Cybersecurity Senior Specialist - Threat Hunter

Southern California Edison (SCE)

Rosemead (CA)

Hybrid

USD 140,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Southern California Edison (SCE) is seeking a Cybersecurity Senior Specialist – Threat Hunter to proactively hunt for threats across enterprise and OT environments. You will leverage threat intelligence to drive targeted hunts and work with SOC, IR, and detection engineering to strengthen detections and monitoring.

The role emphasizes collaboration, validation of security controls, and practical threat research to reduce risk and improve security posture across SCE facilities in California.

Qualifications

  • Five or more years of experience in information technology, information security and/or cybersecurity.
  • US Citizenship is required for this role.
  • Experience operating as a Threat Hunter, Incident Responder, Detection Engineer, or Cyber Defense professional.
  • Strong understanding of adversary tactics, techniques, and procedures (MITRE ATT&CK).

Responsibilities

  • Performs proactive threat hunting across enterprise and OT environments to detect malicious activity.
  • Uses threat intelligence and attacker tradecraft to focus hunts on relevant TTPs.
  • Analyzes telemetry from endpoints, networks, cloud, identities, and OT systems to close visibility gaps.
  • Conducts deep-dive investigations and correlates data to identify indicators of compromise.
  • Collaborates with Detection Engineering, Incident Response, and SOC to improve detections and analytics.
  • Researches adversary tradecraft to validate security controls and maintain current defenses.

Skills

Threat hunting
Threat intelligence
Security analytics
Collaboration

Tools

PowerShell
Python
KQL
Splunk SPL
SQL
EDR/XDR
SIEM

Job description

Join the Clean Energy Revolution
Become a Cybersecurity Senior Specialist – Threat Hunter At Southern California Edison (SCE) And Build a Better Tomorrow. In This Job, You’ll

  • Proactive Threat Hunting Operations: Conduct hypothesis-driven hunting activities across enterprise and operational technology (OT) environments to identify malicious activity, advanced adversary behaviors, and previously undetected security threats before they impact business operations.
  • Threat Intelligence-Driven Analysis: Leverage cyber threat intelligence, industry reporting, and emerging attacker tradecraft to develop targeted hunts focused on relevant tactics, techniques, and procedures (TTPs) that pose risk to SCE's environment.
  • Detection Gap Identification & Improvement: Analyze security telemetry across endpoints, networks, cloud services, identities, and OT systems to uncover visibility gaps, improve monitoring coverage, and enhance detection effectiveness.
  • Advanced Investigation & Incident Discovery: Perform deep-dive investigations into suspicious events, anomalous behavior, and complex attack patterns, correlating data from multiple sources to identify indicators of compromise and adversary activity.
  • Threat-Informed Detection Development: Partner with Detection Engineering, Incident Response, and SOC teams to translate hunting findings into actionable detections, analytics, and automated monitoring capabilities that strengthen organizational defenses.
  • Adversary Tradecraft Research & Validation: Research evolving threats, malware, attack frameworks, and intrusion techniques to validate security controls and ensure defensive capabilities remain aligned with the current threat landscape.
  • Cross-Functional Security Collaboration: Collaborate with Red Team, Blue Team, Cyber Defense, and business stakeholders to drive remediation efforts, enhance cyber resilience, and continuously improve security operations maturity.
  • Strategic Reporting & Communication: Deliver concise, data-driven reporting that communicates hunting outcomes, emerging risks, and security recommendations to technical teams and leadership, enabling informed decision-making and risk reduction.

