Cybersecurity Engineer – Threat Hunting & Security Validation

Cognizant

Blaine (MN)

On-site

USD 115,000 - 134,000

Full time

8 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Medical/Dental/Vision/Life Insurance
Paid holidays + PTO
401(k) plan

Job summary

Cognizant is seeking a Cybersecurity Analyst to advance threat hunting, security validation, and BAS capabilities. You will work with SOC, Incident Response, and Engineering teams to enhance threat detection and response.

Ideal candidates have hands-on Splunk experience and a solid grasp of MITRE ATT&CK, with 4–8 years in related roles and strong scripting skills in Python, PowerShell, or Bash.

Qualifications

  • 4-8 years of Cybersecurity, Threat Hunting, Security Operations, Detection Engineering, or Security Validation experience.
  • Hands-on experience with Threat Hunting, Security Validation, BAS, or related cybersecurity disciplines.
  • Deep understanding of the MITRE ATT&CK framework and adversary TTPs.
  • Experience using Splunk for security investigations, threat analysis, and log correlation.
  • Knowledge of security monitoring, detection engineering, and threat intelligence concepts.
  • Proficiency in scripting and automation using Python, PowerShell, Bash, or similar.

Responsibilities

  • Conduct proactive threat hunting to identify indicators of compromise, suspicious behaviors, and threats.
  • Perform Security Validation and BAS to evaluate security controls and detection capabilities.
  • Analyze security events and telemetry using Splunk and other monitoring tools.
  • Review and improve detection rules, searches, and alerting mechanisms.
  • Map threats to MITRE ATT&CK and support control validation efforts.
  • Develop automation scripts to enhance threat hunting processes.
  • Collaborate with SOC, IR, Threat Intelligence, and Engineering teams.
  • Document findings, recommendations, and remediation actions.

Skills

Threat Hunting
Security Operations
Breach & Attack Simulation
MITRE ATT&CK
Scripting

Tools

Splunk
Python
PowerShell
Bash

Job description

Practice - CIS - Cloud, Infrastructure, and Security Services

About Cloud Infrastructure & Security Services: Cognizant's Cloud, Infrastructure, and Security Services Practice (CIS), is all about embracing digital transformation by driving core modernization holistically across layers. We help customers transform infrastructure and workplace to meet the rapidly evolving needs of the digital era. Our holistic approach delivers key results for our customers by achieving cloud driven modernization and workplace and operational transformation to run the business in a secure environment.

Job Summary

We are seeking a highly motivated Cybersecurity Analyst with expertise in Threat Hunting, Security Validation, and Breach & Attack Simulation (BAS) to strengthen the organization's threat detection and response capabilities. This role will focus on proactively identifying threats, validating security controls, assessing detection effectiveness, and improving overall cyber resilience. The ideal candidate will possess strong analytical skills, hands-on experience with Splunk and security monitoring platforms, and a solid understanding of modern adversary tactics and the MITRE ATT&CK framework. This position requires close collaboration with Security Operations, Incident Response, and Engineering teams to continuously enhance security monitoring and threat defense capabilities.

*Please note, this role is not able to offer visa transfer or sponsorship now or in the future*

In this role, you will:
  • Conduct proactive threat hunting activities to identify indicators of compromise, suspicious behaviors, and emerging threats across enterprise environments.
  • Perform Security Validation and Breach & Attack Simulation (BAS) exercises to evaluate the effectiveness of security controls and detection capabilities.
  • Analyze security events, logs, alerts, and telemetry data using Splunk and other security monitoring platforms.
  • Review, test, and validate detection rules, correlation searches, use cases, and alerting mechanisms to improve threat coverage.
  • Assess the effectiveness of security controls and identify detection gaps, blind spots, and opportunities for improvement.
  • Map threats, adversary behaviors, and attack techniques to the MITRE ATT&CK framework and support control validation efforts.
  • Develop and maintain automation scripts using Python, PowerShell, or Bash to enhance threat hunting and security validation processes.
  • Collaborate with SOC, Incident Response, Threat Intelligence, and Engineering teams to strengthen detection and response capabilities.
  • Document findings, recommendations, attack simulations, and remediation actions arising from threat hunting and validation activities.
  • Support continuous improvement initiatives related to detection engineering, threat intelligence, and security monitoring programs.
What you need to have to be considered
  • 4-8 years of experience in Cybersecurity, Threat Hunting, Security Operations, Detection Engineering, or Security Validation roles.
  • Strong hands-on experience with Threat Hunting, Security Validation, Breach & Attack Simulation (BAS), or related cybersecurity disciplines.
  • Deep understanding of the MITRE ATT&CK framework, adversary tactics, techniques, and procedures (TTPs).
  • Experience using Splunk for security investigations, threat analysis, log correlation, and search query development.
  • Knowledge of security monitoring, detection engineering, security control validation, and threat intelligence concepts.
  • Proficiency in scripting and automation using Python (preferred), PowerShell, Bash, or similar technologies.
  • Familiarity with SOC operations, incident response processes, and attack simulation methodologies.
  • Strong analytical, troubleshooting, communication, and documentation skills.
  • Experience working in fast-paced security operations environments and collaborating across multiple cybersecurity functions.
  • Certifications such as Security+, CySA+, GCIH, GCFA, Splunk Certification, or equivalent cybersecurity credentials are preferred.

