Threat Hunting Investigator - 175938
REMOTE, Remote
Job Id:
0000175939
Job Category:
Cyber Security
Job Location:
REMOTE, Remote
Security Clearance:
No Clearance
Business Unit:
Piper Companies
Division:
Not Defined
Position Owner:
Elizabeth Britt
Piper Companies is looking to fill the role of Threat Hunter Investigator for a leading technology company located in Raleigh, NC. The Threat Hunter Investigator will identify, investigate, and mitigate risks largely posed by internal actors - whether malicious, negligent, or compromised. This role provides direct support to conduct research and investigations into threats and incidents related to protection of critical intellectual property. The Threat Hunter Investigator role is a remote position with EST hours.
Responsibilities of the Threat Hunter Investigator Include:
- Conduct proactive threat hunting and insider risk investigations using logs, endpoint telemetry, user activity, and behavioral indicators to identify potential security threats and malicious activity.
- Research, analyze, and mitigate threats involving sensitive data exposure, intellectual property theft, and other insider risk scenarios, while producing clear and defensible investigative reports.
- Design, develop, test, deploy, and tune advanced threat detections using Splunk SPL, translating threat intelligence, threat hypotheses, and investigative findings into production-ready detection content.
- Build and maintain Risk-Based Alerting (RBA) workflows, including correlation searches, risk rules, risk scoring, notable events, and automated response actions within Splunk Enterprise Security.
- Configure and optimize UEBA detections, anomaly models, and behavioral analytics to identify suspicious user and entity activity across endpoint, network, cloud, and application environments.
- Create technical documentation, runbooks, and operational standards while continuously validating detection effectiveness through testing, tuning, false-positive reduction, and coverage analysis aligned to MITRE ATT&CK methodologies.
Qualifications for the Threat Hunter Investigator Include:
- Bachelor's degree in computer science, Information Systems, Cybersecurity, or related field.
- 8+ years of experience conducting threat investigations, insider threat analysis, and digital forensic investigations involving endpoint devices and sensitive data.
- Strong hands-on experience with Splunk Enterprise Security, including engineering, tuning, and maintaining security detections in a production environment.
- Proven ability to write advanced SPL queries from scratch and develop correlation searches, custom detections, and threat-hunting content.
- Deep experience with Risk-Based Alerting (RBA) and User and Entity Behavior Analytics (UEBA), including risk scoring, behavioral baselining, anomaly detection, and alert prioritization.
- Strong understanding of detection engineering and threat hunting methodologies, with the ability to translate threat intelligence and MITRE ATT&CK techniques into actionable detections and response workflows.
Compensation for the Threat Hunter Investigator Includes:
- $140,000-$165,000 annually
- Comprehensive Benefits: Medical, Dental, Vision, 401(k), PTO, Sick Leave if required by law, and Holidays
This job opens for applications on 10/6/26. Applications for this job will be accepted for at least 30 days from the posting date.
Keywords: threat detection, threat investigator, splunk, insider risks,
#LI-EB1 #REMOTE