Threat Hunting Investigator

remote

Zachary Piper Logo

Job Id:
0000176036

Job Category:
Information Technology

Job Location:
remote

Security Clearance:
No Clearance

Business Unit:
Piper Companies

Division:
Not Defined

Position Owner:
Bailey Horne

Piper Companies is seeking a Threat Hunting Investigator to support insider threat investigations, threat hunting operations, and critical intellectual property protection initiatives. This individual will work closely with Security & Trust, Global Security & Executive Protection, and Incident Detection & Response teams to identify, investigate, and mitigate risks posed by malicious, negligent, or compromised insiders. This is a full-time contract opportunity supporting a fast-paced, collaborative environment focused on advanced threat detection, incident response, and insider risk management. This is a remote opportunity located in the US and must be able to hold a clearance.

 

Responsibilities for the Threat Hunting Investigator include:

·      Conduct proactive threat hunting activities focused on insider threats, intellectual property theft, and emerging security risks.

·      Analyze logs, telemetry, behavioral indicators, and endpoint data to identify suspicious activity and potential threat actors.

·      Perform digital investigations, forensic analysis, and data triage to support incident response and risk mitigation efforts.

·      Develop and present clear investigative findings, technical reports, and recommendations to stakeholders.

·      Design, develop, test, deploy, and maintain advanced threat detections within Splunk Enterprise Security, Risk-Based Alerting (RBA), and UEBA environments.

·      Translate threat intelligence, MITRE ATT&CK techniques, and investigative findings into scalable detection logic and response workflows.

·      Validate and tune detection content through testing, false-positive analysis, telemetry reviews, and continuous improvement initiatives.

 

Qualifications for the Threat Hunting Investigator include:

·      Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related technical field required.

·      8+ years of experience conducting insider threat investigations, evaluating risks, and implementing security countermeasures.

·      8+ years of experience performing digital forensic investigations, data triage, and endpoint analysis.

·      5+ years of hands-on experience engineering and operating Splunk security detections, including Splunk Enterprise Security and Risk-Based Alerting (RBA).

·      Strong expertise developing production-grade detection content utilizing advanced SPL, correlation searches, risk rules, notable events, and adaptive response actions.

·      Experience with Splunk UEBA or comparable behavioral analytics platforms, including anomaly detection, risk scoring, and user/entity behavior analysis.

·      Experience analyzing AWS CloudTrail, endpoint, identity, network, SaaS, and insider-risk telemetry data is highly preferred.

·      Experience with security tools such as Code42, Microsoft Defender, Digital Guardian, or similar insider-risk monitoring platforms is a plus.

 

Compensation for the Threat Hunting Investigator includes:

·      Salary range: $140,000 - $170,000

·      Comprehensive Benefits: Medical, Dental, Vision, 401(k), and applicable sick leave

 

Keywords: Threat hunting, insider threat investigations, threat detection, detection engineering, digital forensics, incident response, security operations, intellectual property protection, Splunk Enterprise Security (ES), Splunk UEBA, Splunk SIEM, Splunk SPL, Risk-Based Alerting (RBA), correlation searches, risk rules, notable events, adaptive response actions, MITRE ATT&CK, threat intelligence, endpoint forensics, data triage, log analysis, telemetry analysis, AWS CloudTrail, cloud security, network security, identity analytics, user activity monitoring, Code42, Microsoft Defender, Digital Guardian, SIEM, UEBA, anomaly detection, behavioral analytics, Python, C++, Verilog, scripting, detection development, detection testing, detection tuning, security analytics, investigative reporting, forensic investigations, insider risk monitoring, endpoint telemetry, network telemetry, SaaS telemetry, security monitoring, threat research, detection content, security use cases, operational runbooks, security metrics, and technical documentation.


#LI-BH1

#REMOTE

 

This job is open for applications on 10/8/2026 and will remain open for at least 30 days from the posting date

Apply For This Position

Personal Information

Required
Required
Required
Required
Required
Required
Required

Additional Details

Required
Required
Required

Voluntary Self-identification Form

Required
Required
Required

Veteran Status *

Discharge Date:

Resume Upload

Please note only files with .pdf, .docx, or .doc file extensions are accepted.

Currently selected file:

Don't have a resume?