Threat Hunting Investigator
remote
Job Id:
0000176036
Job Category:
Information Technology
Job Location:
remote
Security Clearance:
No Clearance
Business Unit:
Piper Companies
Division:
Not Defined
Position Owner:
Bailey Horne
Piper Companies is seeking a Threat Hunting Investigator to support insider threat investigations, threat hunting operations, and critical intellectual property protection initiatives. This individual will work closely with Security & Trust, Global Security & Executive Protection, and Incident Detection & Response teams to identify, investigate, and mitigate risks posed by malicious, negligent, or compromised insiders. This is a full-time contract opportunity supporting a fast-paced, collaborative environment focused on advanced threat detection, incident response, and insider risk management. This is a remote opportunity located in the US and must be able to hold a clearance.
Responsibilities for the Threat Hunting Investigator include:
· Conduct proactive threat hunting activities focused on insider threats, intellectual property theft, and emerging security risks.
· Analyze logs, telemetry, behavioral indicators, and endpoint data to identify suspicious activity and potential threat actors.
· Perform digital investigations, forensic analysis, and data triage to support incident response and risk mitigation efforts.
· Develop and present clear investigative findings, technical reports, and recommendations to stakeholders.
· Design, develop, test, deploy, and maintain advanced threat detections within Splunk Enterprise Security, Risk-Based Alerting (RBA), and UEBA environments.
· Translate threat intelligence, MITRE ATT&CK techniques, and investigative findings into scalable detection logic and response workflows.
· Validate and tune detection content through testing, false-positive analysis, telemetry reviews, and continuous improvement initiatives.
Qualifications for the Threat Hunting Investigator include:
· Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related technical field required.
· 8+ years of experience conducting insider threat investigations, evaluating risks, and implementing security countermeasures.
· 8+ years of experience performing digital forensic investigations, data triage, and endpoint analysis.
· 5+ years of hands-on experience engineering and operating Splunk security detections, including Splunk Enterprise Security and Risk-Based Alerting (RBA).
· Strong expertise developing production-grade detection content utilizing advanced SPL, correlation searches, risk rules, notable events, and adaptive response actions.
· Experience with Splunk UEBA or comparable behavioral analytics platforms, including anomaly detection, risk scoring, and user/entity behavior analysis.
· Experience analyzing AWS CloudTrail, endpoint, identity, network, SaaS, and insider-risk telemetry data is highly preferred.
· Experience with security tools such as Code42, Microsoft Defender, Digital Guardian, or similar insider-risk monitoring platforms is a plus.
Compensation for the Threat Hunting Investigator includes:
· Salary range: $140,000 - $170,000
· Comprehensive Benefits: Medical, Dental, Vision, 401(k), and applicable sick leave
Keywords: Threat hunting, insider threat investigations, threat detection, detection engineering, digital forensics, incident response, security operations, intellectual property protection, Splunk Enterprise Security (ES), Splunk UEBA, Splunk SIEM, Splunk SPL, Risk-Based Alerting (RBA), correlation searches, risk rules, notable events, adaptive response actions, MITRE ATT&CK, threat intelligence, endpoint forensics, data triage, log analysis, telemetry analysis, AWS CloudTrail, cloud security, network security, identity analytics, user activity monitoring, Code42, Microsoft Defender, Digital Guardian, SIEM, UEBA, anomaly detection, behavioral analytics, Python, C++, Verilog, scripting, detection development, detection testing, detection tuning, security analytics, investigative reporting, forensic investigations, insider risk monitoring, endpoint telemetry, network telemetry, SaaS telemetry, security monitoring, threat research, detection content, security use cases, operational runbooks, security metrics, and technical documentation.
#LI-BH1
#REMOTE
This job is open for applications on 10/8/2026 and will remain open for at least 30 days from the posting date