Threat Intelligence/Hunt Engineer

<p><b>What You'll Do  </b><br>This role delivers decision‑ready threat intelligence and intelligence‑driven threat hunting to reduce risk, improve detection, and strengthen enterprise security posture. The position partners across security and business functions, synthesizes multi‑source intelligence and telemetry, and executes hunts and investigations end‑to‑end with a focus on rigor, repeatability, and measurable outcomes. </p><p></p><p><b><span>Responsibilities:</span></b></p><ul><li>Translate evolving business risk and operational vulnerabilities into <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">clear, decision‑ready threat</span> intelligence and <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">briefings, providing actionable</span> insights that <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">enable timely risk</span> reduction, remediation, and mitigation.   </li></ul><ul><li>Partner <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">with cross‑functional technical</span> and business teams to <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">define, maintain,</span> and continuously adapt intelligence requirements as the threat landscape changes, ensuring intelligence <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">outputs remain relevant,</span> prioritized, and operationally actionable. </li></ul><ul><li>Synthesize diverse intelligence streams to assess adversary intent, capability, and risk to the organization.   </li></ul><ul><li><span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">Conduct in‑depth threat</span> research and evaluation of internal and external intelligence reporting while prioritizing emerging and ongoing threats to inform <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">strategic decision‑making and enterprise‑level risk</span> management. </li></ul><ul><li>Correlate internal telemetry, operational data, and external intelligence <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">to identify emerging</span> threats and evolving adversary activity. </li></ul><ul><li><span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">Independently identify when</span> high priority requirements require focus shift to <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">deliver high‑impact tactical</span> and operational support as the threat landscape changes. </li></ul><ul><li>Support and provide input to <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">an intelligence‑driven threat</span> hunting program with repeatable workflows, playbooks, and effective metrics. </li></ul><ul><li>Independently perform continuous hunt cycles and execute the full intel/ hunt <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">lifecycle—using hypothesis‑driven methods</span> and developing <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">deep proficiency with</span> EDR, SIEM, log analytics, network telemetry, and identity systems <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">to identify known</span> and unknown threats. </li></ul><ul><li><span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">Drive hypothesis‑led investigations</span> and hunts by performing exploratory analysis <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">across large‑scale datasets</span> to surface anomalies and weak signals by assessing exploitability in the context of the tech stack. </li></ul><ul><li><span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">Identify detection,</span> visibility, coverage, and mitigation gaps surfaced through intelligence analysis and threat hunting, and research root causes to partner with engineering teams for continuous <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">improvement.  </span></li></ul><ul><li>Contribute to structured documentation processes and methodologies to drive continuous <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">improvement — refining</span> priorities, processes, and tooling.  </li></ul><ul><li><span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">Independently identify new</span> problem spaces and proactively pursue solutions without waiting for direction </li></ul><p></p><p><b>What You Will Need to be Successful:</b></p><ul><li>Experienced practitioner (5 Years Plus) in threat intelligence and/or hunting, producing <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">rigorous, multi‑domain,</span> strategic, and predictive intelligence at scale.  </li></ul><ul><li>Ability to apply structured analytical techniques <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">to operate effectively</span> under uncertainty and incomplete data, forming <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">defensible, well‑supported analytic</span> judgments in <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">ambiguous, fast‑moving environments.  </span></li></ul><ul><li>Knowledge of multiple threat analysis and modeling frameworks (e.g., Diamond Model, MITRE ATT&CK, DREAD, PASTA) to create structured assessments, communicate risk clearly, and drive consistent, repeatable analysis. </li></ul><ul><li>Ability to define and <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">refine intelligence‑driven threat</span> hunts—using repeatable methodologies and playbooks, hunts at scale across diverse datasets, and documenting findings for both technical <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">and non‑technical audiences.  </span></li></ul><ul><li><span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">Hands-on expertise with</span> enterprise hunting tools and data platforms (SIEM, EDR, network telemetry, identity logs, cloud audit <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">pipelines)  </span></li></ul><ul><li>Technology-focused perspective; experience supporting or defining requirements tied to software, infrastructure, or security tooling  </li></ul><ul><li>Diverse <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">background/alternative</span> perspectives that strengthen analytical depth and <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">problem-solving  </span></li></ul><ul><li>Proven ability to translate threat intelligence and hunt findings <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">into decision‑ready insights</span> for technical <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">and non‑technical stakeholders,</span> including senior leadership </li></ul><ul><li>Experience working in a collaborative <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">environment—contributing</span> insights while integrating feedback and perspectives from others  </li></ul><ul><li>Highly self-directed and organized, effectively managing priorities and <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">deliverables end‑to‑end with</span> strong time management and communication. <br> </li></ul><p><b>What You May Need to be Successful:</b></p><ul><li>Experience integrating intelligence efforts across corporate security domains—partnering with Executive Protection, Insider Risk, Trust & Safety, and Physical Security teams, with exposure to geopolitical risk, fraud/insider threat, and supply chain risk.  </li></ul><ul><li>Experience partnering with detection engineering or red <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">teams to validate hypotheses</span> and strengthen threat coverage </li></ul><ul><li><span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">Hands‑on experience</span> <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">building/supporting automation,</span> scripting, or workflow optimization to scale intelligence production, research, or hunt <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">operations  </span></li></ul><ul><li>Familiarity with data engineering concepts relevant to hunting (e.g., pipeline quality, normalization, enrichment, log <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">onboarding)  </span></li></ul><ul><li>Prior experience presenting intelligence findings to senior leadership or executive <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">audiences  </span></li></ul><p></p><p><b>Why Join Us at First Advantage?</b></p><p>At First Advantage, team members are united around a noble purpose: helping organizations to safeguard their workplaces and manage risk. The company’s culture is shaped by its core values — Authenticity, Curiosity, Integrity, Teamwork, Customer-Inspired — empowering team members to bring their best ideas forward, collaborate across departments, and make a real impact.</p><p>First Advantage offers a variety of culture programs and benefits designed to enhance employee experience and development.</p><ul><li><h2>Employee Impact Groups</h2></li><li><h2>FA Cares volunteer opportunities</h2></li><li><h2>Mentorship Advantage Program</h2></li><li><h2>SOAR, award-winning manager development program</h2></li></ul><p><b>We have great people here and are looking for more. Come join us!</b><br> </p><p>Follow us:</p><ul><li><p><a href="https://www.facebook.com/FirstAdvantage1" target="_blank" rel="noopener noreferrer"><span style="color:#0875e1"><u>Facebook</u></span></a></p></li><li><p><a href="https://www.instagram.com/first_advantage/" target="_blank" rel="noopener noreferrer"><span style="color:#0875e1"><u>Instagram</u></span></a></p></li><li><p><a href="https://www.linkedin.com/company/first-advantage" target="_blank" rel="noopener noreferrer"><span style="color:#0875e1"><u>LinkedIn</u></span></a></p></li><li><p><a href="https://twitter.com/firstadvantage" target="_blank" rel="noopener noreferrer"><span style="color:#0875e1"><u>X</u></span></a></p></li><li><p><a href="https://www.youtube.com/user/FirstAdantage1" target="_blank" rel="noopener noreferrer"><span style="color:#0875e1"><u>YouTube</u></span></a></p></li></ul><p></p><p><i><b>Equal Employment Opportunities at First Advantage</b><br></i><span style="color:#000000"><i>First Advantage is an equal opportunity employer. We are committed to providing a workplace and recruitment process that is free from unlawful discrimination, harassment, and retaliation. Employment decisions at First Advantage are based solely on qualifications, merit, and business needs. We do not discriminate in any aspect of employment on the basis of race, color, national origin, ancestry, citizenship, religion, creed, sex, gender identity, gender expression, sexual orientation, marital or family status, pregnancy, age, physical or mental disability, medical condition, genetic information, veteran or military status, or any other characteristic protected by applicable law.</i></span></p>

Back to blog

Other Jobs To Apply