About the role

Working remotely on a full-time basis, the Threat Investigator will identify, investigate, and respond to advanced threats across enterprise environments, utilizing expert-level Splunk skills and supporting CSIRT operations.
Key responsibilities: Write and optimize complex SPL queries to identify threats and enhance detection capabilities Leverage UEBA technologies to analyze user behaviors and investigate potential security incidents Support CSIRT operations by conducting threat investigations and assisting with incident response efforts
Required qualifications: 4+ years of experience in threat hunting, threat investigation, incident response, or cybersecurity operations Expert-level experience with Splunk, including advanced SPL development and dashboard creation Strong hands-on experience with UEBA platforms and behavioral analytics methodologies Experience supporting CSIRT functions and investigating complex security incidents Knowledge of MITRE ATT&CK, threat intelligence, and modern detection engineering practices

Matching similar jobs

JOB OVERVIEW

Experience level

Senior

Location

Denver, CO

Occupation

Information Security Analysts

Industry

Computer Systems Design Services

Posted

today

Tired of running searches?

Rank the roles you'd take once, and matches like these arrive on their own.

CREATE PROFILE