Cyber Security – Senior Threat Hunter
The opportunity:
We are looking for SOC L3 Threat Hunter is responsible for proactively identifying advanced, stealthy, and previously unknown threats across enterprise environments. This role operates beyond alert-driven SOC operations, focusing on hypothesis-based threat hunting, adversary behaviour analysis, and closing detection gaps across Microsoft Sentinel, Microsoft Defender for Endpoint, and Defender for IoT.
The role serves as a technical authority within the SOC, supporting L1/L2 analysts, partnering with Incident.Response and Detection Engineering teams, and continuously improving the organization’s threat visibility and SOC maturity.
Your key responsibilities:
- Conduct hypothesis-driven, TTP-centric threat hunts using telemetry from Microsoft Sentinel and Microsoft Defender platforms.
- Develop hunt hypotheses based on: Adversary campaigns, MITRE ATT&CK; techniques, Threat intelligence, Observed environmental weaknesses.
- Hunt for advanced attack behaviors.
- Validate findings with evidence and determine impact before escalation.
- Perform advanced KQL-based threat hunting across large data volumes in Microsoft Sentinel.
- Identify detection blind spots, noisy analytics, and data quality issues.
- Conduct advanced endpoint hunting using Defender Advanced Hunting.
- Correlate endpoint telemetry with SIEM data to reconstruct end-to-end kill chains.
- Perform threat hunting across IoT/OT and IC environments using Microsoft Defender for IoT telemetry where applicable.
- Produce formal threat hunt reports detailing: Hunt Hypothesis,
Data Sources, Findings, evidence, MITRE ATT&CK; mapping and recommended remediation.
Skills and attributes for success:
- 4–7+ years in SOC, Threat Hunting, Incident Response, or Detection Engineering.
- Proven experience performing proactive threat hunting (not tool monitoring).
- Experience working in enterprise-scale SIEM and EDR environments.
- Advanced expertise in MS Sentinel and Defender Suites.
- Strong mastery of KQL (Kusto Query Language).
- Deep understanding of MITRE ATT&CK;, Adversary tradecraft, Malware and post-exploitation techniques.
- Strong skills in Endpoint telemetry analysis, Network traffic analysis, Log correlation across multiple security layers.
- Advanced analytical and critical-thinking skills.
- Strong written and verbal communication.
- Curiosity-driven, attacker-mindset analysis.
- Ability to work independently on ambiguous, high-impact threats.
Qualifications:
- Bachelor’s degree or a master’s degree in computer engineering, IT security, Computer Science, Information Systems or other related fields.
- Highly proficient in English with good written and oral communication.
- Good analytical, problem solving and interpersonal skills.
What we offer
- Empowering Career Development: Unlock your potential with tailored training and development programs designed to elevate your skills and propel your career forward. We invest in your growth because your success is our success.
- Versátil Work-Life Integration: Enjoy the freedom of our hybrid work model, allowing you to blend professional responsibilities with personal passions. We understand that life is more than just work, and we support you in achieving that balance.
- Comprehensive Well-Being Programs: Prioritize your health with our extensive wellness initiatives, including psychological support sessions and health resources. At EY GDS Spain, your well-being is at the heart of what we do.
- Meaningful Volunteering Opportunities: Make a difference in your community through our engaging volunteering programs. Join us in giving back and creating a positive impact while building connections with like-minded colleagues.
- Recognized Performance and Rewards: Celebrate your achievements with our recognition programs that honor both individual and team successes. We believe in acknowledging hard work and dedication, ensuring you feel valued every step of the way.
Join us at EY GDS Spain, where your journey is supported, your contributions are celebrated, and your future is bright.
EY GDS Spain office is located at Malaga Technology Park and currently employs over 1000 people.
The exceptional EY GDS experience. It’s yours to build.
#J-18808-Ljbffr
📌 Threat Hunter - Senior - EY GDS Spain - Hybrid (Málaga)
🏢 Ey
📍 Málaga