Cybersecurity Senior Specialist - Threat Hunter

Southern California Edison

Rosemead (CA)

Hybrid

USD 130,000 - 165,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid work mode
Relocation assistance

Job summary

Southern California Edison is seeking a Cybersecurity Senior Specialist – Threat Hunter to proactively hunt threats across enterprise and OT environments. You will translate findings into detections, collaborate with Detection Engineering, Incident Response, and SOC teams, and advance the security program to reduce risk.

You will conduct deep investigations, leverage threat intelligence, and align with MITRE ATT&CK to improve detection coverage.

Qualifications

  • Five or more years of experience in information technology, information security and/or cybersecurity.
  • Experience operating as a Threat Hunter, Incident Responder, Detection Engineer, or Cyber Defense professional within complex enterprise environments.
  • Experience conducting hypothesis-driven threat hunting activities utilizing threat intelligence, behavioral analytics, and attacker TTPs to proactively identify malicious activity and previously unknown threats.
  • Strong understanding of adversary tactics, techniques, and procedures per MITRE ATT&CK; map activity to threat actor behaviors.
  • Experience analyzing and correlating security telemetry from multiple sources (endpoint, network, identity, cloud, etc.).
  • Experience partnering with Detection Engineering, Incident Response, and SOC teams to develop and optimize detections and analytics.
  • Experience in OT/ICS cybersecurity within critical infrastructure contexts.
  • Scripting, automation, and data analysis skills (PowerShell, Python, KQL, Splunk SPL, SQL).
  • Experience with EDR/XDR, SIEM, NDR, cloud security monitoring, threat intel platforms, or SOAR.
  • Certifications such as GCFA, GCTI, GCFR, GMON, GCDA, CISSP, Azure Security Engineer, or equivalent.

Responsibilities

  • Performs security risk, vulnerability assessments, and business impact analysis for medium complexity information systems.
  • Caries out project reporting, monitoring status, timeline and budgets; plan security domains.
  • Implements security controls across infrastructure, network, and applications in collaboration with management teams.
  • Monitors technology risk, investigates suspected attacks, and manages security incidents with forensic considerations.
  • Develops metrics, alerts, dashboards, and reports for security monitoring.
  • Maintains incident response plans and executes response per procedures and guidelines.
  • Protects data integrity and confidentiality; supports audits and governance.

Skills

Threat hunting
Threat intelligence
Telemetry analysis
Incident response
Automation scripting

Tools

PowerShell
Python
KQL
Splunk SPL
SQL
EDR/XDR
SIEM
NDR

Job description

Join the Clean Energy Revolution

BecomeaCybersecurity Senior Specialist – Threat Hunterat Southern California Edison (SCE) and build a better tomorrow. In this job, you’ll:

  • Proactive Threat Hunting Operations: Conduct hypothesis-driven hunting activities across enterprise and operational technology (OT) environments to identify malicious activity, advanced adversary behaviors, and previously undetected security threats before they impact business operations.
  • Threat Intelligence-Driven Analysis: Leverage cyber threat intelligence, industry reporting, and emerging attacker tradecraft to develop targeted hunts focused on relevant tactics, techniques, and procedures (TTPs) that pose risk to SCE's environment.
  • Detection Gap Identification & Improvement: Analyze security telemetry across endpoints, networks, cloud services, identities, and OT systems to uncover visibility gaps, improve monitoring coverage, and enhance detection effectiveness.
  • Advanced Investigation & Incident Discovery: Perform deep-dive investigations into suspicious events, anomalous behavior, and complex attack patterns, correlating data from multiple sources to identify indicators of compromise and adversary activity.
  • Threat-Informed Detection Development: Partner with Detection Engineering, Incident Response, and SOC teams to translate hunting findings into actionable detections, analytics, and automated monitoring capabilities that strengthen organizational defenses.
  • Adversary Tradecraft Research & Validation: Research evolving threats, malware, attack frameworks, and intrusion techniques to validate security controls and ensure defensive capabilities remain aligned with the current threat landscape.
  • Cross-Functional Security Collaboration: Collaborate with Red Team, Blue Team, Cyber Defense, and business stakeholders to drive remediation efforts, enhance cyber resilience, and continuously improve security operations maturity.
  • Strategic Reporting & Communication: Deliver concise, data-driven reporting that communicates hunting outcomes, emerging risks, and security recommendations to technical teams and leadership, enabling informed decision-making and risk reduction.

Asa Cybersecurity Senior Specialist, your work will help power our planet, reduce carbon emissions and create cleaner air for everyone. Are you ready to take on the challenge to help us build the future?

Responsibilities
  • Performs security risk, vulnerability assessments, and business impact analysis for medium complexity information systems.
  • Carries out project reporting for assigned projects, monitoring project status, timeline and budgets. Assists in the planning and implementation of current and future security domains including those which may introduce new service areas.
  • Adopts and follows security controls, processes, and procedures to manage risk across all information system environments (infrastructure, network, and applications) with the assistance of the application and infrastructure management teams.
  • Monitors technology risk, identifies root cause or key themes, recommends for resolution. Investigates suspected attacks and manages security incidents. Uses forensics where appropriate. Reviews and shapes the production of evidence to support internal and external audits.
  • Implements appropriate security measures for information systems and applications that control access to data, and prevents unauthorized modification, destruction, or disclosure of information.
  • Develops and maintains metrics, alerts, dashboards, and reports for security monitoring.
  • Maintains incident response plans and performs incident response activities as directed and in accordance with established procedures and guidelines and those of federal authorities.
  • A material job duty of all positions within the Company is ensuring the protection of all its physical, financial and cybersecurity assets, and properly accessing and managing private customer data, proprietary information, confidential medical records, and other types of highly sensitive information and data with the highest standards of conduct and integrity.
Minimum Qualifications
  • Five or more years of experience in information technology, information security and/or cybersecurity. US Citizenship Required.

