Get Hired Faster With COMPANY_NAME!
Don't you ever think you landed here by any accident, You are here because you are searching for something bigger. You know what?
- A better Job
- A better Future
- A better Knowledge
- A better Paycheck
- A greater Path to walk on.
And COMPANY_NAME is here to give you exactly what you've been missing for so long. The reality is that most job seekers chase job postings, but successful job seekers attract job offers by chasing the accurate information. Therefore, that's the shift COMPANY_NAME is going to help you make. Here are the top 10 ideas to up-skill yourself, so lean in to begin:
1: COMPANY_NAME Smart Tools and Direct Employer Connections Help Speed Up Your Hiring Process
COMPANY_NAME is a career-changing advantage that most seekers never get access to. Imagine...
- Instead of applying for job after job and still not getting any callbacks, you suddenly bump into a tool that can do the heavy lifting for you.
- Instead of wondering, "What do employers actually want?", you are getting insights straight from the employer's desk.
- Instead of hoping your resume gets noticed, it’s kept on the table of decision-makers who are hiring right now.
That's the difference COMPANY_NAME makes. Our tools will let you reach employers directly, which automatically speeds up your hiring process.
2: With Better Matches, Real-time Job Alerts, and Direct Employer Responses, COMPANY_NAME Helps Many Candidates Secure Interviews and Job Offers Within 15 to 30 Days!
How does COMPANY_NAME make this possible?
On COMPANY_NAME, you get notified for roles aligned with your profile right from the start. When an employer posts a role that matches your qualifications and skills, you’ll know first. When you apply early, your chances of getting noticed and shortlisted increase by 20%.
COMPANY_NAME also offers direct employer responses—no more waiting for weeks. Here you engage with hiring managers who are actively looking for candidates.
When all these features combine in one place, you move from your first match to your first interview within days. And ultimately, from application to offer—all within 15 to 30 days!
3: The Type of Resume You Need to Get Priority Placement
With COMPANY_NAME, you don’t just need a resume—you need a strategy. A system that pushes your name to the right tables. We’ll show you exactly how the most successful candidates take initiative and get noticed.
4: Browse Full-Time, Part-Time, and Freelancing Roles With COMPANY_NAME
The job market isn’t one-size-fits-all—and your career shouldn’t be either. COMPANY_NAME gives you access to a wide range of opportunities including full-time, part-time, and freelancing roles all in one place.
5: COMPANY_NAME Helps You Grow Your Career
COMPANY_NAME provides insights, tools, and role-matching that help you find the right direction, the right skills, and the opportunities aligned with your ambition.
6: The Easiest Way To Find A Job
COMPANY_NAME cuts the noise, the endless scrolling, and the confusion. With accurate matches, direct employer connection, and real-time updates, you get a clear and simple path from application to interview.
7: Find Roles That Offer Growth, Culture & Benefits
COMPANY_NAME helps you find roles where you grow, feel supported, and thrive—not just survive. With us, you discover opportunities that elevate your professional life.
8: Get Support With Resume, Interviews & Career Planning
COMPANY_NAME provides expert guidance on resumes, interviews, and planning so employers instantly recognize your strengths and value.
9: Your Future Starts Today
COMPANY_NAME gives you everything you need—tools, guidance, and opportunities—to step forward confidently and begin a new chapter where your potential is seen and supported.
10: Get Hired Within 15 to 30 Days With COMPANY_NAME
COMPANY_NAME follows a smart, strategic, and proven approach that gets your profile noticed faster and moves you toward interviews and offers within 15 to 30 days.
