Senior Threat Hunter
- Hiring from
- Colombia
- Work type
- Hybrid
- Posted
Show job descriptionHide job description
Build the Future with AspenView Technology Partners
At AspenView, we are passionate about transforming the way organizations approach technology. We specialize in creating high-performing, nearshore IT teams to help North American clients innovate faster and more efficiently.
As we continue to grow, we’re looking for exceptional people to join our team and help drive impactful change across industries.
Why Join AspenView?
At AspenView, we’re more than a nearshore IT partner—we’re a people-first, purpose-driven company that believes great culture drives great outcomes. We’re passionate about connecting talent and technology to deliver measurable value for clients—and meaningful career paths for our people.
Here’s what you can expect:
- Competitive base
- Flexible work model: hybrid, remote, or in-office
- Real growth opportunities and leadership visibility
- Inclusive, respectful culture that blends U.S. innovation with Colombian heart
- A company that listens, invests in you, and celebrates wins together
We are seeking a Senior Threat Hunter to join the security operations team of a large US consumer lender in the financial services sector, working on-site from AspenView's secure suite in Bogotá, Medellín or Buenos Aires. You'll design and run hypothesis-driven hunts across endpoint, identity, network, email and AWS telemetry in Elastic, reporting to the on-site Threat Hunting Lead and working closely with Detection Engineering so that every good hunt ends as a working detection. This is a hands-on role for someone who can take raw intelligence and turn it into a hunt without being told how, and who knows what living-off-the-land, credential abuse and lateral movement look like in real logs, not just someone who has triaged alerts from a queue.
What you will do:
Hunt Design & Threat Intelligence
- Build hunts from threat intelligence relevant to US consumer finance, recent incidents and known telemetry gaps
- Turn raw intelligence into testable hypotheses on your own
- Decide which data sources and timeframes will answer each hunt question
- Map attacker tradecraft to MITRE ATT&CK to shape and prioritize hunts
Hunt Execution & Investigation
- Run scheduled and ad hoc hunts across CrowdStrike, Defender, Okta, Palo Alto, Proofpoint and AWS data in Elastic
- Pivot quickly when an initial query surfaces something worth chasing
- Separate real findings from noise
- Escalate live attacker activity to Tier 3 and the Incident Response Lead with the evidence attached
- Run indicator and behaviour sweeps during major incidents to scope how far an attacker reached
Detection Engineering Partnership
- Hand candidate detections to Detection Engineering, written well enough to build from
- Identify logging gaps and document them for remediation
- Make sure your hunts end as production detection rules
Reporting & Knowledge Sharing
- Write clear, reproducible hunt reports covering what was tested, found, ruled out and couldn't be tested
- Walk the client's security team through findings directly, in English
- Document hunts so anyone on the team can rerun them
Tools & Technologies:
- Platforms & Infrastructure: Elastic Security (EQL, ES|QL), Splunk or Microsoft Sentinel (equivalent SIEMs), Palo Alto, Proofpoint
- Security & Threat Intelligence: CrowdStrike Falcon, Microsoft Defender, SentinelOne, MITRE ATT&CK, MISP, OpenCTI, Recorded Future, FS-ISAC, malware triage and memory forensics
- Cloud & Data Analysis: AWS (control-plane and cloud telemetry), Okta (identity telemetry), Python, Jupyter
What you bring:
- Experience: 5+ years in threat hunting, Tier 3 investigation or incident response, with hunts you can walk through from hypothesis to outcome, including the ones that found nothing
- Technical Depth: Fluent querying across large data sets in Elastic, Splunk, Sentinel or equivalent, and a strong grasp of living-off-the-land, credential and session abuse, lateral movement and cloud control-plane abuse as they appear in logs
- Consulting / Leadership: Confidence presenting findings straight to a US client's security team, working well with Detection Engineering and IR, and interest in growing into a Threat Hunting Lead, IR Lead or Detection Engineering Lead role
- Mindset: Works independently, stays rigorous and curious, and knows that a hunt proving a control works is a good result
- Language: English at B2 or above
- Location & Schedule: On-site in Bogotá, Medellín or Buenos Aires during US Eastern business hours (no rotating shifts), with occasional call-ins during major incidents
- Security Clearance: Willing to undergo identity, criminal-background, employment and education checks, repeated periodically, and to work in a clean-desk, VDI-only environment
- Clearance: Must pass identity, criminal-background, employment and education checks, repeated periodically.
- Nice to have: Financial-sector threat experience (fraud-motivated intrusion, ransomware, BEC), detection-writing skills, and certifications such as GCTI, GDAT, GCIH, GCFA or eCTHP
Visa Sponsorship
AspenView does not sponsor employment visas for this role. Applicants must be permanently authorized to work in their country of residence and must not require visa sponsorship now or in the future.
Equal Opportunity Employer
AspenView is proud to be an equal opportunity employer. We believe in creating an environment where all employees feel welcome, valued, and empowered to succeed. We celebrate diversity and strive to build a culture of inclusion where all individuals, regardless of their race, color, gender, gender identity or expression, sexual orientation, disability, age, or any other characteristic, can thrive. We encourage applicants from all walks of life to join our team and make a lasting impact.