Cybersecurity Operations Engineer: Threat Hunting
UBQ.io · , ·
- Work mode
- Onsite
- Category
- Security
- Experience
- 3+ years
UBQ.io is seeking a hands-on Cybersecurity Operations Engineer to implement and optimize core security tech across endpoints, networks, and web apps. You will write detections, investigate incidents, and proactively hunt threats in a fast-paced environment.
The role requires deploying EDR/SSE/SIEM/WAF in production, tuning rules, and collaborating with IT and security teams to improve the organization's security posture.
Implement, configure, and maintain EDR platforms with policy tuning and response actions. Deploy and manage SSE solutions including SWG and ZTNA. Administer and tune SIEM, onboard log sources, create correlations, dashboards, alerts. Lead evaluation, rollout, and integration of new security tooling with proper docs. Write and tune detections across the stack (EDR, SIEM, WAF) mapping MITRE ATT&CK coverage. Investigate incidents end-to-end: triage, analysis, containment, eradication, post-incident reports. Proactively threat hunt across endpoints, network, and logs to find gaps and create new detections. Develop and maintain runbooks, playbooks, and SOPs; collaborate with IT and infra teams. Support vulnerability management and continuous improvement of security posture. 3+ years hands-on experience implementing and managing core security technologies (EDR/SSE/SIEM/WAF). Experience deploying and tuning production security tooling, not just reviewing alerts. SOC experience is a plus if hands-on and engineering-focused, not only monitoring. Hands-on detections work and threat hunting, familiarity with MITRE ATT&CK.