Job Search

Threat Hunting Investigator - 175938

REMOTE, Remote

Piper Companies Logo

Job Id:
0000175939

Job Category:
Cyber Security

Job Location:
REMOTE, Remote

Security Clearance:
No Clearance

Business Unit:
Piper Companies

Division:
Not Defined

Position Owner:
Elizabeth Britt

Piper Companies is looking to fill the role of Threat Hunter Investigator for a leading technology company located in Raleigh, NC. The Threat Hunter Investigator will identify, investigate, and mitigate risks largely posed by internal actors - whether malicious, negligent, or compromised. This role provides direct support to conduct research and investigations into threats and incidents related to protection of critical intellectual property. The Threat Hunter Investigator role is a remote position with EST hours.


Responsibilities of the Threat Hunter Investigator Include:


  • Conduct proactive threat hunting and insider risk investigations using logs, endpoint telemetry, user activity, and behavioral indicators to identify potential security threats and malicious activity.
  • Research, analyze, and mitigate threats involving sensitive data exposure, intellectual property theft, and other insider risk scenarios, while producing clear and defensible investigative reports.
  • Design, develop, test, deploy, and tune advanced threat detections using Splunk SPL, translating threat intelligence, threat hypotheses, and investigative findings into production-ready detection content.
  • Build and maintain Risk-Based Alerting (RBA) workflows, including correlation searches, risk rules, risk scoring, notable events, and automated response actions within Splunk Enterprise Security.
  • Configure and optimize UEBA detections, anomaly models, and behavioral analytics to identify suspicious user and entity activity across endpoint, network, cloud, and application environments.
  • Create technical documentation, runbooks, and operational standards while continuously validating detection effectiveness through testing, tuning, false-positive reduction, and coverage analysis aligned to MITRE ATT&CK methodologies.

Qualifications for the Threat Hunter Investigator Include:


  • Bachelor's degree in computer science, Information Systems, Cybersecurity, or related field.
  • 8+ years of experience conducting threat investigations, insider threat analysis, and digital forensic investigations involving endpoint devices and sensitive data.
  • Strong hands-on experience with Splunk Enterprise Security, including engineering, tuning, and maintaining security detections in a production environment.
  • Proven ability to write advanced SPL queries from scratch and develop correlation searches, custom detections, and threat-hunting content.
  • Deep experience with Risk-Based Alerting (RBA) and User and Entity Behavior Analytics (UEBA), including risk scoring, behavioral baselining, anomaly detection, and alert prioritization.
  • Strong understanding of detection engineering and threat hunting methodologies, with the ability to translate threat intelligence and MITRE ATT&CK techniques into actionable detections and response workflows.

Compensation for the Threat Hunter Investigator Includes:


  • $140,000-$165,000 annually
  • Comprehensive Benefits: Medical, Dental, Vision, 401(k), PTO, Sick Leave if required by law, and Holidays

This job opens for applications on 10/6/26. Applications for this job will be accepted for at least 30 days from the posting date.

Keywords: threat detection, threat investigator, splunk, insider risks,

#LI-EB1 #REMOTE

Apply For This Position


Personal Information

Required
Required
Required
Required
Required
Required
Required

Additional Details

Required
Required
Required

Voluntary Self-identification Form

Required
Required
Required

Veteran Status *

Discharge Date:

Resume Upload

Please note only files with .pdf, .docx, or .doc file extensions are accepted.

Currently selected file:

Don't have a resume?