Cyber Threat Hunting Analyst - Cyber Security & TSOC

FirstEnergy

Akron (OH)

On-site

USD 95,000 - 130,000

Full time

13 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Competitive pay
401(k) with matching
Tuition reimbursement

Job summary

FirstEnergy, headquartered in Akron, Ohio, is seeking an experienced Threat Hunter to proactively identify vulnerabilities and strengthen security operations. You will collaborate with SOCs, analyze TTPs, and produce detailed reports for stakeholders while researching IOCs and advisories to reduce noise and improve defenses.

The role requires strong programming knowledge, security expertise, and the ability to work independently within a dynamic team.

Qualifications

  • Bachelor's degree in computer science, Information Security, or similar discipline is required with 1 to 3 years of experience.
  • Industry standard certifications will be considered such as OSCP, GIAC (GCTI, GCIH, GREM, GCFA), CISSP and HTB CPTS.
  • A bachelor's degree in another field with 4 years relevant industry experience in cyber/information security will be considered.
  • In lieu of a degree, 3 years of related experience is required.
  • Related experience includes SOC experience, IT Security in detection, triage, investigation, and remediation of security incidents within a network.
  • Understanding of adversarial techniques (MITRE ATT&CK).
  • Understanding programming/scripting code (Python, PowerShell, Bash, C#).
  • Understanding of Linux and Windows operating systems.
  • Strong communication skills, both verbal and written.
  • Creative problem solving and solutioning.
  • Ability to work independently and in a team.
  • Ability to protect highly confidential information.
  • Ability to learn independently and from others.
  • Ability to find answers using open-sourced information.
  • Understanding of networking concepts and technologies.
  • Must be organized with changing priorities.
  • Must be able to work independently with minimal supervision.

Responsibilities

  • Proactively search for and identify vulnerabilities in the organization’s security systems.
  • Collaborate with the SOCs to convert intelligence into actionable defensive capabilities.
  • Evaluate intelligence sources and feeds for relevance, accuracy, timeliness, and operational value to reduce noise.
  • Analyze threat actors' TTPs and provide detailed technical reports for stakeholders.
  • Analyze threat reporting from OSINT, ISACs, and trusted industry partners.
  • Research and enrich IOCs including domains, IPs, URLs, hashes, certificates.
  • Monitor geopolitical events, vulnerabilities, and nation-state campaigns for impact
  • Act as a cybersecurity SME to support the SOC and advise on security solutions
  • Maintain expertise in log analysis, malware reverse engineering, memory forensics, telemetry, and analytics
  • Assist with incident response for operational and cybersecurity issues
  • Identify process improvements to advance security operations
  • Improve detections in SIEM, EDR, and SOAR by tuning content and creating new rules
  • Re-evaluate controls and advise on best practices
  • Research new capabilities from open and closed sources to enhance SOC ecosystem
  • Collaborate with cross-functional teams on cybersecurity projects
  • Educate stakeholders on security risks and infrastructure changes
  • Champion FE’s Core Values through leadership and example
  • Assist with metrics, reporting, and SOC communications
  • Share information with other FirstEnergy security teams

Skills

Python
PowerShell
Bash
C#
MITRE ATT&CK
Linux
Windows
Communication
Problem solving
Team collaboration

Education

Bachelor's degree in computer science or Information Security
OSCP
GIAC (GCTI, GCIH, GREM, GCFA)
CISSP
HTB CPTS
4+ years cyber/security experience

Tools

SIEM
EDR
SOAR

Job description

  • Understanding programming/scripting code (Python, PowerShell, Bash. C#)
Job Description
FirstEnergy at a Glance

We are a forward-thinking electric utility powered by a diverse team of employees committed to making customers’ lives brighter, the environment better and our communities stronger.

FirstEnergy (NYSE: FE) is dedicated to safety, reliability, and operational excellence. Headquartered in Akron, Ohio, FirstEnergy includes one of the nation's largest investor-owned electric systems, more than 24,500 miles of transmission lines that connect the Midwest and Mid-Atlantic regions, and a regulated generating fleet with a total capacity of 3,780 megawatts.

