
Senior Cloud Threat Hunter – AWS
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in United States.
• Leverage the Falcon platform and threat intelligence to assess cloud logs and pinpoint both historical and current threats.
• Establish and evaluate cloud security configurations, searching for anomalies linked to threat activities.
• Create queries and scripts to manage extensive data sets, correlate information across various sources, and detect outliers indicative of potential threats.
• Identify identity and control plane configurations that could render cloud environments vulnerable to threats and unauthorized access.
• Oversee the complete lifecycle of client projects, encompassing project management, communication, status reports, and task distribution.
• Generate high-quality written and verbal reports, presentations, recommendations, and findings for customer management, regulators, legal counsel, internal stakeholders, and clients.
• Execute threat hunting in cloud environments for intricate, high-profile organizations globally.
• Analyze cloud control plane configurations and offer technical suggestions to minimize adversary opportunities.
• 3-5 years of practical threat hunting experience in cloud environments, preferably with AWS.
• Comprehensive understanding of cloud adversary Tactics, Techniques, and Procedures (TTPs), including attack path chaining and data enrichment with threat intelligence.
• Extensive knowledge of the AWS platform, covering logging, identity, networking, workload security, data security, and multi-account management practices.
• Strong grasp of AWS security architecture patterns, including log management architecture and automation practices utilizing AWS-native services.
• In-depth knowledge of security configuration and architecture of CI/CD pipelines.
• Proficient in writing modular scripts and software tools in Python or Go to interact with AWS services and Falcon APIs.
• Demonstrated experience using AI technologies to enhance decision-making, optimize workflows and processes, boost efficiency, and drive business results.
• Strong capability to verbally convey technical concepts and findings in clear language to both technical and non-technical audiences, including CISO-level stakeholders.
• Exceptional technical writing abilities and capacity to produce high-quality written reports and presentations.
• Meticulous attention to detail, effective time management, delegation skills, and excellent organizational capabilities.
• Candidates may be required to periodically undergo and pass alcohol and/or drug tests during employment.
• CrowdStrike is an E-Verify participant.
• Leader in market compensation and equity awards.
• Comprehensive wellness programs addressing both physical and mental health.
• Competitive vacation and holidays to allow for recharging.
• Paid parental and adoption leave.
• Professional development opportunities available for all employees, regardless of level or role.
• Employee Networks, geographic neighborhood groups, and volunteer opportunities to foster connections.
• Dynamic office culture boasting world-class amenities.
• Eligibility for bonuses.
• Equity grants.
• Health insurance.
• 401k plan.
• Paid time off.
TRM Labs
Instituto Hardware BR HBR
Mitiga
Cellebrite
Get handpicked remote jobs straight to your inbox weekly.