Bbh
Senior Threat Hunter
2 Locations
Apply through hirly
Upload your resume and get a version tailored to this job, plus a cover letter, in about thirty seconds — before you create an account.
Apply with hirlyhirly's read of this role
- Seniority
- Senior
- Work mode
- On-site / unstated
- First seen by hirly
- 25 Sept 2026
Derived automatically from the posting. Sign up to see how the role scores against your own resume.
the posting
At BBH, Partnership is more than a form of ownership—it’s our approach to business and relationships. We know that supporting your professional and personal goals is the best way to help our clients and advance our business. We take that responsibility seriously. With a 200-year legacy and a shared passion for what’s next, this is the right place to build a fulfilling career.
Job Description
As a Senior Threat Hunter within our Cyber Threat Monitoring Team, you will play a critical role in strengthening the organization’s ability to proactively identify, investigate, and respond to advanced cyber threats. This role emphasizes technical threat hunting, advanced SOC investigations, incident response escalation support, and intelligence-driven detection improvement, while leveraging Cyber Threat Intelligence (CTI) to guide proactive defense strategies.
You will serve as a senior escalation resource for complex and high-priority investigations, proactively hunt for adversary activity across enterprise security telemetry, and work closely with SOC analysts, detection engineers, incident response partners, and security leadership to improve the organization’s detection and response capabilities.
Collaborating with cross-functional teams and organizational leaders, you will help develop and mature threat hunting, detection, and response capabilities that protect our networks, systems, data, employees, and clients. The ideal candidate will have strong hands-on SOC or incident response experience, an analytical mindset, a passion for continuous learning, and the ability to translate threat intelligence and investigative findings into actionable detection and response improvements.
Duties and Responsibilities
- Lead and support advanced SOC investigations, incident response activities, and Tier-3 escalations, providing deep technical analysis of security alerts, anomalous behavior, and suspected malicious activity
- Perform proactive threat hunting activities across enterprise security telemetry including SIEM, EDR, identity, network, and cloud logs to identify previously undetected or emerging threats
- Analyze attacker behaviors and intrusion patterns to develop threat hunting hypotheses and detection strategies aligned with the MITRE ATT&CK framework
- Investigate complex security alerts and incidents, performing log analysis, endpoint analysis, and timeline reconstruction to determine root cause, scope, and impact
- Leverage internal telemetry, alerts, and IOC trends to identify threat patterns targeting the organization and opportunities for improved detection coverage
- Enhance threat detection and response capabilities by supporting the development and improvement of SOC detection logic, response procedures, escalation playbooks, and analyst decision trees
- Conduct proactive analysis of alert trends to identify gaps in detection coverage and recommend new or improved monitoring capabilities
- Utilize Cyber Threat Intelligence (CTI) sources to contextualize incidents, inform threat hunting efforts, and prioritize investigations
- Monitor open-source, closed-source, and vendor-provided threat intelligence to stay abreast of emerging threats, vulnerabilities, and adversary tactics relevant to the organization
- Develop and maintain profiles of relevant threat actors, including tactics, techniques, and procedures (TTPs), and incorporate those insights into threat hunting and detection strategies
- Assist in SOC and Incident Response escalations, providing technical expertise and investigative support during security incidents
- Conduct threat, risk, and vulnerability assessments to provide actionable remediation and security control improvement guidance
- Collaborate with the Red Team and Cyber Incident Management to support red team exercises, incident response training, tabletop exercises, and detection validation
- Perform targeted access reviews and anomaly analysis across enterprise systems (Windows, Linux, databases, network infrastructure, cloud platforms) to identify suspicious activity
- Collaborate with DLP and other security teams on insider risk investigations and monitoring initiatives
- Contribute to the development and improvement of SOC procedures, threat hunting methodologies, and intelligence-driven detection processes
- Collaborate with relevant stakeholders on security awareness messaging and threat awareness related communications
Required Qualifications
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field
- 5+ years of experience in Security Operations, Incident Response, Threat Hunting, Detection Engineering, and/or related cybersecurity roles
- Significant relevant experience (e.g., military cyber operations) may be considered in lieu of a degree
- Strong SOC experience investigating security alerts, performing incident response, and log analysis
- Hands-on experience working with SIEM, EDR, and other enterprise security monitoring tools
- Familiarity with the MITRE ATT&CK Framework and attacker TTP analysis
- Excellent collaboration and communication skills, particularly in high-stress situations
- Ability to produce clear technical and operational reporting for both technical teams and leadership
- Strong analytical skills and priority management
Nice to Have
- Master’s degree in Cybersecurity, Computer Science, Information Technology, or related field
- Hands-on experience in two or more of the following areas: Threat Hunting, Security Operations, Incident Response, Detection Engineering, Cyber Threat Intelligence, Security Engineering, Insider Threat Analysis, Digital Forensics, All-Source Intelligence, Penetration Testing, Red Teaming, Network Security Management, Cyber Risk Management, Cloud Security, Vulnerability Management, Malware Analysis
- Experience in the financial services sector and familiarity with security best practices, regulatory requirements, and industry frameworks (e.g., NYDFS, FFIEC, NIST CSF, ISO 27001, SWIFT CSF)
- Experience developing detection logic and threat hunting queries using Splunk SPL, Microsoft KQL, or similar query languages
- Experience with endpoint, identity, and network monitoring technologies such as EDR, IDS/IPS, Firewalls, WAF, DLP, UEBA, email security gateways, and sandboxing technologies
- Experience with Microsoft Sentinel and Defender (MDE, MDI, Defender for Cloud Apps) as well as other Microsoft security ecosystem tools
- Relevant certifications such as CISSP, GCIH, GCFA, GCIA, GSEC, GCTI, CTIA, Security+, Microsoft Security Operations Analyst Associate
Salary Range
NJ & MA: $110,000 to $160,000 base salary + annual bonus target
BBH and its affiliates' compensation program includes base salary, discretionary bonuses, and profit-sharing. The anticipated base salary range(s) shown above are only for the indicated location(s) and may differ in other locations due to cost of living and labor considerations. Base salaries may vary based on factors such as skill, experience and qualification for the role. BBH's total rewards package recognizes your contributions with more than just a paycheck—providing you with benefits that enhance your experience at BBH from long-term savings, healthcare, and income protection to professional development opportunities and time off, our programs support your overall well-being.
We value diverse experiences. We value diverse experiences and transferrable skillsets. If your career hasn’t followed a traditional path, includes alternative experiences, or doesn’t meet every qualification or skill listed in the job description, please do go ahead and apply.
About BBH:
Brown Brothers Harriman (BBH) is a premier global financial services firm, known for premium service, specialist expertise, technology solutions and partnership approach to client management. Across Investor Services and Capital Partners, we work with an enviable roster of sophisticated clients who make BBH their first ca
Similar jobs
- Senior Cyber Threat Hunter (RMI Security Eng. & Ops Dep)Rakuten · 2 LocationsFirst seen 24d ago
- Senior Specialist- Threat HunterSISA Information Security Pvt Ltd · Bangalore, IndiaFirst seen 2d ago
- Senior OT Threat HunterDragos · United StatesFirst seen 11d agoremote
- Sr. Threat HunterSentinellabs · United StatesFirst seen 17d agoremote
- Senior Threat Hunter Simspace Corporation · Hybrid - SingaporeFirst seen 21d agoremote
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job