Senior Threat Hunting Engineer
Say hello to a rewarding career, and come join a leading provider of mission-critical background screening solutions to some of the most recognized Fortune 100 and Global 500 brands.
About the Role:
We are seeking a highly skilled Senior Threat Intel & Hunt Engineer to join our growing cybersecurity team. In this role, you’ll lead proactive threat detection and analysis efforts across the enterprise, mature threat intelligence capabilities, leverage a deep understanding of attacker behavior and endpoint/network telemetry to uncover advanced threats that evade traditional security tools.
Key Responsibilities:
- Conduct proactive threat hunts across endpoints, networks, cloud, products, and identity systems using data from EDR, SIEM, and threat intelligence platforms
- Develop and refine Threat Intelligence driven hypotheses based on threat actor tactics, techniques, and procedures (TTPs)
- Analyze complex datasets to identify malicious or anomalous behavior that indicates compromise
- Collaborate with threat intelligence, incident response, vulnerability management, and engineering teams to improve threat visibility and detection logic
- Create detailed hunt reports in collaboration with Threat Intelligence, communicate findings to key stakeholders, and recommend mitigations for security posture improvement.
- Continuously improve hunting methodologies and contribute to the development of threat hunting playbooks and tools
Requirements:
- 5+ years of experience in cybersecurity with at least 2 years focused on threat hunting, threat detection, or incident response
- Strong knowledge of adversary frameworks such as MITRE ATT&CK and familiarity with attacker TTPs
- Experience with EDR platforms (e.g., CrowdStrike, SentinelOne), SIEM tools (e.g., Splunk, Elastic), and scripting/query languages (e.g., Python, KQL, YARA)
- Ability to work independently to generate hunting hypotheses and follow them through to actionable findings
- Strong analytical skills and the ability to think like an adversary
- Excellent written and verbal communication skills
- Relevant certifications are a plus (e.g., GCTI, GCFA, GCIA, OSCP)
Preferred Qualifications:
- Experience working in cloud or hybrid environments (AWS, Azure, GCP)
- Familiarity with malware analysis, memory forensics, or reverse engineering concepts
- Prior experience supporting security operations in large, complex environments
Why First Advantage is Your Next Big Career Move
First Advantage is going through a technology transformation! We are looking for experts who are excited to work with advanced technologies and provide best-in-class user experiences, drive the development and deployment of scalable solutions, and smoothly guide our agile teams and clients through meaningful changes as we continue to expand our impact.
What Are You Waiting For? Apply Today!
You have learned a little about us today – we want to learn about you! If you think this position and our company are a great fit for your areas of interest and expertise, tell us about you by applying now!
The salary range for this position is approximately $150,000-180,000 base annually. This range reflects our good faith estimate to pay fairly as to what our ideal candidates are likely to expect, and we tailor our offers within the range based on the selected candidate’s experience, industry knowledge, technical and communication skills, and other factors that may prove relevant during the interview process.
United States Equal Opportunity Employment:
First Advantage is proud to be a global leader in removing barriers and supporting our community members to ensure the changing demographics of the workforce are reflected in our hiring and employment practices. We value all of our candidates, employees, and clients, and place great emphasis on hiring and supporting qualified individuals in each role. We are an equal opportunity employer. We do not discriminate on the basis of race, color, ethnicity, ancestry, religion, sex, national origin, sexual orientation, age, citizenship status, marital status, disability, gender identity, gender expression, veteran status, genetic information, or any other area protected by applicable law.