Threat Hunting Consultant in Brazil at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Threat Hunting Consultant based in Brazil.
This role offers the opportunity to strengthen enterprise security through proactive threat hunting, advanced detection engineering, and incident response. You will investigate sophisticated threats across endpoint, identity, network, and security analytics environments. The position combines hands-on technical investigation with the development of high-fidelity detections and defensive capabilities. You will leverage Microsoft Defender, Splunk, behavioral analytics, and threat intelligence to identify and disrupt attacker activity. Your work will help reduce false positives, improve detection coverage, and strengthen incident response readiness. You will collaborate with security teams while contributing expertise, documentation, training, and mentoring in a security-focused environment.
- Conduct hypothesis-driven threat hunts across endpoint, identity, network, and security analytics environments to uncover malicious activity and previously undetected threats.
- Use Microsoft Defender for Endpoint, Microsoft 365 Defender/XDR, Splunk Enterprise Security, Splunk UBA, and related platforms to investigate suspicious activity and identify attacker behaviors.
- Develop and refine high-fidelity detection rules, correlation searches, and threat-hunting queries using KQL and SPL while minimizing false positives.
- Apply the MITRE ATT&CK framework and current attacker TTPs to guide threat-hunting activities, detection coverage, and defensive improvements.
- Perform incident response, endpoint forensics, malware analysis, and technical investigations to determine the scope, impact, and root cause of security incidents.
- Translate threat intelligence into actionable detection logic, hunting hypotheses, response procedures, and other defensive measures.
- Analyze Windows systems, processes, Active Directory, Azure AD, Kerberos, NTLM, network protocols, traffic patterns, and common attack vectors during investigations.
- Develop and improve incident response playbooks and automation using PowerShell and/or Python to increase investigation and response efficiency.
- Document findings, investigative procedures, detection logic, and security recommendations while communicating technical insights clearly to stakeholders.
- Support security capability development through knowledge sharing, training, mentoring, and continuous improvement of threat detection and response practices.
- 5+ years of relevant experience in threat hunting, detection engineering, incident response, cybersecurity operations, or a closely related security discipline.
- Extensive hands-on experience with Microsoft Defender for Endpoint and strong knowledge of Microsoft 365 Defender/XDR security operations.
- Expert-level experience with Splunk Enterprise Security, including advanced SPL for threat hunting, correlation, and security investigations.
- Experience with Splunk UBA or comparable behavioral analytics platforms.
- Advanced proficiency in Kusto Query Language (KQL) and strong ability to develop sophisticated hunting and detection queries.
- Proven experience conducting hypothesis-driven threat hunts and identifying sophisticated attacker behaviors and TTPs.
- Strong understanding of the MITRE ATT&CK framework and practical knowledge of modern attack techniques.
- Demonstrated ability to develop high-fidelity detection rules with strong detection coverage and low false-positive rates.
- Hands-on experience with incident response, endpoint forensics, malware analysis, and security investigations.
- Knowledge of NIST and SANS incident response frameworks and experience developing or maintaining response playbooks.
- Strong understanding of Windows internals, processes, security architecture, Active Directory, Azure AD, Kerberos, and NTLM.
- Knowledge of network protocols, traffic analysis, common attack vectors, and network-based indicators of compromise.
- Scripting and automation experience using PowerShell and/or Python.
- Strong analytical, problem-solving, documentation, communication, training, and mentoring skills.
- Annual salary range of $110,000–$130,000.
- Full-time opportunity focused on advanced cybersecurity, threat hunting, and detection engineering.
- Remote work environment with flexibility to collaborate from India.
- Opportunity to work with leading security technologies including Microsoft Defender, Splunk Enterprise Security, and behavioral analytics platforms.
- Exposure to complex security investigations, enterprise-scale threat detection, incident response, and security automation.
- Opportunities to contribute to security strategy, knowledge sharing, training, and technical mentoring.