Join the Clean Energy Revolution
Become a Cybersecurity Senior Specialist – Threat Hunter At Southern California Edison (SCE) And Build a Better Tomorrow. In This Job, You’ll

  • Proactive Threat Hunting Operations: Conduct hypothesis-driven hunting activities across enterprise and operational technology (OT) environments to identify malicious activity, advanced adversary behaviors, and previously undetected security threats before they impact business operations.
  • Threat Intelligence-Driven Analysis: Leverage cyber threat intelligence, industry reporting, and emerging attacker tradecraft to develop targeted hunts focused on relevant tactics, techniques, and procedures (TTPs) that pose risk to SCE's environment.
  • Detection Gap Identification & Improvement: Analyze security telemetry across endpoints, networks, cloud services, identities, and OT systems to uncover visibility gaps, improve monitoring coverage, and enhance detection effectiveness.
  • Advanced Investigation & Incident Discovery: Perform deep-dive investigations into suspicious events, anomalous behavior, and complex attack patterns, correlating data from multiple sources to identify indicators of compromise and adversary activity.
  • Threat-Informed Detection Development: Partner with Detection Engineering, Incident Response, and SOC teams to translate hunting findings into actionable detections, analytics, and automated monitoring capabilities that strengthen organizational defenses.
  • Adversary Tradecraft Research & Validation: Research evolving threats, malware, attack frameworks, and intrusion techniques to validate security controls and ensure defensive capabilities remain aligned with the current threat landscape.
  • Cross-Functional Security Collaboration: Collaborate with Red Team, Blue Team, Cyber Defense, and business stakeholders to drive remediation efforts, enhance cyber resilience, and continuously improve security operations maturity.
  • Strategic Reporting & Communication: Deliver concise, data-driven reporting that communicates hunting outcomes, emerging risks, and security recommendations to technical teams and leadership, enabling informed decision-making and risk reduction.

As a Cybersecurity Senior Specialist, your work will help power our planet, reduce carbon emissions and create cleaner air for everyone. Are you ready to take on the challenge to help us build the future?

Responsibilities

  • Performs security risk, vulnerability assessments, and business impact analysis for medium complexity information systems.
  • Carries out project reporting for assigned projects, monitoring project status, timeline and budgets. Assists in the planning and implementation of current and future security domains including those which may introduce new service areas.
  • Adopts and follows security controls, processes, and procedures to manage risk across all information system environments (infrastructure, network, and applications) with the assistance of the application and infrastructure management teams.
  • Monitors technology risk, identifies root cause or key themes, recommends for resolution. Investigates suspected attacks and manages security incidents. Uses forensics where appropriate. Reviews and shapes the production of evidence to support internal and external audits.
  • Implements appropriate security measures for information systems and applications that control access to data, and prevents unauthorized modification, destruction, or disclosure of information.
  • Develops and maintains metrics, alerts, dashboards, and reports for security monitoring.
  • Maintains incident response plans and performs incident response activities as directed and in accordance with established procedures and guidelines and those of federal authorities.
  • A material job duty of all positions within the Company is ensuring the protection of all its physical, financial and cybersecurity assets, and properly accessing and managing private customer data, proprietary information, confidential medical records, and other types of highly sensitive information and data with the highest standards of conduct and integrity.

Minimum Qualifications

  • Five or more years of experience in information technology, information security and/or cybersecurity. US Citizenship Required.

Preferred Qualifications

  • Experience operating as a Threat Hunter, Incident Responder, Detection Engineer, or Cyber Defense professional within complex enterprise environments, with demonstrated ability to collaborate across Cybersecurity, IT, Cloud, and OT organizations.
  • Experience conducting hypothesis-driven threat hunting activities utilizing threat intelligence, behavioral analytics, and attacker TTPs to proactively identify malicious activity and previously unknown threats.
  • Strong understanding of adversary tactics, techniques, and procedures as defined by frameworks such as MITRE ATT&CK, with experience mapping observed activity to threat actor behaviors and intrusion methodologies.
  • Experience analyzing and correlating security telemetry from multiple sources, including endpoint, network, identity, cloud, email, and security monitoring platforms to identify indicators of compromise and suspicious activity.
  • Experience partnering with Detection Engineering, Incident Response, and SOC teams to develop, validate, and optimize detection content, use cases, analytics, and automated response capabilities.
  • Experience or familiarity with cybersecurity operations in OT/ICS environments, including an understanding of critical infrastructure threats, operational reliability requirements, and industrial control system security considerations.
  • Demonstrated capability in leveraging scripting, automation, and data analysis technologies (e.g., PowerShell, Python, KQL, Splunk SPL, SQL) to improve hunting effectiveness, operational efficiency, and investigation workflows.
  • Experience utilizing advanced security technologies such as EDR/XDR, SIEM, NDR, cloud security monitoring, threat intelligence platforms, and security orchestration tools to conduct investigations and threat hunting activities.
  • Relevant industry certifications such as GCFA, GCTI, GCFR, GMON, GCDA, CISSP, Azure Security Engineer Associate, or equivalent cybersecurity certifications.

