Back to Jobs
Blackpoint Cyber
Development 12h ago

Threat Hunting Analyst

Blackpoint Cyber
CanadaCanada
Full-time
Not Disclosed
Senior-Level

Job Description

Key Skills Required

Master these to land this role

Python2h 41mFree Trial ✨
Start 10-Day Free Trial
QA Engineer1h 50mFree Trial ✨
Start 10-Day Free Trial
Automation EngineerIncident ResponseCybersecurity

Want to know if you're a match for this job?

Calculate My Match Score

Blackpoint Cyber is the leading provider of world-class cybersecurity threat hunting, detection, and remediation technology. Founded by former National Security Agency (NSA) cyber operations experts, Blackpoint Cyber is in hyper-growth mode, fueled by a recent $190M Series C funding round.

How You'll Make an Impact:

  • Analyze and evaluate anomalous network and system events in a 24x7x365 Security Operation Center (SOC) environment via conducting lead-less threat hunting.
  • Collaborate with MDR Analysts to research and investigate emerging cybersecurity threats; become an escalation point of contact for advanced intrusion analysis.
  • Develop Incident analysis reports and work across business units and customers to bring issues to a close.
  • Help design and build operational processes and procedures to improve overall SOC efficiency.
  • Provide actionable threat and vulnerability analysis based on security events for multiple independent customer environments.
  • Build test lab environments to research emerging techniques and contribute to internal and external knowledge development of threat operations.
  • Review sandbox technologies for additional Indicators of Compromise (IOCs) uncovered from artifacts during analysis.

What You'll Bring:

  • 5+ years of experience in an information security role. Progressive relevant training and/or certification may substitute for 1 year of experience.
  • Experience working in a Security Operations Center (SOC).
  • 2+ years of experience with triaging endpoint events from EDR, NGAV, and supporting the Incident Response (IR) process.
  • Deep knowledge of assessing threat indicators in a Windows Environment (e.g., Malware, Malicious Anomalies, Abnormal Network Activity, Root-Level Compromise, Forensic Artifacts).
  • Robust understanding of at least two of the following: Windows, Linux, or OSX.
  • Familiarity with the ELK stack (Dashboards, Logstash Config, Searching), and scripting/programming with PowerShell, Python, and Go.
  • Familiarity with AWS services (EC2, S3, IAM) and Azure/M365.
  • Experience in developing, refining, and performing leadless threat hunting analysis to uncover new or potential incidents and report on results.
  • Excellent problem-solving, critical thinking, and analytical skills with the ability to deconstruct issues (hunting anomalous pattern detection).
  • Excellent written and verbal communication skills to effectively summarize and present technical findings to both technical and non-technical audiences.

Bonus:

  • Bachelor’s Degree in Computer Science or a related technical discipline.
  • Experience in Network/System Administration and/or Engineering.
  • Deep forensic knowledge of Windows, Mac OS, and/or Linux.
  • Experience in Digital Forensics and Incident Response.
  • Malware Analysis (Behavioral and/or Static analysis using IDA, Cuckoo Sandbox, x86/x64 Debugging), Pentesting/Red/Blue Team.
  • Experience with Capture The Flag (CTF) Development.

How would you rate this job post?

See what other professionals think about this role.

banner
logo

Blackpoint Cyber

View Company Profile

Blackpoint Cyber (operating at blackpointcyber.com) is a cybersecurity platform engineered for threat hunting, detection, and response. Founded in 2014 by former U.S. Department of Defense and intelligence security experts and headquartered in Denver, CO, Blackpoint Cyber leverages real-world cyber experience and deep knowledge of cyber defense tactics to help MSPs safeguard their customers from cyberthreats. Under the hood, the company offers a nation-state-grade cybersecurity ecosystem. This allows MSPs to protect their customers from cyber threats. Backed by no venture capital or outside funding.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More