Threat Hunt Senior Associate
DTCC
Threat Hunt Senior Associate
Are you ready to make an impact at DTCC?
Do you want to work on innovative projects, collaborate with a dynamic and supportive team, and receive investment in your professional development? At DTCC, we are at the forefront of innovation in the financial markets. We are committed to helping our employees grow and succeed. We believe that you have the skills and drive to make a real impact. We foster a thriving internal community and are committed to creating a workplace that looks like the world that we serve.
The Information Technology group delivers secure, reliable technology solutions that enable DTCC to be the trusted infrastructure of the global capital markets. The team delivers high-quality information through activities that include development of essential, building infrastructure capabilities to meet client needs and implementing data standards and governance.
Pay and Benefits:
- Competitive compensation, including base pay and annual incentive
- Comprehensive health and life insurance and well-being benefits, based on location
- Pension / Retirement benefits
- Paid Time Off and Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
- DTCC offers a flexible/hybrid model of 3 days onsite and 2 days remote (onsite Tuesdays, Wednesdays and a third day unique to each team or employee).
The Impact you will have in this role:
Being a member of CISO Team and as a Threat Hunt Senior Associate, you will execute hypothesis-driven hunts across endpoint, identity, network, and cloud telemetry; track and document hunt activity end-to-end; and translate findings into actionable improvements, detections, response playbooks, hardening tasks, and prioritized engineering work.
This role is hands-on and requires a practitioner mindset: you'll spend your time asking better questions of the data, validating what "normal" looks like in complex systems, and proving or disproving attacker behaviors using repeatable methods. You'll also provide surge support to incident response during investigations where hunt techniques accelerate containment and root cause analysis.
This is a mid-level role for someone who can operate independently on scoped hunts, communicate clearly, and contribute to a sustained, measurable hunting program.
Your Primary Responsibilities:
Hunt Execution & Documentation (Core)
- Execute hypothesis-based threat hunts mapped to MITRE ATT&CK tactics/techniques, focusing on realistic adversary behaviors (credential access, persistence, lateral movement, defense evasion, and cloud abuse).
- Use behavioral analytics and anomaly detection to identify suspicious patterns across endpoint + identity + cloud + network telemetry, then validate with deeper artifact review.
- Perform, track, and record hunt activity in a structured way: hypotheses, datasets queried, query versions, findings (positive/negative), evidence, confidence, and follow-up actions.
- Maintain clean, audit-ready hunt notes that allow another analyst to reproduce your work and understand decisions made under uncertainty.
Investigative Workflows & Telemetry Correlation
- Correlate logs across EDR/XDR, SIEM, cloud control plane logs, identity logs, and container/Kubernetes telemetry to build a coherent narrative from partial signals.
- Investigate attacker tradecraft such as:
- Credential theft and replay (token theft, OAuth abuse, suspicious refresh patterns)
- "Living off the land" execution (PowerShell, WMI, LOLBins on Windows; bash/curl/wget/systemd on Linux)
- Persistence mechanisms (scheduled tasks/cron, service modifications, registry run keys, launch agents)
- Command-and-control behaviors and egress anomalies (beaconing, domain fronting indicators, unusual TLS fingerprints where available)
- Cloud and Kubernetes abuse (suspicious role assumptions, unusual API call sequences, kubeconfig access, container escape precursors)
- Triage and deepen suspicious signals into defensible findings: timeline, scope, impact, root cause, and containment recommendations.
Detection Engineering & Continuous Improvement
- Translate hunt results into durable controls: new detections, tuning improvements, telemetry onboarding, or gaps to address (instrumentation, logging coverage, parsing, enrichment).
- Draft and iterate detection logic (e.g., Sigma/YARA, SIEM analytics rules, EDR custom IOAs) with measurable success criteria: false-positive rate, time-to-detect improvements, and coverage mapped to ATT&CK.
- Partner with SOAR/automation engineers to operationalize repetitive enrichment and triage steps into playbooks.
Purple Teaming & Adversary Simulation
- Collaborate with Red Team / Purple Team efforts to validate detection coverage, refine alerts, and ensure hunts align to current and relevant TTPs.
- Help design and execute controlled simulations (atomic tests, adversary emulation plans), then close the loop by updating detections, documentation, and response procedures.
- Incident Support (When Needed)
- Provide incident surge support: rapid scoping queries, hunting for related activity, identifying patient-zero candidates, and strengthening containment decisions with evidence.
- Contribute to post-incident reviews by identifying detection gaps, improving playbooks, and capturing lessons learned as backlog items.
