Adversary Threat Hunter - Southern Company Cybersecurity
Overview
Southern Company seeks a skilled Adversary Threat Hunter to lead proactive threat hunting initiatives within a robust IT environment. The role focuses on identifying suspicious behavior and unauthorized access while supporting incident response and security technology enhancements. Candidates must bring extensive security experience and expertise in modern threat hunting methodologies.
What You'll Do11
- 1Design and execute threat hunting strategies leveraging SIEM platforms like Splunk and EDR/NDR solutions
- 2Develop hypotheses based on threat intelligence and adversary tactics using frameworks like MITRE ATT&CK
- 3Conduct forensic analysis on Windows and Linux systems using memory and disk artifact collection techniques
- 4Map adversary behaviors to analytical models while identifying visibility gaps in security tooling
- 5Document hunt plans and findings in standardized formats for repeatable processes
- 6Collaborate with cross-functional teams to implement security controls and improve defensive posture
- 7Analyze log data using statistical methods to detect anomalies and suspicious activities
- 8Create visualizations and baselines to identify trends and potential security incidents
- 9Contribute to security operations by managing multiple priorities and meeting deadlines
- 10Communicate complex findings to stakeholders through clear written and verbal reports
- 11Drive continuous improvement of threat hunting methodologies through research and experimentation
Requirements11
- 15+ years building ETL pipelines with Spark and Airflow
- 27+ years of information technology security experience
- 3Broad knowledge of access control least privilege data integrity and core security capabilities
- 4Strong understanding of network design principles including topology protocols and virtualization
- 5Practical experience with Splunk Gravwell or other SIEM platforms
- 6Demonstrated experience in security operations monitoring incident response forensics and penetration testing
- 7Forensic analysis skills on Windows and Linux/Unix systems
- 8Experience using EDR NDR SOAR and memory analysis tools
- 9Ability to develop hypotheses from threat intelligence and adversary tradecraft
- 10Basic understanding of YARA Snort Sigma detection logic and data analysis methods
- 11Familiarity with MITRE ATT&CK Cyber Kill Chain Diamond Model and threat intelligence lifecycle
Salary Insight
Salary not disclosed in listing
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.

Belcan, LLC
VerifiedCybersecurity Operations & Communications Lead
Own the security operations and communications strategy for a global enterprise, coordinating incident response across SIEM, SOAR, and EDR platforms. You lead a team of analysts, manage threat intelligence feeds, and craft executive-level briefings. This role sits at the intersection of technical operations and stakeholder communication, reporting directly to the CISO. You will drive the adoption of MITRE ATT&CK framework and NIST guidelines, shaping the organization's cyber resilience.
First Citizens Bank
VerifiedSenior Information Security Analyst (Incident Response)
Remote role supporting Cyber Incident Response team at First Citizens Bank. Experienced senior analyst needed to detect and respond to threats interact with stakeholders and restore operations. Technical role supporting Threat Hunting Intelligence and Monitoring with content creation threat analysis detection recommendations and colleague mentoring.
Cylake-Inc
VerifiedSecurity Researcher (Detection Systems)
Join Cylake-Inc in San Jose, California for an onsite opportunity. Lead the creation of next-generation cybersecurity products from the ground up. Shape the future of threat detection while growing your career with a world-class team.
Deloitte
VerifiedSecurity Engineer III Red Team Operator TS Clearance
We seek a Security Engineer III Red Team Operator with TS Clearance to lead adversary simulation efforts. This role drives proactive defense through red team operations, penetration testing, and threat hunting across enterprise environments. Responsibilities include designing attacks, collaborating with blue teams, and delivering actionable insights. The ideal candidate excels in offensive security while maintaining strict compliance and communication standards. Unique opportunity to shape client resilience strategies.

BCforward
VerifiedCyber Security Engineer, SOC & Incident Response
Own security monitoring and incident response for a Fortune 500 client in Phoenix, AZ. You will join BCforward's security operations team, working onsite to detect, investigate, and mitigate threats across a hybrid cloud and on-premise environment. This role demands hands-on expertise with SIEM platforms and EDR tools, with a direct impact on the client's security posture.
SMART TECH SKILLS LLC
VerifiedDetection Engineering & SOAR Architect - SMART TECH SKILLS LLC
Senior Security Operations Analyst leads detection response and orchestration at a public sector organization. This role builds scalable AI-assisted workflows using CrowdStrike Falcon and Torq while enforcing Zero Trust principles. The ideal candidate drives detection engineering excellence and differentiates through advanced automation and governance.