threat hunting, with a strong emphasis on cloud environments and Kubernetes. You will lead efforts to protect our customers from advanced cyber threats while contributing to the continuous improvement of Snowbit's methodologies, processes, and technology stack.

Role snapshot

We are hiring a senior engineer to run proactive threat hunts and deliver log-based incident analysis across our customers' Coralogix environments. The role sits in the Threat Detection & Response (TDR) team and exists because hunt coverage is constrained by analyst hours, not by data. We are closing that gap by building agentic hunting capability, so this hire both hunts and builds the systems that hunt.

About The Team

TDR's scope is threat hunting, incident response support and threat intelligence. We own detection engineering and proactive hunting rather than queue-driven alert triage. This is a build-and-investigate role, where the work is forming the hypothesis, proving or disproving it in the data, and turning what we learn into durable detection logic. We work across multiple customer Coralogix tenants, each with its own log sources, naming conventions and data quality. A hunt written once has to be adapted, validated and re-run per environment, which is where most of the craft lives.

Requirements
What you'll do

The role splits roughly 40% proactive hunting, 25% detection engineering, 20% incident analysis support and reporting, and 15% building the agentic tooling that makes the first three scale. That mix shifts during active customer incidents.

Proactive threat hunting
  • Develop and run hypothesis-driven hunts across cloud, identity, endpoint and network telemetry in customer Coralogix tenants.
  • Translate threat intelligence, MITRE ATT&CK techniques and post-incident lessons into testable hunt hypotheses with defined data requirements and success criteria.
  • Build and maintain a reusable hunt library so a hunt proven in one environment can be re-run in another with known adaptations.
  • Establish baselines for normal behaviour per environment and identify the deviations worth escalating.
Detection engineering
  • Write, tune and validate detection rules and alert definitions, with documented logic, expected false-positive profile and response guidance.
  • Measure detection coverage against ATT&CK and close the gaps that matter most for each customer's threat profile.
  • Reduce alert noise by improving rule precision rather than raising thresholds, and evidence the improvement.
Incident response support
  • Perform log-based analysis during customer incidents: reconstruct timelines, scope affected identities and assets, and establish what the evidence does and does not support.
  • Identify indicators of compromise and pivot across data sources to find related activity.
  • Hand the customers' IR team a defensible evidence package and clear, prioritised recommendations.
Building agentic threat hunting
  • Turn manual hunts into agentic ones: encode a hypothesis, its queries, its pivots and its scoring into a workflow that runs repeatedly across tenants without an analyst driving each step.
  • Build and extend the orchestration layer (specialist agents per log source, a correlation layer that links findings across identity, cloud and network telemetry, and a customer context layer that keeps each tenant's baselines distinct).
  • Connect models to security data through MCP servers and clients, and package repeatable procedures as reusable skills the whole team can run.
  • Define the human checkpoints: what an agent may do unattended, what requires analyst verification before it reaches a customer, and how every finding traces back to source evidence.
  • Evaluate the system over time (false positives, unsupported conclusions, query and prompt drift) and improve it against that evidence rather than impressions.
Reporting and enablement
  • Produce customer-facing analysis reports in clear, non-sensational language that distinguishes confirmed findings from assessments.
  • Feed detection and logging gaps found during hunts back into onboarding and coverage recommendations.
  • Mentor less experienced analysts on query technique, evidence handling and analytic rigour.
What You'll Need
  • 4 - 8 years in threat hunting, detection engineering, SOC analysis or DFIR, with at least two spent on proactive hunting or detection content rather than queue triage alone.
  • Fluency in a log query language - Dataprime, KQL, SPL, Lucene, SQL or equivalent. You should be able to write multi-stage aggregations, joins and time-window correlations without reaching for a template.
  • You build with AI, not just alongside it. You have shipped something real (an agent, an MCP server or client, a tool-calling workflow, an LLM-driven enrichment or triage pipeline) and you can explain where it worked, where it failed and how you knew the difference. If you have automated a hunt or an investigation this way, lead with it.
  • Working command of MITRE ATT&CK as an analytic tool: mapping observed behaviour to techniques, and reasoning about coverage gaps, not just tagging rules after the fact.
  • Demonstrable incident analysis experience: timeline reconstruction, scoping, pivoting across sources, and separating what the evidence proves from what it suggests.
  • Written communication that stands up to customer scrutiny. You will write reports read by security leaders and sometimes by auditors. Clarity, accurate hedging and no unearned certainty.
  • Analytic discipline, you state your confidence level, you note what would disprove your hypothesis, you verify AI-generated conclusions against source data, and you are comfortable concluding that nothing was found.
  • Comfort working across multiple tenants with inconsistent data quality, partial log coverage and no ability to change the source systems.
  • This is a work from Office role in Gurugram.
Cultural Fit

We're seeking candidates who are hungry, humble, and smart. Coralogix fosters a culture of innovation and continuous learning, where team members are encouraged to challenge the status quo and contribute to our shared mission. If you thrive in dynamic environments and are eager to shape the future of observability solutions, we'd love to hear from you.

Coralogix is an equal opportunity employer and encourages applicants from all backgrounds to apply.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Threat Hunting And Incident Response Engineer
Senior Threat Hunting And Incident Response Engineer

Snowbit by Coralogix • Gurugram District

On-site
INR 2,500,000 - 6,000,000
Senior Threat Hunting & Incident Response Engineer
Senior Threat Hunting & Incident Response Engineer

Coralogix, inc. • Gurugram District

On-site
INR 900,000 - 1,300,000
Threat Hunting Analyst
Threat Hunting Analyst

Network Intelligence India • Bengaluru

On-site
INR 800,000 - 1,500,000
Threat Hunter
Threat Hunter

JUARA IT SOLUTIONS • Chennai District

On-site
INR 900,000 - 1,300,000
PARTNER CONSULTANT - Threat hunting
PARTNER CONSULTANT - Threat hunting

Happiest Minds Technologies • Dadri

On-site
INR 3,000,000 - 5,000,000
Senior Associate - Threat Hunting
Senior Associate - Threat Hunting

NPCI • Hyderabad

On-site
INR 900,000 - 1,300,000
Threat Analyst 2
Threat Analyst 2

Jobgether • India

Remote
INR 1,200,000 - 2,400,000
Remote-first working model
Exposure to wide security technologies
Collaborative security team
+2
Senior Threat Hunter
Senior Threat Hunter

Palo Alto Networks • Bengaluru

On-site
INR 2,800,000 - 4,200,000
Disability accommodations
Global team collaboration
Threat Hunting Sr. Analyst
Threat Hunting Sr. Analyst

METRO Global Solution Center IN • Maharashtra

On-site
INR 1,200,000 - 1,800,000
Cybersecurity Threat Hunter
Cybersecurity Threat Hunter

Broadway Global Services • Bengaluru

On-site
INR 400,000 - 700,000
Challenging role
Certification support
Growth opportunities
+2