**NOTE: The Primary Responsibilities of this role are not limited to the details above. **
Qualifications:
- Min 3-6 years of relevant experience
- Bachelor's Degree and/or equivalent experience
- 3-6 years in Threat Hunting, Detection Engineering, Incident Response, or SOC investigations in a production environment (financial services/fintech experience is a plus but not required).
- Demonstrated experience running hypothesis-driven hunts and documenting outcomes in a way that supports repeatability and measurement.
- Strong log analysis skills and comfort working across multiple telemetry sources (endpoint, identity, network, cloud).
- Practical detection and query experience in one or more:
- KQL (Microsoft Sentinel / Defender)
- Splunk SPL
- Elastic/Kibana (EQL/KQL/Lucene)
- Chronicle/Google SecOps query language or equivalent
- Solid operating system fundamentals:
- Windows internals basics (process ancestry, services, scheduled tasks, registry persistence)
- Linux fundamentals (systemd, cron, auth logs, process/network inspection)
- Familiarity with attacker tradecraft and investigative methods aligned to MITRE ATT&CK ability to map raw evidence to techniques without forcing it.
- Ability to communicate clearly—writeups that separate observation from inference, quantify confidence, and identify next steps.
- Proven ability to prioritize: know when you have enough evidence to escalate vs. when to keep iterating.
Talents Needed for Success:
- Experience hunting across cloud + containerized environments (AWS/Azure/GCP; Kubernetes; CI/CD telemetry).
- Experience developing or tuning detections using Sigma, YARA, EDR custom detections, or SIEM correlation rules.
- Familiarity with NIST CSF / NIST 800-61 incident response concepts and how hunting feeds detection/response maturity.
- Experience with SOAR automation, enrichment pipelines, and case management workflows.
- Comfortable scripting for analysis and automation (Python, PowerShell, Bash) and using tools like jq, osquery, CyberChef.
Certifications (any of the following are valued):
- GCFA, GCIH, GCIA
- OSCP (useful signal for investigative depth; not required)
- CISSP (helpful for program maturity context; not required)
Tools & Technologies
You won't need every item day one—but you should be comfortable learning quickly and working across a modern stack.
EDR/XDR: Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne (
$80k - $110k
...investors and counsel in identifying, assessing, and mitigating risks associated with AI system deployment, algorithmic bias, data privacy, and... ...including AI system security architecture reviews, threat models specific to ML pipelines, compliance mappings, and remediation...SeniorPart timeFlexible hours- ...Shutts & Bowen LLP is looking for a mid to senior-level associate to join their Land Use and Zoning Practice in Miami. The role involves advising clients on zoning, land use, and development matters, ensuring regulatory compliance, and navigating government processes....Senior
- ...Decentralized Masters in Miami, Florida seeks an experienced VC Senior Associate to manage deal processes from screening to closure. Ideal candidates have 3-5 years in venture capital or investment banking, with a strong ability in financial modeling and producing investment...Senior
- ...cybersecurity, focusing on delivering exceptional services to clients. This role involves implementing advanced security technologies and strategies to protect client operations, providing insights and guidance for incident response and threat detection. #J-18808-Ljbffr...Senior
- Nicklaus Children's Health System in Miami is looking for a professional to support the Annual Giving office in developing and implementing key fundraising programs. This role involves engaging with donors, managing grassroots fundraising events, and overseeing donor relations...SeniorWork at office
- Kaseya Limited is seeking a highly Senior Technical Product Manager for Threat Detection Efficacy to enhance security product effectiveness. This role involves improving detection efficacy and working closely with various teams to identify gaps and drive measurable improvements...Senior
- Kaseya Limited in Miami is seeking a Senior Technical Product Manager for Threat Detection Efficacy. This role focuses on improving the effectiveness of security products, requiring strong expertise in endpoint security and collaboration with various teams to enhance detection...Senior
- ...role Are you skilled at developing wealth management strategies? Does financial data excite you? We’re looking for a Senior Wealth Strategy Associate to: Assist Financial Advisors with client/potential client meetings and provide support for client relationship building...SeniorFull time
- ...A leading consulting firm is seeking an HRIS Oracle Senior Associate specializing in Performance Management and Oracle Journeys to enhance their employee lifecycle processes. The role requires 4+ years of HRIS experience, particularly with Oracle HCM systems. You will...Senior
- Hut 8 in Miami, Florida is looking for an Associate or Senior Associate to support the Head of Corporate Finance. This role is pivotal in evaluating strategic financial initiatives, including M&A opportunities in AI and energy sectors. The ideal candidate will have a background...Senior
- A leading professional services firm is seeking a Senior Associate for their EY-Parthenon team in Miami. The role involves managing M&A advisory, analyzing financial aspects, and offering negotiation support to clients. Candidates should possess a bachelor's degree in...Senior
