Back to jobs

Threat Hunting Analyst

Hack in HireMadrid, Community of Madrid, SpainPosted 2w ago
Cybersecurity Analyst
Apply on LinkedIn

Job Description

We, on behalf of our client, are looking for a Threat Hunting Analyst / Purple Team

The area is organized into two complementary teams: Purple Team and Threat Hunting. Currently, the main focus is on the design and deployment of Deception campaigns, as well as ongoing coverage against MITRE ATT&CK TTPs and end-to-end analysis of monitoring rules, with an approach that combines offense and response (Purple Team style).


Main responsibilities


  • Design, deploy, and maintain Deception campaigns.
  • Identify and prioritize relevant TTPs, evaluate current coverage (SIEM/EDR), and detect gaps.
  • Develop new detection rules when a deficiency is identified (in EDR, SIEM, or both, as appropriate), justifying the choice of tool.
  • Investigate in depth when coverage analysis reveals anomalous or suspicious behavior, escalating to the relevant teams when necessary.
  • Audit existing monitoring rules through the complete workflow: attack/event generation, verification that the alert is triggered, and analysis of the generated ticket (fields, response times, actions taken: blocking, user contact, etc.).
  • Independently explore EDR telemetry in high-volume data environments to identify patterns, hunting hypotheses, and improvement opportunities without constant detailed instructions.


Desired profile


  • True autonomy: ability to investigate, prioritize, and move forward without constant supervision. We are looking for a decisive individual, not someone who needs to be told every step.
  • Hands-on experience with EDR (queries, telemetry, creating detection rules) and SIEM.
  • Solid knowledge of the MITRE ATT&CK framework and its practical application (mapping TTPs to detections).
  • Combined attack and defense mindset: ability to think like an attacker to design validations and like a SOC analyst to evaluate the response.
  • Curiosity and initiative to delve deeper into findings that were not within the initial scope of a task.
  • Preferred: Previous experience in Purple Team, Threat Hunting, or Detection Engineering in high-volume telemetry environments.
  • Preferred: Experience with deception platforms or techniques.


Especially valued


  • Proven ability to work with large volumes of data/telemetry and extract signal from noise.
  • Experience writing detection rules from scratch (not just adjusting existing rules).
  • Strong documentation and communication skills, as the work involves conveying technical findings to other teams.