Threat Hunting Investigator
United States, REMOTE
Job Id:
0000175695
Job Category:
Cyber Security
Job Location:
United States, REMOTE
Security Clearance:
No Clearance
Business Unit:
Piper Companies
Division:
Not Defined
Position Owner:
Anne Green
Piper Companies is seeking a Threat Hunting Investigator to support a leading technology organization protecting critical intellectual property from insider threats. The Threat Hunting Investigator will conduct technical investigations and engineer advanced security detections across Splunk environments. The Threat Hunting Investigator is a long term contract opportunity and allows you to work remote in the United States.
Responsibilities of the Threat Hunting Investigator:
• Conduct threat hunting and investigations focused on insider threats and critical IP theft.
• Analyze endpoint, identity, cloud, network, and behavioral telemetry.
• Build, deploy, and tune advanced Splunk detections using SPL, Enterprise Security, RBA, and UEBA.
• Translate threat research and MITRE ATT&CK techniques into production-ready detection logic.
• Perform endpoint forensic analysis and produce clear investigative reports.
• Test and continuously improve detection accuracy, coverage, and response workflows.
Requirements of the Threat Hunting Investigator:
• Bachelor’s degree in Computer Science, Information Systems, or related field.
• 8-10 years of insider threat, digital investigation, and endpoint forensic experience.
• 5+ years of hands-on Splunk security detection engineering experience.
• Advanced experience with SPL, Splunk Enterprise Security, RBA, and UEBA.
• Experience with MITRE ATT&CK and multi-source security telemetry.
• Experience with AWS CloudTrail, Microsoft Defender, Code42, or Digital Guardian preferred.
• Strong investigative judgment and communication skills.
Compensation for the Threat Hunting Investigator:
• $120,000 - $160,000
• Full Comprehensive Benefits: Health, Vision, Dental, PTO, Paid Holiday and Sick Leave if Required by Law.
Keywords:
Threat Hunting Investigator, Threat Hunter, Insider Threat, Insider Risk, Splunk, Splunk Enterprise Security, Splunk ES, SPL, RBA, UEBA, Detection Engineering, Threat Detection, MITRE ATT&CK, Digital Forensics, Endpoint Security, Incident Response, IP Theft, AWS CloudTrail, Microsoft Defender, Code42, Digital Guardian
This job opens for applications on 10/02/2026. Applications for this job will be accepted for at least 30 days from the posting date.
#LI-AG1
#REMOTE