Threat Hunt Senior Associate
<strong>Are you ready to make an impact at DTCC?<br><br></strong>Do you want to work on innovative projects, collaborate with a dynamic and supportive team, and receive investment in your professional development? At DTCC, we are at the forefront of innovation in the financial markets. We are committed to helping our employees grow and succeed. We believe that you have the skills and drive to make a real impact. We foster a thriving internal community and are committed to creating a workplace that looks like the world that we serve.<br><br>The Information Technology group delivers secure, reliable technology solutions that enable DTCC to be the trusted infrastructure of the global capital markets. The team delivers high-quality information through activities that include development of essential, building infrastructure capabilities to meet client needs and implementing data standards and governance.<br><br><strong>Pay and Benefits:<br><br></strong><ul><li>Competitive compensation, including base pay and annual incentive</li><li>Comprehensive health and life insurance and well-being benefits, based on location</li><li>Pension / Retirement benefits</li><li>Paid Time Off and Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.</li><li>DTCC offers a flexible/hybrid model of 3 days onsite and 2 days remote (onsite Tuesdays, Wednesdays and a third day unique to each team or employee).<br><br></li></ul><strong>The Impact you will have in this role: <br><br></strong>Being a member of CISO Team and as a Threat Hunt Senior Associate, you will execute hypothesis-driven hunts across endpoint, identity, network, and cloud telemetry; track and document hunt activity end-to-end; and translate findings into actionable improvements, detections, response playbooks, hardening tasks, and prioritized engineering work.<br><br>This role is hands-on and requires a practitioner mindset: you'll spend your time asking better questions of the data, validating what "normal" looks like in complex systems, and proving or disproving attacker behaviors using repeatable methods. You'll also provide surge support to incident response during investigations where hunt techniques accelerate containment and root cause analysis.<br><br>This is a mid-level role for someone who can operate independently on scoped hunts, communicate clearly, and contribute to a sustained, measurable hunting program.<br><br><strong>Your Primary Responsibilities:<br><br></strong><strong>Hunt Execution & Documentation (Core)<br><br></strong><ul><li>Execute hypothesis-based threat hunts mapped to MITRE ATT&CK tactics/techniques, focusing on realistic adversary behaviors (credential access, persistence, lateral movement, defense evasion, and cloud abuse).</li><li>Use behavioral analytics and anomaly detection to identify suspicious patterns across endpoint + identity + cloud + network telemetry, then validate with deeper artifact review.</li><li>Perform, track, and record hunt activity in a structured way: hypotheses, datasets queried, query versions, findings (positive/negative), evidence, confidence, and follow-up actions.</li><li>Maintain clean, audit-ready hunt notes that allow another analyst to reproduce your work and understand decisions made under uncertainty.<br><br></li></ul><strong>Investigative Workflows & Telemetry Correlation<br><br></strong><ul><li>Correlate logs across EDR/XDR, SIEM, cloud control plane logs, identity logs, and container/Kubernetes telemetry to build a coherent narrative from partial signals.</li><li>Investigate attacker tradecraft such as:</li><ul><li>Credential theft and replay (token theft, OAuth abuse, suspicious refresh patterns)</li><li>"Living off the land" execution (PowerShell, WMI, LOLBins on Windows; bash/curl/wget/systemd on Linux)</li><li>Persistence mechanisms (scheduled tasks/cron, service modifications, registry run keys, launch agents)</li></ul><li>Command-and-control behaviors and egress anomalies (beaconing, domain fronting indicators, unusual TLS fingerprints where available)</li><li>Cloud and Kubernetes abuse (suspicious role assumptions, unusual API call sequences, kubeconfig access, container escape precursors)</li><li>Triage and deepen suspicious signals into defensible findings: timeline, scope, impact, root cause, and containment recommendations.<br><br></li></ul><strong>Detection Engineering & Continuous Improvement<br><br></strong><ul><li>Translate hunt results into durable controls: new detections, tuning improvements, telemetry onboarding, or gaps to address (instrumentation, logging coverage, parsing, enrichment).</li><li>Draft and iterate detection logic (e.g., Sigma/YARA, SIEM analytics rules, EDR custom IOAs) with measurable success criteria: false-positive rate, time-to-detect improvements, and coverage mapped to ATT&CK.