Skip to main content
Northwestern Mutual

Sr Threat Hunt Engineer

RemoteUnited States only· Prefers United States
Published
Role
Security
Experience
Senior
Employment
Full-time
Company size
Enterprise
$119k–$178.4k/yr
Check eligibility

Open to US only · Prefers United States. Set where you work from to check your eligibility.

The listing prefers candidates in United States.

No BS summary

Senior threat-hunting engineer with 5–10+ years across threat intelligence, hunting, IR or detection engineering. Must be hands-on with SIEM, EDR, cloud and identity telemetry and strong Python scripting/automation skills. Remote (US hiring signals) and experience in enterprise/financial-services environments preferred.

Core skills

Threat huntingSIEMEDR

Required skills

Threat intelligence platformsCloud security API integrationIdentity telemetryPythonREST APIswebhooksautomationquery developmentdashboard buildingalertingversion control workflowsMITRE ATT&CK

Optional skills

PowerShellBashAI-assisted security workflowsCI/CD for security contentSOAR platformscloud-native security tooling

What you'll do

  • Maintain and mature the operational hunt framework used across Cyber Defense.
  • Build, document, and refine the templates, integrations, and standards hunters from multiple teams follow.
  • Design, build, and maintain integrations and automation across the hunt lifecycle — spanning work-tracking, collaboration, ticketing, knowledge management, SIEM, EDR, threat intelligence platforms, and reporting.
  • Execute hunts and support the hunt community across teams.
  • Perform proactive and signal-driven hunts, respond to hunt questions from hunters across Cyber Defense, and partner with Threat Intelligence to translate hunt-informed analysis into actionable intelligence.
  • Synthesize hunt outcomes into cross-hunt correlations, control gap identification, and inputs to future hunts and detections.
  • Partner with detection engineering to translate hunt findings into production rules and analytics.
  • Contribute detection candidates through the established handoff pipeline.
  • Consume and apply threat intelligence to hunt activity and track adversary TTPs.
  • Mentor analysts and junior hunters; lead technical deep-dives.
  • Report on program outcomes to internal stakeholders.
  • Evaluate, integrate, and maintain security tooling used by the Threat Hunting Program.
  • Evaluate and integrate AI to accelerate hunt workflows with appropriate human review and tracking.
  • Research current and emerging cyber threats and document threats into contextual reports.
  • Serve as a trusted advisor to business unit leadership and technical teams.
  • Participate in collaborative threat analysis with internal and external trusted entities.
  • Perform other duties as assigned.

What they require

  • Minimum of 5-10 years in threat intelligence, threat hunting, incident response, or detection engineering.
  • Bachelor's degree in computer science, cybersecurity, engineering, or related field (or equivalent experience).
  • Relevant certifications such as GCTI, GCIH, GCFA, GCIA, GCDA, OSCP, CEH, or CISSP are a plus.
  • Cloud-focused security certifications (e.g., AWS Security Specialty, GCP Professional Cloud Security Engineer) are valued.
  • Deep hands-on experience running proactive and signal-driven hunts across SIEM, EDR, network, cloud, and identity telemetry in enterprise environments.
  • Strong scripting and automation skills; Python required.
  • Experience with PowerShell, Bash or equivalent a plus.
  • Deep experience with enterprise SIEM search languages, advanced query development, dashboards, saved searches and query optimization.
  • Hands-on experience developing and consuming REST APIs across security tooling.
  • Experience building event-driven automation using webhooks or similar patterns.
  • Experience building, integrating, and maintaining security tooling and workflows at enterprise scale.
  • Working knowledge of version control workflows, branching strategies, and code review practices.
  • Ability to write clear technical documentation and runbooks.
  • Ability to communicate complex findings to technical and leadership audiences.
  • Applicable knowledge of adversary TTPs, MITRE ATT&CK, unified kill chain, and OSINT.
  • Hands-on experience with SIEM, IDS/IPS, threat intelligence platforms, and SOAR/automation platforms.
  • Ability to analyze host, network, cloud, and identity telemetry; knowledge of OS internals, malware behavior, vulnerabilities and exploitation techniques.
  • Experience with incident collaboration, adversary tooling, and threat-informed defense methodology.
  • Capability to work across diverse teams in a cross-team enablement role.
  • High level of integrity, professionalism, project management and organizational skills.

Benefits

  • Employer shares salary range and refers to geographic-specific pay structures and benefits.
  • Equal opportunity employer statement (commitment to diverse backgrounds).

Digital Platform organization investing in the Business Event Hub, an internal near-real-time messaging platform built on a Business Domain Driven Architecture.

🇺🇸 United StatesInsuranceEnterprisenorthwesternmutual.com/
$119k–$178.4k/yr