Jump to content

Threat Hunting Consultant - San Jose, CA | TCS Job


 Share

Job Opportunity Details

Type

Full Time

Salary

Not Telling

Work from home

No

Weekly Working Hours

Not Telling

Positions

Not Telling

Working Location

San Jose, CA, San Jose, CA, United States   [ View map ]
Microsoft Security Stack Expertise
Extensive hands-on experience with Microsoft Defender for Endpoint (MDE)
Proficiency with Microsoft 365 Defender (XDR) unified security operations
Advanced knowledge of Kusto Query Language (KQL) for threat hunting and detection
Deep understanding of MDE investigation capabilities, automated response features, and integration architecture
SIEM and Analytics
Expert-level Splunk Enterprise Security experience
Proficiency in Splunk Processing Language (SPL) for complex correlation and hunting queries
Experience with Splunk User Behavior Analytics (UBA) or similar behavioral detection platforms
Knowledge of SIEM architecture, data onboarding, and optimization techniques
Threat Hunting and Detection Engineering
Demonstrated experience conducting hypothesis-driven threat hunts
Strong understanding of MITRE ATT&CK framework and its practical application
Ability to translate threat intelligence and attack research into actionable hunting queries
Experience developing high-fidelity detection rules with low false positive rates
Knowledge of adversary tactics, techniques, and procedures (TTPs) across multiple threat actor groups
Incident Response
Proven track record in hands-on incident response and investigation
Expertise in endpoint forensics and malware analysis
Familiarity with incident response frameworks (NIST, SANS) and playbook development
Experience with containment, eradication, and recovery procedures for complex security incidents
Understanding of forensic evidence preservation and chain of custody requirements
Technical Foundations
Deep understanding of Windows internals, process behaviors, and security architecture
Knowledge of network protocols, traffic analysis, and common attack vectors
Familiarity with authentication protocols (Active Directory, Azure AD, Kerberos, NTLM)
Understanding of scripting and automation (PowerShell, Python, or similar)

Knowledge Transfer and Teaching Ability
Proven ability to explain complex technical concepts to varied technical audiences
Experience developing and delivering technical training or mentorship programs
Patience and commitment to building team capability, not just completing tasks
Ability to adapt teaching style to different learning preferences and skill levels
Communication and Collabo ration
Excellent written communication skills for documentation and reporting
Strong verbal communication skills for training delivery and incident collaboration
Ability to work effectively with cross-functional teams (IR, detection engineering, IT operations)
Comfort operating in a fully remote environment with distributed team members
Problem Solving and Initiative
Self-directed work style with ability to identify priorities independently
Creative problem-solving approach to novel security challenges
Intellectual curiosity and continuous learning mindset
Ability to translate theoretical threat research into practical defensive measures
Minimum 5-7 years of experience in cybersecurity with focus on detection, threat hunting, and/or incident response
At least 2 years of hands-on experience with Microsoft Defender for Endpoint in an enterprise environment
Demonstrated experience conducting threat hunts that led to actionable security improvements
Previous experience supporting or leading security tool migrations or implementations (highly valued)
Certifications (Preferred)

Highly Valued:
GIAC Cyber Threat Intelligence (GCTI)
GIAC Certified Incident Handler (GCIH)
GIAC Certified Forensic Analyst (GCFA)
Certified Threat Intelligence Analyst (CTIA)

Relevant:
Microsoft Certified: Security Operations Analyst Associate (SC-200)
Splunk Enterprise Security Certified Admin
CISSP, CISM, or equivalent security management certification
Offensive Security certifications (OSCP, OSCE) demonstrating adversarial perspective

 Knowledge Transfer and Teaching Ability
Proven ability to explain complex technical concepts to varied technical audiences
Experience developing and delivering technical training or mentorship programs
Patience and commitment to building team capability, not just completing tasks
Ability to adapt teaching style to different learning preferences and skill levels
Communication and Collaboration
Excellent written communication skills for documentation and reporting
Strong verbal communication skills for training delivery and incident collaboration
A bility to work effectively with cross-functional teams (IR, detection engineering, IT operations)
Comfort operating in a fully remote environment with distributed team members
Problem Solving and Initiative
Self-directed work style with ability to identify priorities independently
Creative problem-solving approach to novel security challenges
Intellectual curiosity and continuous learning mindset
Ability to translate theoretical threat research into practical defensive measures

Location: Remote
Salary Range: $110,000 - $150,000 a year
#LI-CM2

More Information

Application Details

  • Organization Details
    TCS / Tata Consultancy Services
 Share


User Feedback

Recommended Comments

There are no comments to display.

Join the conversation

You are posting as a guest. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Add a comment...

×  Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×  Your link has been automatically embedded.   Display as a link instead

×  Your previous content has been restored.   Clear editor

×  You cannot paste images directly. Upload or insert images from URL.

Loading...
×
×
  • Create New...