Senior Threat Hunter

Brown Brothers Harriman & Co.

Boston (MA)

On-site

USD 110,000 - 160,000

Full time

6 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Brown Brothers Harriman & Co. (BBH) in Boston is seeking a Senior Threat Hunter to join our Cyber Threat Monitoring Team.

You will lead advanced SOC investigations, perform proactive threat hunting across SIEM, EDR, identity, network and cloud logs, and escalate complex incidents with technical analysis. The role emphasizes CTI-driven detection, MITRE ATT&CK-aligned hypotheses, and collaboration with SOC analysts, detection engineers, and security leadership to improve detection and response

Qualifications

  • Bachelor’s degree or higher in a cyber-related field.
  • 5+ years in Security Operations, Incident Response, Threat Hunting, or related roles.
  • Hands-on experience with SIEM/EDR and enterprise security monitoring tools.
  • Familiarity with MITRE ATT&CK and attacker TTP analysis.

Responsibilities

  • Lead and support advanced SOC investigations, incident response activities, and Tier-3 escalations, providing deep technical analysis of security alerts.
  • Perform proactive threat hunting across SIEM, EDR, identity, network, and cloud logs to identify threats.
  • Analyze attacker behaviors to develop threat hunting hypotheses and MITRE ATT&CK-aligned detection strategies.
  • Investigate complex alerts to determine root cause, scope, and impact.
  • Collaborate with security teams to improve detection logic, playbooks, and response procedures.
  • Contextualize incidents with CTI sources and stay current on emerging threats.

Skills

Threat hunting
SOC investigations
Incident response
SIEM
EDR
MITRE ATT&CK
Analytical thinking

Education

Bachelor's degree in Cybersecurity/CS/IT

Tools

Splunk SPL
Microsoft KQL

Job description

At BBH, Partnership is more than a form of ownership—it’s our approach to business and relationships. We know that supporting your professional and personal goals is the best way to help our clients and advance our business. We take that responsibility seriously. With a 200-year legacy and a shared passion for what’s next, this is the right place to build a fulfilling career.

Job Description As a Senior Threat Hunter within our Cyber Threat Monitoring Team, you will play a critical role in strengthening the organization’s ability to proactively identify, investigate, and respond to advanced cyber threats. This role emphasizes technical threat hunting, advanced SOC investigations, incident response escalation support, and intelligence-driven detection improvement, while leveraging Cyber Threat Intelligence (CTI) to guide proactive defense strategies. You will serve as a senior escalation resource for complex and high-priority investigations, proactively hunt for adversary activity across enterprise security telemetry, and work closely with SOC analysts, detection engineers, incident response partners, and security leadership to improve the organization’s detection and response capabilities. Collaborating with cross-functional teams and organizational leaders, you will help develop and mature threat hunting, detection, and response capabilities that protect our networks, systems, data, employees, and clients.

The ideal candidate will have strong hands‑on SOC or incident response experience, an analytical mindset, a passion for continuous learning, and the ability to translate threat intelligence and investigative findings into actionable detection and response improvements.

