Padmi

Senior Threat Hunter (Specialist I - Information Security) - London

London · HybridPosted 2 months ago
CybersecurityUnspecified
Apply at UST

Opens the source posting on usource.ripplehire.com

Source description

About the role

View original

We are looking for a Senior Threat Hunter with strong expertise in Python and Jupyter Notebooks to join our Managed Security Services team in London. This role combines advanced threat hunting with engineering capabilities, focusing on building scalable, automated, and repeatable threat hunting frameworks across large datasets in enterprise environments. Key Responsibilities

Perform proactive, hypothesis-driven threat hunting aligned to MITRE ATT&CK Analyze and investigate security data across endpoint, network, and cloud environments Identify indicators of compromise, suspicious activity, and emerging threats Develop and maintain Jupyter Notebook-based hunting frameworks Build reusable Python modules, APIs, and automation tools Design and maintain data pipelines for telemetry and threat intelligence integration Automate hunting workflows using orchestration tools (e.g., Azure ML pipelines) Apply data normalization, validation, and correlation techniques Collaborate with SOC, Threat Intelligence, and Detection Engineering teams Produce clear and structured threat hunting reports and findings

Required Skills & Experience

5+ years of experience in Threat Hunting, Detection Engineering, or Incident Response Strong hands-on experience with:

Python (Pandas preferred) Jupyter Notebooks

Experience working with:

SIEM / EDR / XDR platforms Large-scale security telemetry and data analysis

Strong understanding of:

MITRE ATT&CK framework and attacker TTPs Windows and Linux operating systems Network traffic and log analysis

Experience in cloud threat hunting (AWS, Azure, GCP) Good understanding of:

CI/CD pipelines, SDLC, and automation practices

Preferred Qualifications

  • Experience with tools such as Microsoft Sentinel, Defender, CrowdStrike, Cybereason Experience building automation for detection validation, rule deployment, or telemetry pipelines Relevant certifications such as GIAC, OSCP, or CEH

  • Work Model

  • Hybrid role based in London Permanent position Collaboration with global teams

  • advanced persistent threat,threat hunting,jupyter notebook,python,network traffic analysis,

One address, no account. We’ll tell you when matching roles go live.

More at UST

Related open roles

View all roles