In this role the professional oversees a global team of threat hunters. As a hunt lead, they must have a solid understanding of threat hunting and its relation to other services offerings. With the assistance of the Service Lead, they will manage the delivery of threat hunting across multiple clients.
The hunt lead must speak technically about threats to potential and existing clients, the client lead, and D&R leadership. They must always be aware of ongoing threats and be ready to "spring into action" during an emerging threat.
Responsibilities:
Responsibilities for the MSS and MXDR Hunt Lead include, but are not limited to:
- Manage day-to-day hunt operations across the designated delivery model. Guide the overall hunting program for the model to react to current events internal and external to the clients and achieve meaningful results in coordination with the client lead and other threat hunters.
- Assist the Service Lead in strategically growing the threat hunt service and building the service roadmap.
- Assist the Service Lead in planning resourcing and recruitment.
- Provide mentorship and growth of threat hunters (junior, senior, and client leads).
- Accountability of the service of the designated delivery model and client pool to the Service Lead.
- Leading/attending client meetings, QBRs, client discussions as requested by the Service lead or D&R leadership.
- Assist the Service Lead on strategic integration with other services - intel, engineering, IR, service delivery managers, etc.
- Review weekly in collaboration with the Hunting Client Lead hunting activity for the client pool, provide guidance when needed to address client-specific incidents/investigations.
- Interface regularly with the Service Lead to provide client/hunter feedback that guides service level decisions, such as client assignment, Hunter career advancement, and team training strategy.
- Lead morning touchpoint calls with the team and is available for general status meetings if requested by the Service Lead. For engagements with significant client delivery or client relationship challenges, may attend biweekly status and Hunting calls with the client.
- When an incident occurs, the Fusion/Mavericks Hunt Lead and the Client Hunt Lead will jump in to coordinate the work on the incident-specific tasks delegated to other hunters by one of these roles.
- Serve as the technical SME for ongoing threats for the threat hunt team, support Adhoc technical conversations for leaders outside threat hunting, and support threat hunt conversations with potential clients (not necessarily familiar clients).
- The Fusion/Mavericks should be able to step in for the Service Lead in the event of their absence.
- Performs other duties as assigned.
Qualifications:
- Minimum of 5 years of experience in security information.
- Experience leading a team.
- Extensive knowledge on network, endpoint, threat intelligence, as well as the functioning of specific applications or underlying IT infrastructure, and have experience with SIEM technologies, EDR solutions, forensics tools, malware analysis
- Strong attention to detail with the ability to work on difficult mission requirements that have little to no known documentation
- Ability to perform analysis of network traffic (i.e., IDS/IPS/DLP events, packet capture, and FW logs) and host activity across a wide array of technologies and platforms
- Experience working with various security methodologies and processes; advanced knowledge of TCP/IP protocols
- Experience in security technologies such as: Security information and event management (SIEM), IDS/IPS, Data Loss Prevention (DLP), Proxy, Web Application Firewall (WAF), Endpoint detection and response (EDR), Anti-Virus, Sandboxing, network- and host- based firewalls, Threat Intelligence, Penetration Testing, etc.
- Experience providing analysis and trending of security log data from heterogeneous security devices
- Knowledge of Advanced Persistent Threats (APT) tactics, technics and procedures
- Excellent spoken and written communication skills
- Strong analytical and problem-solving skills