Duties and Responsibilities
  • Lead and support advanced SOC investigations, incident response activities, and Tier-3 escalations, providing deep technical analysis of security alerts, anomalous behavior, and suspected malicious activity
  • Perform proactive threat hunting activities across enterprise security telemetry including SIEM, EDR, identity, network, and cloud logs to identify previously undetected or emerging threats
  • Analyze attacker behaviors and intrusion patterns to develop threat hunting hypotheses and detection strategies aligned with the MITRE ATT&CK framework
  • Investigate complex security alerts and incidents, performing log analysis, endpoint analysis, and timeline reconstruction to determine root cause, scope, and impact
  • Leverage internal telemetry, alerts, and IOC trends to identify threat patterns targeting the organization and opportunities for improved detection coverage
  • Enhance threat detection and response capabilities by supporting the development and improvement of SOC detection logic, response procedures, escalation playbooks, and analyst decision trees
  • Conduct proactive analysis of alert trends to identify gaps in detection coverage and recommend new or improved monitoring capabilities
  • Utilize Cyber Threat Intelligence (CTI) sources to contextualize incidents, inform threat hunting efforts, and prioritize investigations
  • Monitor open-source, closed-source, and vendor-provided threat intelligence to stay abreast of emerging threats, vulnerabilities, and adversary tactics relevant to the organization
  • Develop and maintain profiles of relevant threat actors, including tactics, techniques, and procedures (TTPs), and incorporate those insights into threat hunting and detection strategies
  • Assist in SOC and Incident Response escalations, providing technical expertise and investigative support during security incidents
  • Conduct threat, risk, and vulnerability assessments to provide actionable remediation and security control improvement guidance
  • Collaborate with the Red Team and Cyber Incident Management to support red team exercises, incident response training, tabletop exercises, and detection validation
  • Perform targeted access reviews and anomaly analysis across enterprise systems (Windows, Linux, databases, network infrastructure, cloud platforms) to identify suspicious activity
  • Collaborate with DLP and other security teams on insider risk investigations and monitoring initiatives
  • Contribute to the development and improvement of SOC procedures, threat hunting methodologies, and intelligence-driven detection processes
  • Collaborate with relevant stakeholders on security awareness messaging and threat awareness related communications
Required Qualifications
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field
  • 5+ years of experience in Security Operations, Incident Response, Threat Hunting, Detection Engineering, and/or related cybersecurity roles
  • Significant relevant experience (e.g., military cyber operations) may be considered in lieu of a degree
  • Strong SOC experience investigating security alerts, performing incident response, and log analysis
  • Hands‑on experience working with SIEM, EDR, and other enterprise security monitoring tools
  • Familiarity with the MITRE ATT&CK Framework and attacker TTP analysis
  • Excellent collaboration and communication skills, particularly in high‑stress situations
  • Ability to produce clear technical and operational reporting for both technical teams and leadership
  • Strong analytical skills and priority management
Nice to Have
  • Master’s degree in Cybersecurity, Computer Science, Information Technology, or related field
  • Hands‑on experience in two or more of the following areas: Threat Hunting, Security Operations, Incident Response, Detection Engineering, Cyber Threat Intelligence, Security Engineering, Insider Threat Analysis, Digital Forensics, All‑Source Intelligence, Penetration Testing, Red Teaming, Network Security Management, Cyber Risk Management, Cloud Security, Vulnerability Management, Malware Analysis
  • Experience in the financial services sector and familiarity with security best practices, regulatory requirements, and industry frameworks (e.g., NYDFS, FFIEC, NIST CSF, ISO 27001, SWIFT CSF)
  • Experience developing detection logic and threat hunting queries using Splunk SPL, Microsoft KQL, or similar query languages
  • Experience with endpoint, identity, and network monitoring technologies such as EDR, IDS/IPS, Firewalls, WAF, DLP, UEBA, email security gateways, and sandboxing technologies
  • Experience with Microsoft Sentinel and Defender (MDE, MDI, Defender for Cloud Apps) as well as other Microsoft security ecosystem tools
  • Relevant certifications such as CISSP, GCIH, GCFA, GCIA, GSEC, GCTI, CTIA, Security+, Microsoft Security Operations Analyst Associate
Salary Range

Salary Range NJ & MA: $110,000 to $160,000 base salary + annual bonus target

BBH and its affiliates' compensation program includes base salary, discretionary bonuses, and profit-sharing. The anticipated base salary range(s) shown above are only for the indicated location(s) and may differ in other locations due to cost of living and labor considerations. Base salaries may vary based on factors such as skill, experience and qualification for the role.

BBH's total rewards package recognizes your contributions with more than just a paycheck—providing you with benefits that enhance your experience at BBH from long‑term savings, healthcare, and income protection to professional development opportunities and time off, our programs support your overall well‑being.