About The Opportunity

This position’s base reporting location is in Akron, Ohio, and reports to the Supervisor of Threat Hunting.

This position’s base reporting location is in Akron, Ohio, and reports to the Supervisor of Threat Hunting.

Responsibilities Include
  • Proactively search for and identify vulnerabilities in the organization’s security systems
  • Collaborate with the SOCs to convert intelligence into actionable defensive capabilities
  • Evaluate intelligence sources and feeds for relevance, accuracy, timeliness, and operational value to reduce unnecessary alerting and noise
  • Analyze threat actors' TTPs (Tactics, Techniques, and Procedures) to provide detailed technical reports with a high level of attention to detail for stakeholders, as well as assist in developing related content
  • Analyze threat reporting from commercial intelligence platforms, OSINT, government advisories, ISACs, and trusted industry partner
  • Research and enrich IOCs, including domains, IP addresses, URLs, file hashes, certificates, and adversary infrastructure
  • Monitor geopolitical events, vulnerabilities, cybercriminal activity, and nation-state campaigns for potential organizational impact
  • Act as a cybersecurity subject matter expert (SME) to support the SOC, providing consultancy and advice on the delivery of security solutions
  • Maintain a high level of expertise in log analysis, malware reverse engineering, memory forensics, network and endpoint telemetry, and behavioral analytics
  • Assist with incident response for operational and cybersecurity related issues
  • Identify process improvements to further advance security operations
  • Improve detections in SIEM, EDR, and SOAR platforms by fine-tuning existing content and developing new custom rules and alerts
  • Re-evaluate current controls and make recommendations for best practices based on new information received in an ever-evolving threat landscape
  • Research new capabilities from both open and closed sourced technologies to find opportunities to enhance the Security Operation Center (SOC) ecosystem
  • Participate with cross-functional team members in issue identification, process impacts and solution development for cybersecurity projects and initiatives
  • Educate and influence IT, Cyber Security and Business stakeholders to better understand existing security risks, best practices, and infrastructure designs/changes required to support business and IT strategies securely
  • Champions FE’s Core Values & Behaviors, through coaching and by personal example
  • Assist with metrics, reporting, and other SOC communications
  • Process and share information with other FirstEnergy security teams
Qualifications
  • Bachelor's degree in computer science, Information Security, or similar discipline is required with 1 to 3 years of experience
  • Industry standard certifications will be considered such as OSCP, GIAC (GCTI, GCIH, GREM, GCFA), CISSP and HTB CPTS
  • A bachelor's degree in another field with 4 years relevant industry experience in cyber/information security will be considered
  • In lieu of a degree, 3 years of related experience is required
  • Related experience includes but is not limited to: SOC (Security Operations Center) experience, IT Security experience in detection, triage, investigation, and remediation of security incidents within a network
  • Understanding of adversarial techniques (i.e., MITRE ATT&CK framework)
  • Understanding programming/scripting code (Python, PowerShell, Bash. C#)
  • Understanding of both Linux and Windows operating systems
  • Demonstrate strong communication skills, both verbal and written
  • Demonstrate creative problem solving and solutioning
  • Ability to work effectively, independently and within a team environment
  • Ability to handle, protect and preserve highly confidential information
  • Ability to learn independently and from others
  • Ability to find answers effectively using open-sourced information
  • Understanding of networking concepts and technologies
  • Must be organized and comfortable with ongoing changes in priorities
  • Must be able to work independently with minimal supervision
Level Qualifications

II - Qualifications at Level II include all the above, plus a minimum of 3 years professional experience in a cyber related function

  • Strong foundation in cyber security
  • Ability to create, detect, and enhance security content
  • Working knowledge of relevant experience

III - Qualifications at Level III include all the above, plus a minimum of 5 years professional experience in a cyber-related function. Experience and subject matter expert knowledge in at least one major discipline required

  • Demonstrable subject matter expert knowledge in Threat Emulation, Threat Hunting, or Threat Intelligence
  • Proven ability to mentor and guide others in creating, detecting, and enhancing security content
  • In-depth knowledge of relevant work experience
Benefits, Compensation & Workforce Diversity

At FirstEnergy, employees are key to our success. We depend on their talents to meet the challenges of our changing business environment. We are committed to rewarding individual and team efforts through our total rewards philosophy which includes competitive pay plus incentive compensation, a company-sponsored pension plan, 401(k) savings plan with matching employer contribution, a choice of medical, prescription drug, dental, vision, and life insurance programs, as well as skills development training with tuition reimbursement.