- Fontainebleau Development is hiring a Senior Design Associate to work in Miami. This role focuses on the design and development of high-end projects, particularly in Food & Beverage and amenity spaces, from concept to construction. Ideal candidates will have a professional...Senior
- Bennett Thrasher in Miami is seeking a Senior Associate to join their Transaction Advisory team. This role involves facilitating buy-side and sell-side advisory engagements, and requires strong accounting principles and Excel proficiency. The ideal candidate will have...Senior
$75k - $80k
...Connect organic performance to business outcomes, translating complex SEO and AEO concepts into clear, actionable recommendations for senior stakeholders. Help clients understand how evolving search behavior impacts brand visibility, competitive positioning, and growth...SeniorFlexible hoursShift work$96.8k - $159.6k
Ernst & Young Oman is seeking a Senior Associate for their Financial Diligence team. This role involves analyzing financial data, writing reports, and discussing key business performance metrics with management. Candidates should have a strong background in accounting...SeniorFlexible hours- ...Professionals Make the Move Gain exposure to large, complex organizations, including Fortune 500 companies Work directly with senior tax leaders and business executives Develop a broader commercial and operational understanding of corporate tax Build...SeniorPermanent employmentWork at office
- ...always at the forefront of our operations. Position Summary BBVA Global Wealth Advisors is seeking a motivated and analytical AML Senior Associate to join our growing Compliance Team. This role serves as a crucial pillar in our financial crime prevention program. The...SeniorShift work
- BCG Attorney Search is looking for a mid-to-senior level Corporate Associate in Miami, FL, with 3-5 years of experience in M&A transactions. The ideal candidate will handle M&A transactions, advise on private equity, assist with joint ventures, and provide guidance on...Senior
$390k
A leading global law firm in Miami is seeking a Senior Associate with a minimum of five years experience in international arbitration and litigation. The ideal candidate must possess strong writing and negotiation skills and the ability to communicate effectively. This...Senior- ...Are you skilled at developing wealth management strategies? Does financial data excite you? We're looking for a Senior Wealth Strategy Associate to: • Assist Financial Advisors with client/potential client meetings and provide support for client relationship building...SeniorFlexible hours
- Kaseya Limited is seeking a Threat Detection Analyst to enhance its detection and response capabilities. This role involves investigating security alerts and improving detection logic to ensure a robust security posture across Kaseya’s platforms. Candidates should have...Senior
$77k - $202k
Description SummaryAt PwC, our people in infrastructure focus on designing and implementing robust, secure IT systems that support business operations. They enable the smooth functioning of networks, servers, and data centres to optimise performance and minimise downtime...Senior- ...and service industries. Boyne Capital offers team members broad participation in the investments and the GP of the Fund. As Senior Associate of Portfolio Operations, you will play a key role in augmenting our investment thesis by ensuring that operational strategies...Senior
- Job Overview Job OverviewA law firm seeks a Senior Associate with 5-7 years of litigation experience for their insurance coverage practice group in Miami, Florida. This role involves representing US and foreign insurance companies in complex coverage litigation and market...SeniorFlexible hours
- ...progression, and a culture that values depth, quality, and genuine collaboration. The Associate Executive Search will join a high-performing team delivering retained mandates for senior leadership roles across North America, Europe, and Asia. Responsibilities Conduct...SeniorWork at officeWork from home
- Position Summary Shutts & Bowen is seeking a Senior Associate or Partner for our Corporate Group in our Miami office. The successful candidate will have 6-15 years of relevant experience in the areas of mergers & acquisitions, joint ventures, fundraising documentation/...SeniorWork at office
- ...multifamily acquisitions and are actively expanding our investor base and portfolio nationwide. The Opportunity We’re hiring a Senior Investor Relations Associate to lead investor engagement, communication, and onboarding efforts for our growing portfolio of funds. This is a high...Senior
- ...Florida. The position is also not eligible for work authorization sponsorship. Position Summary The BIM Sr. Associate is responsible for the technical execution and quality control of Building Information Modeling (BIM) data across the Newbuild...SeniorFull timeWork at office
$2,000 per month
The Miami office of Clyde & Co seeks an Attorney with 5-7 years of litigation experience for our insurance coverage practice group. Responsibilities Analyze insurance policies, draft coverage opinions and provide coverage recommendations for clients. Conduct legal research...SeniorTemporary workWork at officeRemote workFlexible hours- Job Description Job Description SUMMARY : Provides administrative, analytical, and transactional support to CRE lenders throughout the loan lifecycle. This role is responsible for coordinating loan documentation, assisting with underwriting and closing processes, ...SeniorPermanent employmentWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Threat Hunt Senior Associate. Be the first to apply!


