Back to jobs
Threat Hunting Analyst
Hack in HireMadrid, Community of Madrid, SpainPosted 2w ago
Cybersecurity Analyst
Job Description
We, on behalf of our client, are looking for a Threat Hunting Analyst / Purple Team
The area is organized into two complementary teams: Purple Team and Threat Hunting. Currently, the main focus is on the design and deployment of Deception campaigns, as well as ongoing coverage against MITRE ATT&CK TTPs and end-to-end analysis of monitoring rules, with an approach that combines offense and response (Purple Team style).
Main responsibilities
- Design, deploy, and maintain Deception campaigns.
- Identify and prioritize relevant TTPs, evaluate current coverage (SIEM/EDR), and detect gaps.
- Develop new detection rules when a deficiency is identified (in EDR, SIEM, or both, as appropriate), justifying the choice of tool.
- Investigate in depth when coverage analysis reveals anomalous or suspicious behavior, escalating to the relevant teams when necessary.
- Audit existing monitoring rules through the complete workflow: attack/event generation, verification that the alert is triggered, and analysis of the generated ticket (fields, response times, actions taken: blocking, user contact, etc.).
- Independently explore EDR telemetry in high-volume data environments to identify patterns, hunting hypotheses, and improvement opportunities without constant detailed instructions.
Desired profile
- True autonomy: ability to investigate, prioritize, and move forward without constant supervision. We are looking for a decisive individual, not someone who needs to be told every step.
- Hands-on experience with EDR (queries, telemetry, creating detection rules) and SIEM.
- Solid knowledge of the MITRE ATT&CK framework and its practical application (mapping TTPs to detections).
- Combined attack and defense mindset: ability to think like an attacker to design validations and like a SOC analyst to evaluate the response.
- Curiosity and initiative to delve deeper into findings that were not within the initial scope of a task.
- Preferred: Previous experience in Purple Team, Threat Hunting, or Detection Engineering in high-volume telemetry environments.
- Preferred: Experience with deception platforms or techniques.
Especially valued
- Proven ability to work with large volumes of data/telemetry and extract signal from noise.
- Experience writing detection rules from scratch (not just adjusting existing rules).
- Strong documentation and communication skills, as the work involves conveying technical findings to other teams.