About BBH

Brown Brothers Harriman (BBH) is a premier global financial services firm, known for premium service, specialist expertise, technology solutions and partnership approach to client management. Across Investor Services and Capital Partners, we work with an enviable roster of sophisticated clients who make BBH their first call when they are tackling their hardest challenges. Delivering for our clients and each other energizes us. We believe that how we do our work is just as important as what we do. We are relentless problem solvers who know our best ideas come from collective debate and development—so we are never possessive about our ideas. Every day we come together as a diverse community of smart and caring people to deliver exceptional service and expert advice—creating success that lasts. No matter where you sit in the organization, everyone is empowered to contribute their ideas. BBHers can pick up the phone and call any colleague, and they are happy to help. Expanding your impact beyond your daily role is part of how we operate as trusted partners to one another. We believe stability is a competitive advantage, but being stable means having the knowledge, skill, and discipline to evolve, often—pushing the boundaries of innovation. As a private partnership, every investment we make is in the relationships, technologies, products and development we believe are in the long‑term interests of our clients and our people.

We value diverse experiences. We value diverse experiences and transferrable skillsets.

We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, gender, national origin, age, genetic information, creed, marital status, sexual orientation, gender identity, disability status, protected veteran status, or any other protected status under federal, state or local law.

Brown Brothers Harriman (BBH) is a global financial services firm known for premium service and specialist expertise. BBH works with leading asset managers, financial institutions, private businesses and their owners, wealthy families, and sophisticated institutional investors. As a private partnership, we are uniquely built to put clients first and create success that lasts. We believe our success starts with yours. At BBH, partnership is more than just a form of ownership—it’s our approach to business and relationships. Every day we come together as a diverse community of smart and caring people to deliver exceptional service and expert advice. Across Investor Services and Capital Partners, we work with an enviable roster of sophisticated clients who make BBH their first call when they are tackling their hardest challenges. No matter where you sit in the organization, everyone is empowered to contribute their ideas and perspective. BBHers can pick up the phone and call any colleague, and they are happy to help – which is why expanding your impact beyond your daily role is part of how we operate as trusted partners to one another. Delivering for our clients and each other energizes us. We believe stability is a competitive advantage, but being stable means having the knowledge, skill, and discipline to evolve, often—pushing the boundaries of innovation. Every investment we make is in the relationships, technologies, products and development we believe are in the long‑term interests of our clients and our people. With a 200-year legacy and a shared passion for what’s next, this is the right place to build a fulfilling career.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cyber Threat Analyst
Senior Cyber Threat Analyst

Brown Brothers Harriman • United States

On-site
USD 110,000 - 160,000
Cyber Incident Response Manager
Cyber Incident Response Manager

Brown Brothers Harriman & Co. • Jersey City (NJ)

On-site
USD 150,000 - 180,000
Discretionary bonuses
Profit-sharing
Professional development opportunities
Senior Vulnerability & Security Engineer
Senior Vulnerability & Security Engineer

Brown Brothers Harriman & Co. • Jersey City (NJ)

On-site
USD 150,000 - 195,000
Cyber Red Team Operator
Cyber Red Team Operator

Brown Brothers Harriman • Jersey City (NJ)

On-site
USD 120,000 - 160,000
Web Security Engineer
Web Security Engineer

Brown Brothers Harriman & Co. • Jersey City (NJ), Northern (KY)

On-site
USD 100,000 - 130,000
Head of Information Security / Identity and Access Management
Head of Information Security / Identity and Access Management

Brown Brothers Harriman & Co. • Jersey City (NJ)

On-site
USD 200,000 - 260,000
Cyber Red Team Operator
Cyber Red Team Operator

Brown Brothers Harriman • Philadelphia

On-site
USD 120,000 - 160,000
Braid Cloud Engineer
Braid Cloud Engineer

Brown Brothers Harriman & Co. • Boston (MA)

On-site
USD 140,000 - 200,000
Base salary
Discretionary bonuses
Profit-sharing
+3
Product Manager, Solutions Design
Product Manager, Solutions Design

Brown Brothers Harriman & Co. • Boston (MA)

On-site
USD 130,000 - 180,000
Senior Microsoft 365 Information Security Engineer – Data Protection & Insider Risk
Senior Microsoft 365 Information Security Engineer – Data Protection & Insider Risk

Brown Brothers Harriman & Co. • Jersey City (NJ)

On-site
USD 110,000 - 160,000