Additional Information

  • This position’s work mode is hybrid. The employee will report to an SCE facility for a set number of days with the option to work remotely on the remaining days. Unless otherwise noted, employees are required to work and reside in the state of California. Further details of this work mode will be discussed at the interview stage. The work mode can be changed based on business needs.
  • Visit our Candidate Resource page to get meaningful information related to benefits, perks, resources, testing information, hiring process, and more!
  • Qualified applications with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.
  • The primary work location for this position is Rosemead, CA.
  • Position will require up to 10% traveling and being out in the field throughout the SCE service territory.
  • This position has been identified as a NERC/CIP impacted position - Prior to being hired, the successful candidate must pass a Personnel Risk Assessment (PRA) or Background Investigation. Once hired, the candidate must complete specified training prior to gaining un-escorted access to assigned work location and performing necessary job duties.
  • Relocation may apply to this position.

About Southern California Edison

  • The people at SCE don't just keep the lights on. Our mission is so much bigger. We’re fueling the kind of innovation that’s changing an entire industry, and quite possibly the planet. Join us and create a future with cleaner energy, while providing our customers with the safety and reliability they demand. At SCE, you’ll have a chance to grow personally and professionally, making a real impact in Southern California and around the world.
  • Southern California Edison is a proud Equal Opportunity Employer, including disability and protected veteran status.
  • We are committed to ensuring that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodations at AskHR@sce.com or (626) 302-3456 and select option 2.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Senior Specialist - Threat Hunter
Cybersecurity Senior Specialist - Threat Hunter

Southern California Edison • Rosemead (CA)

Hybrid
USD 130,000 - 165,000
Hybrid work mode
Relocation assistance
Cyber Threat Intelligence Advisor
Cyber Threat Intelligence Advisor

Thomson Reuters Markets Espana SL. • Rosemead (CA), Northern (KY)

Hybrid
USD 130,000 - 190,000
Hybrid work mode
Cyber Threat Intelligence Advisor
Cyber Threat Intelligence Advisor

Southern California Edison (SCE) • Rosemead (CA)

Hybrid
USD 140,000 - 210,000
Hybrid work arrangement
Cyber Threat Intelligence Senior Specialist
Cyber Threat Intelligence Senior Specialist

Southern California Edison • Rosemead (CA), Northern (KY)

Hybrid
USD 120,000 - 150,000
Cyber Threat Intelligence Senior Specialist
Cyber Threat Intelligence Senior Specialist

Thomson Reuters Markets Espana SL. • Rosemead (CA)

Hybrid
USD 130,000 - 170,000
Hybrid work model
Cyber Threat Intelligence Advisor
Cyber Threat Intelligence Advisor

Southern California Edison • Rosemead (CA)

On-site
USD 110,000 - 170,000
Hybrid work mode
Cybersecurity Senior Advisor
Cybersecurity Senior Advisor

Edisonrefertalent • Rosemead (CA)

Hybrid
USD 120,000 - 160,000
Cybersecurity Senior Advisor
Cybersecurity Senior Advisor

Southern California Edison (SCE) • Rosemead (CA)

Hybrid
USD 120,000 - 160,000
Cybersecurity Engineering, Risk & Governance Senior Advisor
Cybersecurity Engineering, Risk & Governance Senior Advisor

Southern California Edison • Rosemead (CA)

Hybrid
USD 130,000 - 170,000
Hybrid work model
Professional development opportunities
Health Insurance
Cybersecurity Vulnerability Management Data Senior Specialist
Cybersecurity Vulnerability Management Data Senior Specialist

Southern California Edison (SCE) • Rosemead (CA)

Hybrid
USD 100,000 - 130,000