Cyber Security Threat Hunter
Location: Centurion, Gauteng (provisional – to be confirmed)
Positions Available: 5
Salary: Market-related
Employment Type: To be confirmed
Job Overview
We are seeking experienced and highly skilled Cyber Security Threat Hunters to proactively identify, investigate and analyse sophisticated cybersecurity threats across complex enterprise IT environments.
The successful candidates will be responsible for identifying malicious activities, advanced persistent threats, hidden compromises and suspicious behaviours that may not be detected by traditional automated security monitoring technologies.
This role requires strong hands-on expertise in proactive threat hunting, advanced security investigations, threat intelligence, endpoint and network telemetry analysis, and enterprise security monitoring technologies.
The ideal candidates will have proven experience developing threat-hunting hypotheses, analysing large volumes of security data, identifying attacker tactics, techniques and procedures (TTPs), and uncovering potential security compromises across endpoints, networks, identities and cloud environments.
Unlike a traditional SOC Analyst who primarily investigates alerts generated by security monitoring systems, a Cyber Security Threat Hunter proactively searches for threats that may have bypassed existing security controls or remain undetected within the organisation.
Key Responsibilities
Proactive Cybersecurity Threat Hunting
- Conduct proactive threat-hunting activities across enterprise networks, endpoints, servers, applications and cloud environments.
- Identify suspicious behaviours, malicious activities and potential security compromises that have not triggered existing security alerts.
- Develop and execute structured threat-hunting hypotheses based on threat intelligence, attacker behaviour and environmental risk.
- Analyse endpoint, network, identity and cloud telemetry to identify indicators of compromise.
- Investigate potential advanced persistent threats, credential compromise, lateral movement and unauthorised access.
- Identify suspicious processes, persistence mechanisms and abnormal system behaviour.
- Conduct targeted investigations into high-risk systems, privileged accounts and critical infrastructure.
- Document threat-hunting methodologies, findings and investigation outcomes.
- Recommend improvements to security controls, monitoring and detection capabilities.
- Collaborate with SOC analysts, incident responders and detection engineers.
Advanced Threat Detection and Investigation
- Analyse security events and telemetry from SIEM, EDR, XDR and network monitoring platforms.
- Correlate security data from multiple sources to identify potential attacker activity.
- Investigate suspicious authentication patterns, privilege escalation and lateral movement.
- Analyse endpoint process activity, network connections, file modifications and system artefacts.
- Identify command-and-control communications and potential data exfiltration activities.
- Investigate suspicious PowerShell execution, scripting activity and other potentially malicious behaviours.
- Conduct advanced security investigations across Windows, Linux and cloud environments.
- Validate indicators of compromise and distinguish genuine threats from benign activity.
- Escalate confirmed or suspected security incidents to incident response teams.
- Maintain accurate investigation records and technical evidence.
Threat Intelligence and Adversary Analysis
- Analyse cyber threat intelligence to identify relevant threats targeting the organisation.
- Research attacker tactics, techniques and procedures.
- Apply the MITRE ATT&CK framework to threat-hunting investigations.
- Translate threat intelligence into actionable hunting hypotheses and investigation procedures.
- Monitor emerging threats, malware campaigns, exploitation techniques and adversary behaviours.
- Identify indicators of compromise associated with relevant threat actors.
- Conduct threat-informed investigations based on industry-specific risks.
- Support the development of threat profiles and attack scenarios.
- Collaborate with threat intelligence teams to improve threat detection and hunting coverage.
Endpoint and Network Threat Hunting
- Conduct advanced investigations using endpoint detection and response technologies.
- Analyse endpoint telemetry, processes, registry changes, scheduled tasks and persistence mechanisms.
- Investigate suspicious network traffic and abnormal communication patterns.
- Identify potential lateral movement and unauthorised internal network activity.
- Analyse DNS, proxy, firewall and network flow logs.
- Investigate suspicious remote access activity and unusual authentication events.
- Identify potential malware execution and attacker persistence.
- Support network-based threat detection and investigation.
- Recommend improvements to endpoint and network security monitoring.
Cloud and Identity Threat Hunting
- Conduct threat-hunting investigations across Microsoft Azure, AWS or equivalent cloud environments.
- Investigate suspicious cloud authentication and access activity.
- Analyse Microsoft Entra ID, Active Directory and privileged account security events.
- Identify potential identity compromise, token misuse and abnormal account behaviour.
- Investigate suspicious cloud workload activity and unauthorised configuration changes.
- Analyse cloud audit logs and security monitoring data.
- Identify potential privilege escalation and persistence within cloud environments.