Preferred Qualifications

  • Experience operating as a Threat Hunter, Incident Responder, Detection Engineer, or Cyber Defense professional within complex enterprise environments, with demonstrated ability to collaborate across Cybersecurity, IT, Cloud, and OT organizations.
  • Experience conducting hypothesis-driven threat hunting activities utilizing threat intelligence, behavioral analytics, and attacker TTPs to proactively identify malicious activity and previously unknown threats.
  • Strong understanding of adversary tactics, techniques, and procedures as defined by frameworks such as MITRE ATT&CK, with experience mapping observed activity to threat actor behaviors and intrusion methodologies.
  • Experience analyzing and correlating security telemetry from multiple sources, including endpoint, network, identity, cloud, email, and security monitoring platforms to identify indicators of compromise and suspicious activity.
  • Experience partnering with Detection Engineering, Incident Response, and SOC teams to develop, validate, and optimize detection content, use cases, analytics, and automated response capabilities.
  • Experience or familiarity with cybersecurity operations in OT/ICS environments, including an understanding of critical infrastructure threats, operational reliability requirements, and industrial control system security considerations.
  • Demonstrated capability in leveraging scripting, automation, and data analysis technologies (e.g., PowerShell, Python, KQL, Splunk SPL, SQL) to improve hunting effectiveness, operational efficiency, and investigation workflows.
  • Experience utilizing advanced security technologies such as EDR/XDR, SIEM, NDR, cloud security monitoring, threat intelligence platforms, and security orchestration tools to conduct investigations and threat hunting activities.
  • Relevant industry certifications such as GCFA, GCTI, GCFR, GMON, GCDA, CISSP, Azure Security Engineer Associate, or equivalent cybersecurity certifications.

Additional Information

  • This position’s work mode is hybrid. The employee will report to an SCE facility for a set number of days with the option to work remotely on the remaining days. Unless otherwise noted, employees are required to work and reside in the state of California. Further details of this work mode will be discussed at the interview stage.The work mode can be changed based on business needs.
  • Visit our Candidate Resource page to get meaningful information related to benefits, perks, resources, testing information, hiring process, and more!
  • Qualified applications with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.
  • The primary work location for this position is Rosemead, CA.
  • Position will require up to 10% traveling and being out in the field throughout the SCE service territory.
  • This position has been identified as a NERC/CIP impacted position - Prior to being hired, the successful candidate must pass a Personnel Risk Assessment (PRA) or Background Investigation. Once hired, the candidate must complete specified training prior to gaining un-escorted access to assigned work location and performing necessary job duties.
  • Relocation may apply to this position.

About Southern California Edison

The people at SCE don't just keep the lights on. Our mission is so much bigger. We’re fueling the kind of innovation that’s changing an entire industry, and quite possibly the planet. Join us and create a future with cleaner energy, while providing our customers with the safety and reliability they demand. At SCE, you’ll have a chance to grow personally and professionally, making a real impact in Southern California and around the world.

Southern California Edison is a proud Equal Opportunity Employer, including disability and protected veteran status.

We are committed to ensuring that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodations at AskHR@sce.com or (626) 302-3456 and select option 2.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Senior Specialist - Threat Hunter
Cybersecurity Senior Specialist - Threat Hunter

Southern California Edison (SCE) • Rosemead (CA)

Hybrid
USD 140,000 - 190,000
Cyber Threat Intelligence Advisor
Cyber Threat Intelligence Advisor

Thomson Reuters Markets Espana SL. • Rosemead (CA), Northern (KY)

Hybrid
USD 130,000 - 190,000
Hybrid work mode
Cyber Threat Intelligence Advisor
Cyber Threat Intelligence Advisor

Southern California Edison (SCE) • Rosemead (CA)

Hybrid
USD 140,000 - 210,000
Hybrid work arrangement
Cyber Threat Intelligence Senior Specialist
Cyber Threat Intelligence Senior Specialist

Thomson Reuters Markets Espana SL. • Rosemead (CA), Northern (KY)

Hybrid
USD 130,000 - 170,000
Cyber Threat Intelligence Senior Specialist
Cyber Threat Intelligence Senior Specialist

Southern California Edison • Rosemead (CA), Northern (KY)

Hybrid
USD 120,000 - 150,000
Cyber Threat Intelligence Advisor
Cyber Threat Intelligence Advisor

Southern California Edison • Rosemead (CA)

On-site
USD 110,000 - 170,000
Hybrid work mode
Cybersecurity Senior Advisor
Cybersecurity Senior Advisor

Edisonrefertalent • Rosemead (CA)

Hybrid
USD 120,000 - 160,000
Cybersecurity Senior Advisor
Cybersecurity Senior Advisor

Southern California Edison (SCE) • Rosemead (CA)

Hybrid
USD 120,000 - 160,000
Cybersecurity Engineering, Risk & Governance Senior Advisor
Cybersecurity Engineering, Risk & Governance Senior Advisor

Southern California Edison • Rosemead (CA)

Hybrid
USD 130,000 - 170,000
Hybrid work model
Professional development opportunities
Health Insurance
NERC Compliance Senior Advisor
NERC Compliance Senior Advisor

Thomson Reuters Markets Espana SL. • Rosemead (CA)

Hybrid
USD 130,000 - 170,000
Hybrid work model