PC
Threat Hunting Investigator
- Salary
- $140K–$165K
- Hiring from
- United States
- Work type
- Remote
- Posted
Is this job info correct?
Show job descriptionHide job description
Piper Companies is looking to fill the role of Threat Hunter Investigator for a leading technology company located in Raleigh, NC. The Threat Hunter Investigator will identify, investigate, and mitigate risks largely posed by internal actors - whether malicious, negligent, or compromised. This role provides direct support to conduct research and investigations into threats and incidents related to protection of critical intellectual property. The Threat Hunter Investigator role is a remote position with EST hours.
Responsibilities of the Threat Hunter Investigator Include:
Keywords: threat detection, threat investigator, splunk, insider risks,
#REMOTE
Responsibilities of the Threat Hunter Investigator Include:
- Conduct proactive threat hunting and insider risk investigations using logs, endpoint telemetry, user activity, and behavioral indicators to identify potential security threats and malicious activity.
- Research, analyze, and mitigate threats involving sensitive data exposure, intellectual property theft, and other insider risk scenarios, while producing clear and defensible investigative reports.
- Design, develop, test, deploy, and tune advanced threat detections using Splunk SPL, translating threat intelligence, threat hypotheses, and investigative findings into production-ready detection content.
- Build and maintain Risk-Based Alerting (RBA) workflows, including correlation searches, risk rules, risk scoring, notable events, and automated response actions within Splunk Enterprise Security.
- Configure and optimize UEBA detections, anomaly models, and behavioral analytics to identify suspicious user and entity activity across endpoint, network, cloud, and application environments.
- Create technical documentation, runbooks, and operational standards while continuously validating detection effectiveness through testing, tuning, false-positive reduction, and coverage analysis aligned to MITRE ATT&CK methodologies.
- Bachelor's degree in computer science, Information Systems, Cybersecurity, or related field.
- 8+ years of experience conducting threat investigations, insider threat analysis, and digital forensic investigations involving endpoint devices and sensitive data.
- Strong hands-on experience with Splunk Enterprise Security, including engineering, tuning, and maintaining security detections in a production environment.
- Proven ability to write advanced SPL queries from scratch and develop correlation searches, custom detections, and threat-hunting content.
- Deep experience with Risk-Based Alerting (RBA) and User and Entity Behavior Analytics (UEBA), including risk scoring, behavioral baselining, anomaly detection, and alert prioritization.
- Strong understanding of detection engineering and threat hunting methodologies, with the ability to translate threat intelligence and MITRE ATT&CK techniques into actionable detections and response workflows.
- $140,000-$165,000 annually
- Comprehensive Benefits: Medical, Dental, Vision, 401(k), PTO, Sick Leave if required by law, and Holidays
Keywords: threat detection, threat investigator, splunk, insider risks,
#REMOTE