- Support investigations involving Microsoft 365 and hybrid identity infrastructure.
- Recommend improvements to cloud security monitoring and identity protection controls.
Detection Engineering and Security Improvement
- Identify gaps in existing security monitoring and detection capabilities.
- Translate successful threat-hunting findings into new detection rules and security use cases.
- Develop or refine SIEM queries, correlation searches and threat detection logic.
- Support the validation of security detection rules and monitoring coverage.
- Collaborate with detection engineers to improve automated threat identification.
- Recommend additional log sources and telemetry collection requirements.
- Reduce false positives and improve security alert quality.
- Participate in Purple Team exercises and detection validation activities.
- Support continuous improvement of organisational threat detection capabilities.
Threat-Hunting Reporting and Documentation
- Develop structured threat-hunting plans, hypotheses and investigation procedures.
- Maintain detailed records of hunting activities and technical findings.
- Prepare threat-hunting reports and security investigation summaries.
- Document identified attack techniques, indicators of compromise and potential security weaknesses.
- Present findings to cybersecurity teams and relevant stakeholders.
- Recommend remediation measures and improvements to security controls.
- Track recurring threats and security monitoring gaps.
- Support security maturity assessments and continuous improvement initiatives.
Minimum Requirements
- Relevant diploma or degree in Information Technology, Computer Science, Cybersecurity, Information Security, Digital Forensics or a related discipline.
- Typically 3–5 years of relevant hands-on experience in cybersecurity operations, threat hunting, advanced security investigations, incident response or a closely related technical specialisation.
- Proven practical experience conducting proactive threat-hunting investigations within enterprise environments.
- Strong understanding of attacker tactics, techniques and procedures.
- Practical experience developing and executing threat-hunting hypotheses.
- Strong hands-on experience with SIEM, EDR or XDR technologies.
- Experience analysing endpoint, network, identity and security log data.
- Familiarity with the MITRE ATT&CK framework.
- Experience investigating credential compromise, privilege escalation, lateral movement and attacker persistence.
- Strong understanding of Windows and Linux operating systems.
- Knowledge of Microsoft Active Directory, authentication systems and identity-related threats.
- Good understanding of TCP/IP networking, DNS, HTTP/HTTPS and common network protocols.
- Experience using security query languages such as KQL or SPL.
- Familiarity with threat intelligence and indicators of compromise.
- Understanding of incident response and digital forensic investigation principles.
- Experience with cloud security investigations would be advantageous.
- Strong analytical, investigative and technical problem-solving skills.
Technical Skills and Competencies
Proactive Threat Hunting
- Hypothesis-driven threat hunting
- Intelligence-driven threat hunting
- Behaviour-based threat hunting
- Endpoint threat hunting
- Network threat hunting
- Identity threat hunting
- Cloud threat hunting
- Advanced persistent threat investigations
- Attacker behaviour analysis
- Threat-hunting methodology development
- Threat-hunting reporting
- Detection gap identification
SIEM and Security Analytics
Practical experience with one or more of the following platforms:
- Microsoft Sentinel
- Splunk Enterprise Security
- IBM QRadar
- Elastic Security
- Google Security Operations
- Other enterprise SIEM and security analytics platforms
Relevant competencies include:
- Advanced security log analysis
- Event correlation
- Security telemetry investigation
- SIEM query development
- Detection logic analysis
- Security data enrichment
- Threat intelligence correlation
- Security analytics
- Behavioural anomaly investigation
Endpoint Detection and Response
Experience with relevant platforms such as:
- Microsoft Defender for Endpoint
- Microsoft Defender XDR
- CrowdStrike Falcon
- SentinelOne
- Palo Alto Cortex XDR
- VMware Carbon Black
- Other enterprise EDR and XDR technologies
Relevant competencies include:
- Endpoint process analysis
- Process tree investigation
- Suspicious execution analysis
- Persistence mechanism investigation
- Endpoint telemetry analysis
- Malware behaviour identification
- Endpoint compromise investigation
- Advanced endpoint hunting queries
Threat Intelligence and Adversary Techniques
- MITRE ATT&CK
- Threat actor tactics, techniques and procedures
- Indicators of Compromise (IOCs)
- Indicators of Attack (IOAs)
- Threat intelligence analysis
- Adversary behaviour profiling
- Advanced persistent threats
- Command-and-control detection
- Credential compromise investigation
- Privilege escalation analysis
- Lateral movement detection
- Data exfiltration investigation