</li><li>Partner with SOAR/automation engineers to operationalize repetitive enrichment and triage steps into playbooks.<br><br></li></ul><strong>Purple Teaming & Adversary Simulation<br><br></strong><ul><li>Collaborate with Red Team / Purple Team efforts to validate detection coverage, refine alerts, and ensure hunts align to current and relevant TTPs.</li><li>Help design and execute controlled simulations (atomic tests, adversary emulation plans), then close the loop by updating detections, documentation, and response procedures.</li><li>Incident Support (When Needed) </li><li>Provide incident surge support: rapid scoping queries, hunting for related activity, identifying patient-zero candidates, and strengthening containment decisions with evidence.</li><li>Contribute to post-incident reviews by identifying detection gaps, improving playbooks, and capturing lessons learned as backlog items.</li><li>NOTE: The Primary Responsibilities of this role are not limited to the details above. **<br><br></li></ul><strong>Qualifications:<br><br></strong><ul><li>Min 3-6 years of relevant experience</li><li>Bachelor's Degree and/or equivalent experience</li><li>3-6 years in Threat Hunting, Detection Engineering, Incident Response, or SOC investigations in a production environment (financial services/fintech experience is a plus but not required).</li><li>Demonstrated experience running hypothesis-driven hunts and documenting outcomes in a way that supports repeatability and measurement.</li><li>Strong log analysis skills and comfort working across multiple telemetry sources (endpoint, identity, network, cloud).</li><li>Practical detection and query experience in one or more:</li><ul><li>KQL (Microsoft Sentinel / Defender)</li><li>Splunk SPL</li><li>Elastic/Kibana (EQL/KQL/Lucene)</li><li>Chronicle/Google SecOps query language or equivalent</li></ul><li>Solid operating system fundamentals: </li><li>Windows internals basics (process ancestry, services, scheduled tasks, registry persistence)</li><li>Linux fundamentals (systemd, cron, auth logs, process/network inspection)</li><li>Familiarity with attacker tradecraft and investigative methods aligned to MITRE ATT&CK; ability to map raw evidence to techniques without forcing it.</li><li>Ability to communicate clearly-writeups that separate observation from inference, quantify confidence, and identify next steps.</li><li>Proven ability to prioritize: know when you have enough evidence to escalate vs. when to keep iterating.<br><br></li></ul><strong>Talents Needed for Success:<br><br></strong><ul><li>Experience hunting across cloud + containerized environments (AWS/Azure/Google Cloud Platform; Kubernetes; CI/CD telemetry).</li><li>Experience developing or tuning detections using Sigma, YARA, EDR custom detections, or SIEM correlation rules.</li><li>Familiarity with NIST CSF / NIST 800-61 incident response concepts and how hunting feeds detection/response maturity.</li><li>Experience with SOAR automation, enrichment pipelines, and case management workflows.</li><li>Comfortable scripting for analysis and automation (Python, PowerShell, Bash) and using tools like jq, osquery, CyberChef.<br><br></li></ul>Certifications (any of the following are valued):<br><br><ul><li>GCFA, GCIH, GCIA</li><li>OSCP (useful signal for investigative depth; not required)</li><li>CISSP (helpful for program maturity context; not required)<br><br></li></ul><strong> Tools & Technologies <br><br></strong>You won't need every item day one-but you should be comfortable learning quickly and working across a modern stack.<br><br>EDR/XDR: Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne (or equivalent)<br><br>SIEM / Analytics: Microsoft Sentinel (KQL), Splunk (SPL), Elastic (EQL/KQL), Chronicle/Google SecOps<br><br>Cloud & Identity: Azure/AWS logs, Entra ID/Azure AD, Okta (or equivalent), CloudTrail/Activity Logs, IAM telemetry<br><br>Containers: Kubernetes audit logs, container runtime signals, registry, and CI/CD telemetry<br><br>Detection Content: Sigma, YARA, ATT&CK mappings, custom IOAs, correlation rules<br><br>Workflow: Case management, runbooks/playbooks, SOAR tooling, structured reporting, and metrics<br><br>The salary range is indicative for roles at the same level within DTCC across all US locations. Actual salary is determined based on the role, location, individual experience, skills, and other considerations. We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, sex, gender, gender expression, sexual orientation, age, marital status, veteran status, or disability status. We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.