Threat Hunter & SIEM/SOAR Automation Engineer

Dentons

Chicago (IL)

On-site

USD 84,000 - 108,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Dentons US LLP is recruiting a Threat Analyst to proactively hunt for threats in client environments and tune SIEM use cases while developing automation and SOAR playbooks. The analyst will investigate events, monitor threat intelligence, and collaborate with internal teams to improve security operations.

Responsibilities include threat scenario analysis, in-depth investigations, creation of reports, and ongoing metrics for security operations.

Qualifications

  • Bachelor’s degree in Computer Science, Information Security, or related field.
  • Minimum 2 years of experience in Cyber Intelligence or as a Threat Hunter, preferably within a CIRT/SOC; hands-on experience with SIEM content and automation development.
  • Direct prior experience with core security technologies such as SIEM, vulnerability scanners, anti-virus solutions, and EDRs.
  • Strong knowledge of threat intelligence and threat hunting, including MITRE ATT&CK, kill chain, hypothesis-driven methods, and IOC lifecycle management.
  • Demonstrated experience with SIEM platforms (e.g., Splunk, Microsoft Sentinel, Elastic): data onboarding, parsing, correlation rules, dashboards, and tuning.
  • Experience with SOAR platforms (e.g., Splunk SOAR, Microsoft Sentinel automation, Swimlane) and building playbooks for enrichment and response.
  • Strong analytical and investigative skills; knowledge of technical security controls and mitigations.
  • Experience with advanced endpoint analytics and EDR tooling (e.g., CrowdStrike, Defender for Endpoint, Sophos).
  • Good working knowledge of common security threats, industry best practices, and security technologies.
  • 24x7 on-call availability for high severity incidents.
  • Knowledge of digital forensics, malware analysis, penetration testing and ethical hacking.
  • Proficiency in scripting languages (Python, PowerShell, shell) is a plus.
  • Industry certifications are a strong asset (e.g., GIAC, Microsoft SC-200, Splunk Enterprise Security, AWS/Azure security certs).

Responsibilities

  • Analyze activity trends using a mix of tools and analytical methodologies to hunt for threats not otherwise detected by configured security alerts.
  • Conduct threat scenario analysis to develop new use cases with relevant attack vectors; develop attack scenarios to formulate hunting strategies to identify threats undetected by existing controls.
  • Perform in-depth investigation of events of interest identified during hunts or from security alerts as defined investigation and response procedures.
  • Monitor, triage, and operationalize threat intelligence from commercial, open-source, ISAC/ISAO, and government sources.
  • Correlate threat intelligence with internal telemetry to identify potential compromise and guide hunts and incident response.
  • Create and deliver regular threat hunting and threat intelligence reports including hypotheses, datasets, findings, false positives, and detection/response improvements.
  • Contribute to the tuning and development of SIEM use cases and other security control configurations to enhance threat detection capabilities.
  • Define and track Security Operations metrics.
  • Design, develop, and maintain automation and SOAR playbooks to streamline alert triage, enrichment, containment, and notification workflows.
  • Automate routine operational tasks (e.g., IOC curation, asset/context lookups, quarantine, user suspension) to reduce MTTD/MTTR.
  • Facilitate vulnerability management by correlating vuln data with exploits-in-the-wild; prioritize remediation based on risk and exposure.
  • Participate in IR exercises to validate processes and IR capabilities.
  • Other duties as assigned to fully meet the requirements of the position.

Skills

Threat hunting
Analytical thinking
Investigation
Collaboration
Scripting (Python)
Communication

Education

Bachelor’s degree in Computer Science, Information Security, or related field

Tools

Splunk
Microsoft Sentinel
Elastic
Splunk SOAR
Swimlane
EDR tooling (CrowdStrike, Defender for Endpoint)

Job description

Dentons US LLP is recruiting a Threat Analyst to proactively hunt for threats in client environments and tune SIEM use cases while developing automation and SOAR playbooks. The analyst will investigate events, monitor threat intelligence, and collaborate with internal teams to improve security operations.

Responsibilities include threat scenario analysis, in-depth investigations, creation of reports, and ongoing metrics for security operations.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Threat Analyst
Threat Analyst

Dentons • Chicago (IL)

On-site
USD 84,000 - 108,000
Cyber Threat Analyst - SIEM & Threat Hunting
Cyber Threat Analyst - SIEM & Threat Hunting

Cellebrite • Tysons (VA)

On-site
USD 120,000 - 170,000
Senior Security Operations Lead - Threat Hunting & IR
Senior Security Operations Lead - Threat Hunting & IR

DLA Piper • Baltimore (MD)

Hybrid
USD 94,000 - 131,000
Security Operations Center Analyst — Threat Hunter
Security Operations Center Analyst — Threat Hunter

DMI • Crownsville (MD)

On-site
USD 90,000 - 130,000
SOC Threat Hunter & Incident Response Engineer
SOC Threat Hunter & Incident Response Engineer

No Limit Staffing, Inc. • United States

On-site
USD 90,000 - 120,000
Threat Detection & Response Engineer
Threat Detection & Response Engineer

United States Digital Space LLC • United States

Hybrid
USD 120,000 - 180,000
Paid parental leave
Certification reimbursement
Digital mental health support
+1
Threat Hunter: SIEM & AI-Driven Threat Discovery
Threat Hunter: SIEM & AI-Driven Threat Discovery

Motion Recruitment • Woodbridge Township (NJ)

On-site
USD 83,000 - 138,000
Medical Insurance
Dental Benefits
Vision Benefits
+2
SOC Analyst - Onsite in MD | Threat Hunting & SIEM
SOC Analyst - Onsite in MD | Threat Hunting & SIEM

careers-dminc • Crownsville (MD)

On-site
USD 85,000 - 120,000
Healthcare coverage
Annual performance reviews
Tuition assistance
+2
SOC Threat Hunter & Incident Response Engineer
SOC Threat Hunter & Incident Response Engineer

Cyberdata Technologies, Inc. • Herndon (VA)

On-site
USD 80,000 - 120,000
Senior InfoSec Analyst - Threat Hunting & IR Lead (Hybrid)
Senior InfoSec Analyst - Threat Hunting & IR Lead (Hybrid)

DLA Piper • Austin (TX)

Hybrid
USD 94,000 - 131,000
Medical Insurance
Dental Insurance
401(k) Plan
+1