#LI-EF1

#CB

#Ind123

Applications will be accepted until 11 Sep 2026.

Salary and Other Compensation:

The annual salary for this position is between $[114,500 - 134,000] depending on experience and other qualifications of the successful candidate.

This position is also eligible for Cognizant's discretionary annual incentive program, based on performance and subject to the terms of Cognizant's applicable plans.

Benefits: Cognizant offers the following benefits for this position, subject to applicable eligibility requirements:

  • Medical/Dental/Vision/Life Insurance
  • Paid holidays plus Paid Time Off
  • 401(k) plan and contributions
  • Long-term/Short-term Disability
  • Paid Parental Leave
  • Employee Stock Purchase Plan
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer - Threat Management
Cybersecurity Engineer - Threat Management

Cognizant • New York (NY)

On-site
USD 115,000 - 134,000
Medical benefits
PTO & holidays
401(k) plan
+3
Qualys Configuration Compliance Specialist
Qualys Configuration Compliance Specialist

Cognizant • Charlotte (NC)

On-site
USD 108,000 - 128,000
Medical/Dental/Vision/Life Insurance
Paid holidays and PTO
401(k) plan and contributions
+3
Cybersecurity Project Manager
Cybersecurity Project Manager

Cognizant • Princeton (NJ)

On-site
USD 137,000 - 160,000
Medical/Dental/Vision/Life Insurance
Paid holidays plus PTO
Long-term/Short-term Disability
+1
Vulnerability Management Engineer
Vulnerability Management Engineer

Cognizant • New York (NY)

On-site
USD 134,000 - 155,000
Medical/Dental/Vision/Life Insurance
Paid holidays and PTO
401(k) plan and contributions
+3
Security Automation & Orchestration Engineer
Security Automation & Orchestration Engineer

Cognizant • Annapolis (MD)

On-site
USD 115,000 - 134,000
Medical/Dental/Vision/Life Insurance
Paid holidays plus PTO
401(k) plan and contributions
+3
Security Automation & Orchestration Engineer
Security Automation & Orchestration Engineer

Cognizant • Bismarck (ND)

On-site
USD 115,000 - 134,000
Medical/Dental/Vision/Life Insurance
Paid holidays plus Paid Time Off
401(k) plan and contributions
+3
Security Automation & Orchestration Engineer
Security Automation & Orchestration Engineer

Cognizant • New York (NY)

On-site
USD 115,000 - 134,000
Medical/Dental/Vision/Life Insurance
Paid holidays plus Paid Time Off
401(k) plan and contributions
+3
Senior IAM Analyst
Senior IAM Analyst

Cognizant • New York (NY)

On-site
USD 134,000 - 155,000
Medical/Dental/Vision/Life Insurance
Paid holidays plus Paid Time Off
401(k) plan and contributions
+3
Data Security Delivery Lead
Data Security Delivery Lead

Cognizant • Charlotte (NC)

On-site
USD 137,000 - 160,000
Medical Insurance
Dental Insurance
Vision Insurance
+8
Threat Hunting & Security Validation Engineer
Threat Hunting & Security Validation Engineer

Cognizant • Blaine (MN)

On-site
USD 115,000 - 134,000
Medical/Dental/Vision/Life Insurance
Paid holidays + PTO
401(k) plan