Threat Investigator

ZP Group

United States

Remote

USD 120,000 - 180,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Medical Insurance
Dental Insurance
Vision Insurance
401(k)

Job summary

Piper Companies is seeking a Threat Investigator to support a leading cybersecurity and incident response organization focused on protecting enterprise environments from advanced threats.

The role emphasizes CSIRT operations, threat detection, incident response, and user behavior analytics, with hands-on use of Splunk Enterprise Security and Splunk UEBA to identify anomalous activity.

This position offers remote work flexibility and a competitive salary range with comprehensive benefits.

Qualifications

  • Secret clearance eligibility required.
  • Experience in Threat Investigation, Incident Response, SOC, or CSIRT environments.
  • Hands-on experience with Splunk Enterprise Security and/or Splunk UEBA.
  • Strong understanding of enterprise security concepts, threat detection methodologies, and incident response processes.
  • Experience investigating suspicious user activity, insider threat indicators, and behavioral anomalies.
  • Familiarity with security monitoring, log analysis, SIEM technologies, and threat intelligence.
  • Knowledge of security frameworks, attack techniques, and cyber threat lifecycle concepts.
  • Strong analytical, troubleshooting, and communication skills.
  • Ability to work remotely while supporting distributed security operations teams.

Responsibilities

  • Monitor, detect, investigate, and respond to security incidents across enterprise environments.
  • Utilize Splunk Enterprise Security and Splunk UEBA to identify anomalous user behavior and potential threats.
  • Conduct threat assessments, event monitoring, incident detection, and response activities.
  • Perform in-depth investigations and root cause analysis of security events and alerts.
  • Develop mitigation strategies and recommendations to reduce organizational security risk.
  • Analyze user behavior trends and suspicious activity to support proactive threat hunting efforts.
  • Collaborate with security operations, engineering, and leadership teams during incident response activities.
  • Support vulnerability management initiatives and contribute to security architecture discussions.
  • Document investigative findings and provide recommendations to stakeholders.

Skills

Threat investigation
Incident response
CSIRT
Splunk ES
Splunk UEBA
SIEM
Threat intelligence
User behavior analytics
Cyber threat lifecycle
Communication

Tools

Splunk Enterprise Security
Splunk UEBA

Job description

Piper Companies is seeking a Threat Investigator to support a leading cybersecurity and incident response organization focused on protecting enterprise environments from advanced threats. The Threat Investigator role is ideal for a security professional with experience in CSIRT operations, threat detection, incident response, and user behavior analytics, particularly within Splunk Enterprise Security and Splunk UEBA environments.

Responsibilities of the Threat Investigator:
  • Monitor, detect, investigate, and respond to security incidents across enterprise environments.
  • Utilize Splunk Enterprise Security and Splunk UEBA to identify anomalous user behavior and potential threats.
  • Conduct threat assessments, event monitoring, incident detection, and response activities.
  • Perform in-depth investigations and root cause analysis of security events and alerts.
  • Develop mitigation strategies and recommendations to reduce organizational security risk.
  • Analyze user behavior trends and suspicious activity to support proactive threat hunting efforts.
  • Collaborate with security operations, engineering, and leadership teams during incident response activities.
  • Support vulnerability management initiatives and contribute to security architecture discussions.
  • Document investigative findings and provide recommendations to stakeholders.
Qualifications of the Threat Investigator:
  • Must be eligible to obtain a Secret Clearance.
  • Experience in Threat Investigation, Incident Response, SOC, or CSIRT environments.
  • Hands-on experience with Splunk Enterprise Security and/or Splunk User Behavior Analytics (UEBA).
  • Strong understanding of enterprise security concepts, threat detection methodologies, and incident response processes.
  • Experience investigating suspicious user activity, insider threat indicators, and behavioral anomalies.
  • Familiarity with security monitoring, log analysis, SIEM technologies, and threat intelligence.
  • Knowledge of security frameworks, attack techniques, and cyber threat lifecycle concepts.
  • Strong analytical, troubleshooting, and communication skills.
  • Ability to work remotely while supporting distributed security operations teams.
Compensation for the Threat Investigator includes:
  • Salary range: $120,000 – $180,000 depending on experience
  • Comprehensive benefits package including medical, dental, vision, 401(k), and PTO

This job opens for applications on 10/02/2026. Applications for this job will be accepted for at least 30 days from the posting date.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Threat Investigator
Threat Investigator

Piper Companies • United States

Remote
USD 120,000 - 180,000
Medical, dental, vision benefits
401(k)
PTO
Threat Investigator
Threat Investigator

Zachary Piper Solutions • United States

Remote
USD 120,000 - 180,000
Medical benefits
PTO and 401(k)
Threat Hunting Investigator
Threat Hunting Investigator

Zachary Piper Solutions • United States

Remote
USD 140,000 - 165,000
Threat Hunting Investigator
Threat Hunting Investigator

ZP Group • United States

Remote
USD 140,000 - 165,000
Medical, Dental, Vision
401K
Sick leave
Threat Hunting Investigator
Threat Hunting Investigator

Piper Companies • United States

Remote
USD 140,000 - 165,000
Medical insurance
Dental insurance
Vision insurance
+2
Remote Threat Hunter & Incident Responder (Splunk ES/UEBA)
Remote Threat Hunter & Incident Responder (Splunk ES/UEBA)

ZP Group • United States

Remote
USD 120,000 - 180,000
Medical Insurance
Dental Insurance
Vision Insurance
+1
Remote Threat Hunter & Incident Response Specialist
Remote Threat Hunter & Incident Response Specialist

Piper Companies • United States

Remote
USD 120,000 - 180,000
Medical, dental, vision benefits
401(k)
PTO
Remote Cyber Threat Investigator (Splunk ES/UEBA)
Remote Cyber Threat Investigator (Splunk ES/UEBA)

Zachary Piper Solutions • United States

Remote
USD 120,000 - 180,000
Medical benefits
PTO and 401(k)
Threat Investigator - 175219
Threat Investigator - 175219

Piper Companies • North Carolina

Hybrid
USD 120,000 - 150,000
Health, Vision, Dental
PTO and Paid Holidays
Hybrid work flexibility
Remote Threat Hunter & Insider Risk Investigator
Remote Threat Hunter & Insider Risk Investigator

ZP Group • United States

Remote
USD 140,000 - 165,000
Medical, Dental, Vision
401K
Sick leave