- Threat-informed defence
Network Threat Hunting
- TCP/IP
- DNS
- HTTP/HTTPS
- Network traffic analysis
- Firewall logs
- Proxy logs
- VPN logs
- Network flow analysis
- Network Detection and Response (NDR)
- Intrusion Detection Systems (IDS)
- Wireshark
- Zeek
- Suricata
- Network-based indicators of compromise
Windows, Linux and Identity Security
- Windows security event logs
- Windows Server
- Linux system logs
- Microsoft Active Directory
- Microsoft Entra ID
- Windows authentication
- Kerberos
- NTLM
- Privileged account monitoring
- PowerShell activity analysis
- Scheduled tasks and persistence
- Endpoint and server security artefacts
- Identity compromise investigation
Cloud Security Threat Hunting
- Microsoft Azure
- Microsoft 365
- Microsoft Entra ID
- Microsoft Defender for Cloud
- AWS CloudTrail
- Amazon GuardDuty
- AWS Security Hub
- Cloud audit logs
- Cloud identity security
- Cloud workload investigations
- Hybrid identity monitoring
- Cloud privilege escalation investigations
Scripting and Query Languages
- Kusto Query Language (KQL)
- Splunk Search Processing Language (SPL)
- Python
- PowerShell
- Bash
- SQL fundamentals
- Regular expressions
- Security data parsing
- Threat-hunting automation
- API-based security data analysis
Digital Forensics and Investigation Tools
Familiarity with tools such as:
- Velociraptor
- KAPE
- Volatility
- Autopsy
- Wireshark
- Sysinternals Suite
- YARA
- Sigma
- Other endpoint investigation and threat-hunting tools
Cybersecurity Frameworks and Standards
- MITRE ATT&CK
- NIST Cybersecurity Framework
- NIST SP 800-61 – Incident Response
- ISO/IEC 27001
- Cyber Kill Chain
- Threat-informed defence methodologies
- Digital forensic investigation principles
- Enterprise security monitoring best practices
Relevant Certifications (Advantageous)
One or more of the following certifications would be beneficial:
- GIAC Cyber Threat Intelligence (GCTI)
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Intrusion Analyst (GCIA)
- GIAC Network Forensic Analyst (GNFA)
- GIAC Certified Forensic Analyst (GCFA)
- GIAC Defending Advanced Threats (GDAT)
- CompTIA CySA+
- CompTIA Security+
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- Certified Information Systems Security Professional (CISSP)
- Certified Ethical Hacker (CEH)
- Relevant threat hunting, detection engineering, digital forensics or incident response certifications
Key Personal Attributes
- Strong investigative mindset and analytical abilities.
- Excellent attention to detail and technical accuracy.
- Ability to identify subtle indicators of malicious activity.
- Curiosity and persistence when investigating complex cybersecurity threats.
- Strong technical troubleshooting and problem-solving skills.
- Ability to analyse large volumes of security information.
- Excellent communication and technical reporting abilities.
- Ability to collaborate with SOC analysts, incident responders and security engineers.
- Proactive approach to identifying hidden threats and security weaknesses.
- Strong organisational and documentation skills.
- High levels of confidentiality, accountability and professional integrity.
Application Requirements
Interested candidates should submit an updated CV clearly detailing their practical cybersecurity threat-hunting, advanced security investigation and threat detection experience, together with copies of relevant academic qualifications and professional certifications.
Candidates should specifically highlight:
- Threat-hunting investigations they have personally conducted.
- Examples of hypothesis-driven or intelligence-driven threat hunts.
- SIEM, EDR and XDR platforms used during threat-hunting activities.
- Experience investigating advanced threats, credential compromise, lateral movement and attacker persistence.
- Practical use of MITRE ATT&CK during security investigations.
- Advanced security queries developed using KQL, SPL or equivalent languages.
- Endpoint, network, identity and cloud threat-hunting experience.
- Experience identifying threats that were not detected by existing security alerts.
- Detection rules or monitoring improvements developed from threat-hunting findings.
- Threat intelligence sources and methodologies used professionally.
- The size and complexity of enterprise environments investigated.
- Relevant threat hunting, cybersecurity investigation and professional security certifications.
Important: This is a specialist Cyber Security Threat Hunter opportunity requiring demonstrable hands-on experience proactively searching for and investigating cybersecurity threats. General IT support, basic SOC alert monitoring or theoretical cybersecurity knowledge without substantial threat-hunting or advanced security investigation experience will not be sufficient.
Please note: Specific project requirements, remuneration, employment arrangements, shift or on-call expectations and working conditions will be confirmed during the recruitment process. The required threat-hunting seniority level will also be confirmed with the client.