  • competitive pay plus incentive compensation
  • a company-sponsored pension plan
  • 401(k) savings plan with matching employer contribution
  • a choice of medical, prescription drug, dental, vision, and life insurance programs
  • skills development training with tuition reimbursement

Please visit our website at www.firstenergycorp.com to learn more about all of our employee rewards programs.

FirstEnergy proudly supports workforce diversity. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, sex, sexual orientation, gender identity, age, status as a protected veteran, or status as a qualified individual with a disability.

No recruiters or agencies without a previously signed contract. Unable to sponsor or transfer H-1B visas at this time.

Safety

Safety is a core value for FirstEnergy and is essential to all of our business activities. We ensure employees have the tools, information, and processes to perform their duties in a manner that assures safety for themselves, their co-workers, our customers and the public. Our goals are to provide a safe work environment, to maintain an accident‑free, injury‑free workplace, and to promote and maintain public safety. To meet these goals, we dedicate ourselves to achieving world‑class safety standards.

Position Classification

Exempt

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Threat Hunting Analyst - Cyber Security & TSOC
Cyber Threat Hunting Analyst - Cyber Security & TSOC

Socket.dev • Akron (OH)

On-site
USD 90,000 - 130,000
Competitive pay
Pension plan
401(k) with company match
+2
Cyber Threat Hunting Analyst - Cyber Security & TSOC
Cyber Threat Hunting Analyst - Cyber Security & TSOC

FirstEnergy Corp • Akron (OH)

On-site
USD 110,000 - 150,000
Supervisor Compliance Field Support & Physical Security - Corporate Security - Akron FirstEnergy Headquarters
Supervisor Compliance Field Support & Physical Security - Corporate Security - Akron FirstEnergy Headquarters

FirstEnergy • Akron (OH)

On-site
USD 110,000 - 160,000
Supervisor Compliance Field Support & Physical Security - Corporate Security - Akron FirstEnergy Headquarters
Supervisor Compliance Field Support & Physical Security - Corporate Security - Akron FirstEnergy Headquarters

FirstEnergy Corp • Akron (OH)

On-site
USD 110,000 - 150,000
Competitive pay
Pension plan
401(k) with matching employer contrib.
+2
Physical Security Field Representative II - Corporate Security - Akron, OH
Physical Security Field Representative II - Corporate Security - Akron, OH

FirstEnergy • Akron (OH)

On-site
USD 80,000 - 110,000
Competitive pay
Pension plan
401(k) with matching
+2
Physical Security Field Representative II - Corporate Security - Akron, OH
Physical Security Field Representative II - Corporate Security - Akron, OH

FirstEnergy Corp • Akron (OH)

On-site
USD 75,000 - 95,000
Administrative Support Specialist
Administrative Support Specialist

COMFORT SYSTEMS • Akron (OH)

On-site
USD 48,000 - 66,000
Employee Experience Specialist V
Employee Experience Specialist V

FirstEnergy • Akron (OH)

On-site
USD 90,000 - 120,000
Competitive pay and incentives
Pension plan and 401(k) with match
Medical, dental, vision and life保险
Safety Representative IV
Safety Representative IV

FirstEnergy • Cranberry Township

On-site
USD 75,000 - 95,000
401(k) savings plan with matching contributions
Medical, prescription drug, dental, and vision insurance
Tuition reimbursement and skills development training
Safety Representative V
Safety Representative V

FirstEnergy • Akron (OH)

On-site
USD 94,775 - 133,800
401(k) savings plan with matching employer contribution
Medical, dental, and vision insurance
Tuition reimbursement