About this role
About the Role EY is seeking a Cyber Security – Senior Threat Hunter to proactively identify advanced, stealthy threats across enterprise environments. This role goes beyond alert-driven SOC operations, focusing on hypothesis-based threat hunting, adversary behavior analysis, and closing detection gaps across Microsoft Sentinel, Defender for Endpoint, and Defender for IoT. The Senior Threat Hunter serves as a technical authority within the SOC, supporting L1/L2 analysts and partnering with Incident Response and Detection Engineering teams to continually improve threat visibility and SOC maturity. What You'll Do
- Conduct hypothesis-driven, TTP-centric threat hunts using telemetry from Microsoft Sentinel and Defender platforms.
- Develop hunt hypotheses based on adversary campaigns, MITRE ATT&CK techniques, threat intelligence, and observed environmental weaknesses.
- Hunt for advanced attack behaviors.
- Validate findings with evidence and determine impact before escalation.
- Perform advanced KQL-based threat hunting across large data volumes in Microsoft Sentinel.
- Identify detection blind spots, noisy analytics, and data quality issues.
- Conduct advanced endpoint hunting using Defender Advanced Hunting.
- Correlate endpoint telemetry with SIEM data to reconstruct end-to-end kill chains.
- Perform threat hunting across IoT/OT and ICS. What We're Looking For
- Experience in proactive threat hunting and adversary behavior analysis within enterprise environments.
- Proficiency with telemetry and tooling from Microsoft Sentinel, Microsoft Defender for Endpoint, and Defender for IoT.
- Strong knowledge of MITRE ATT&CK and threat intelligence integration.
- Skilled in performing KQL-based queries and handling large data volumes.
- Ability to correlate endpoint telemetry with SIEM data to reconstruct kill chains and identify detection gaps.
- Experience with IoT/OT and ICS threat landscapes. Nice to Have
- Experience serving as a technical authority within a SOC and collaborating with Incident Response and Detection Engineering teams. Compensation & Benefits
- Not specified in the posting.