Conduct proactive threat hunting across Cloud and On‑Prem enterprise environments to identify malicious activity, anomalies, and emerging threats.
Perform in‑depth investigations using SIEM technologies, leveraging strong query and analysis skills to detect adversary behaviors and indicators of compromise.
Analyze authentication flows, access patterns, and system telemetry to uncover potential compromise or advanced attacker techniques.
Utilize cyber threat intelligence, the MITRE ATT&CK framework, and emerging threat research to inform hunting strategies and detection engineering.
Investigate and respond to high‑impact security incidents, collaborating closely with CSIRT and cross‑functional teams to contain and remediate threats.
Partner with SIEM administrators, vendors, and offensive cybersecurity teams to enhance threat visibility and detection capabilities.
Develop and maintain detection logic, contributing to the full detection development lifecycle and identifying opportunities for detection improvements.
Apply offensive knowledge to strengthen hunting methodologies and validate detection coverage.
Document findings, investigations, and procedures with strong writing, communication, and operational discipline.
Support continuous improvement efforts, including planning, operational procedure refinement, and readiness activities within the CSIRT.
Provide after‑hours support as part of a rotating on‑call schedule, including responding to high‑priority alerts and security incidents.
Requirements
Experience in cybersecurity within a global enterprise environment.
Experience performing Cybersecurity Threat Hunting across Cloud and On‑Prem environments.
Experience with offensive security techniques and applying that knowledge to improve detection and hunting.
Strong understanding of incident response operations, tools, methodologies, and investigation workflows.
Knowledge of threat hunting methodologies, cyber threat intelligence, and the MITRE ATT&CK framework.
Experience working within SIEM platforms, including building and tuning queries and analyzing diverse log sources.
Ability to develop and enhance detection logic and contribute to the detection engineering lifecycle.
Strong documentation, writing, and communication skills for both technical and non‑technical audiences.
Ability to collaborate effectively across SIEM administrators, vendors, offensive security teams, and CSIRT.
Tech Stack
Cloud
Cyber Security
Benefits
Medical, dental, and vision benefits*
Paid time off plan (Vacation, Holidays, Volunteer, etc.)*
401(k) savings plans*
Health Savings Account (HSA)*
Flexible Spending Accounts (FSAs)*
Health Lifestyle Programs*
Employee Assistance Program*
Voluntary Benefits and Employee Discounts*
Career Development*
Incentive bonus*
Disability benefits
Life Insurance
Parental leave
Adoption benefits
Tuition Reimbursement
Senior Cybersecurity Threat Hunter at Caterpillar Inc. | JobVerse