Threat Hunting Lead
- Hiring from
- Argentina, Colombia
- Work type
- Hybrid
- Posted
Show job descriptionHide job description
Build the Future with AspenView Technology Partners
At AspenView, we are passionate about transforming the way organizations approach technology. We specialize in creating high-performing, nearshore IT teams to help North American clients innovate faster and more efficiently.
As we continue to grow, we’re looking for exceptional people to join our team and help drive impactful change across industries.
Why Join AspenView?
At AspenView, we’re more than a nearshore IT partner—we’re a people-first, purpose-driven company that believes great culture drives great outcomes. We’re passionate about connecting talent and technology to deliver measurable value for clients—and meaningful career paths for our people.
Here’s what you can expect:
- Competitive base
- Flexible work model: hybrid, remote, or in-office
- Real growth opportunities and leadership visibility
- Inclusive, respectful culture that blends U.S. innovation with Colombian heart
- A company that listens, invests in you, and celebrates wins together
We are seeking a Threat Hunting Lead to join the security operations team of a large US consumer lender in the financial services sector. You'll own the hunt plan and lead intelligence-driven hunts across endpoint, identity, network, email and AWS telemetry in Elastic, directing two Senior Threat Hunters and working daily with the US-based Detection Engineering Lead so that every good hunt ends as a working detection. This is a hands-on role for someone who has actually taken hunts from hypothesis to outcome and knows what living-off-the-land, credential abuse and lateral movement look like in real logs, not just someone who has triaged alerts from a queue.
What you will do:
Hunt Strategy & Planning
- Own the hunt plan, building hypotheses from threat intel on US consumer finance, recent incidents and known telemetry gaps.
- Decide which hypotheses get hunt time and set priorities for the team.
- Help the client decide where GenAI-enabled capabilities add value to hunting and where they don't.
Hunt Execution
- Run scheduled and ad hoc hunts across CrowdStrike, Defender, Okta, Palo Alto, Proofpoint and AWS data in Elastic.
- Track living-off-the-land techniques, credential and session abuse, and lateral movement, mapped to MITRE ATT&CK.
- Sweep the estate for related activity to support Incident Response during major incidents.
Detection Handoff & Client Reporting
- Turn hunt outcomes into detection backlog items with Detection Engineering and make sure they ship.
- Write clear client hunt reports covering what was tested, found, ruled out and couldn't be tested.
- Present results directly to the client's security leadership.
Team Leadership
- Direct and review the work of two Senior Threat Hunters.
- Mentor the team on hypothesis design, tradecraft and query quality.
Tools & Technologies:
- Platforms & Infrastructure: Elastic Security (EQL, ES|QL), Splunk or Sentinel, Palo Alto, Proofpoint, VDI-based client environment.
- Security & Threat Intelligence: CrowdStrike Falcon, Microsoft Defender, SentinelOne, Okta, MITRE ATT&CK, MISP, OpenCTI, Recorded Future, FS-ISAC.
- Cloud & Data Analysis: AWS telemetry, Python, Jupyter.
What you bring:
- Experience: 4+ years in threat hunting, Tier 3 investigation or incident response, with hunts you can walk through from hypothesis to outcome.
- Querying: Fluent SIEM or data-platform querying (Elastic, Splunk, Sentinel or equivalent) across large data sets.
- Tradecraft: Solid MITRE ATT&CK knowledge and a sharp eye for LOTL, credential/session abuse and lateral movement in logs.
- Consulting / Leadership: Experience leading or mentoring hunters or analysts, and confidence presenting to client security leadership.
- Mindset: Hypothesis-driven, candid when a hunt comes up empty, and focused on getting detections shipped.
- Language: English at B2 or above.
- Nice to have: Elastic EQL/ES|QL, deep EDR experience, Okta and AWS hunting, threat intel platforms, Python/Jupyter, financial-sector threat knowledge (fraud, ransomware, BEC), detection writing, and GCTI, GDAT, GCIH or eCTHP certification.
- Clearance: Must pass identity, criminal-background, employment and education checks, repeated periodically.
- Location: On-site in Medellín, Bogotá or Buenos Aires, working US Eastern business hours.
Visa Sponsorship
AspenView does not sponsor employment visas for this role. Applicants must be permanently authorized to work in their country of residence and must not require visa sponsorship now or in the future.
Equal Opportunity Employer
AspenView is proud to be an equal opportunity employer. We believe in creating an environment where all employees feel welcome, valued, and empowered to succeed. We celebrate diversity and strive to build a culture of inclusion where all individuals, regardless of their race, color, gender, gender identity or expression, sexual orientation, disability, age, or any other characteristic, can thrive. We encourage applicants from all walks of life to join our team and make a lasting impact.