Dieses Stellenangebot ist nicht mehr verfügbar
Information Security Analyst Sr. Lead - Threat Hunter
Entergy
- Big Bear City, California, United States
- Big Bear City, California, United States
Über
Workplace Flexibility: Hybrid
Legal Entity: Entergy Services, LLC
The position is based out of The Woodlands, TX, New Orleans, LA, Little Rock, AR, or Jackson, MS. Relocation assistance and sponsorship are not available.
Job Summary / Purpose The Cyber Threat Hunter will proactively detect and respond to advanced threats that evade traditional and modern security tools. Using threat intelligence, behavioral analytics, AI and Agentic AI tools, the hunter will uncover hidden risks and ensure the security of our systems and data. The hunter coordinates results with the Entergy Consolidated Security Operations Center (CSOC), supporting continuous improvement of threat detection, rapid response, and incident reporting.
Primary Responsibilities
Create threat models to understand the IT enterprise, identify gaps, and prioritize mitigations.
Use threat models and intelligence to form threat hypotheses.
Execute automated hunts, analyze results, perform forensic activities, and deliver reports.
Orchestrate AI agents for threat hunting.
Run and manage security controls for AI systems within hunting operations.
Develop and maintain SOPs, playbooks, and workflows.
Expand and maintain the Forensics program.
Iteratively search systems and networks for advanced threats.
Analyze network, host, and application logs.
Analyze malware and code.
Understand and deploy deception capabilities against advanced threats.
Report risk analysis and threat findings to stakeholders.
Lead hunt missions with minimal supervision.
Recommend mitigation actions to improve security practices.
Brief senior leaders and translate technical topics into non‑technical terms.
Develop queries for CSOC to detect new attacks.
Stay current on the cyber threat landscape and threat actor activity.
Investigate high‑priority threat campaigns, TTPs, and malicious actors.
Create workflows and automation within security tools.
Collaborate with business units to enhance detection and response.
Participate in post‑incident reviews to identify lessons learned.
Have knowledge of Industrial Control Systems (ICS) and OT for critical infrastructure protection.
Travel up to 25%.
Will Be Responsible For
Reviewing current and emerging threat intelligence to maintain situational awareness and initiate hunts.
Maintaining threat hunts and supporting CSOC during incident escalations.
Providing weekly briefings of reports.
Collecting, aggregating, and reporting on metrics from threat hunts and security cases.
Conducting technical analysis on host‑based, network‑based, cloud‑focused, and mobile systems to identify advanced threats.
Minimum Requirements Education : Bachelor's degree in Cybersecurity, Information Security, IT, Computer Science, or equivalent experience; or 5-10 years of relevant experience. Additional certifications may be considered in lieu of a degree.
Experience (5+ years) in Security Operations, incident response, detection engineering, offensive security/red team, or cyber threat intelligence. Proficient with threat hunting, host‑ and network‑based monitoring, offensive security strategies, AI/Agentic AI tools, multiple EDR and SIEM tools. Experience in digital forensics, cyber threat intelligence enrichment, and log analysis tools. Ability to develop scripts and work independently.
Minimum Knowledge, Skills, and Abilities
Planning, organizational, and time‑management skills.
Understanding of MITRE ATT&CK Framework.
Knowledge of AI and Agentic AI for threat hunting.
Problem‑solving and decision‑making ability.
Excellent written and verbal communication.
Teamwork and collaboration across functions.
Self‑motivation and independence.
Analytical and critical‑thinking skills.
Cloud and IT‑OT monitoring and incident response.
Systems knowledge (including industrial control systems).
Report writing and effective communication.
Commitment to customer service.
Preferred Certifications
GIAC Certified Incident Handler
GIAC Certified Forensic Analyst
CISSP
SANS GCIA – Intrusion Analyst
SANS GMON – Continuous Monitoring Certification
CCSP – Certified Cloud Security Professional
GIAC Penetration Tester
OSCP – Kali Linux Offensive Security Certified Professional
Technical Competencies
Hands‑on technical engineering and process management skills.
Security operations, cyber security monitoring, intrusion detection, and secured networks.
Artificial intelligence and Agentic AI knowledge.
Networking protocols and enterprise network architecture.
Network and host‑based analysis expertise.
Proficiency in PowerShell and Python scripting.
Advanced knowledge of UNIX and Windows operating systems.
Up‑to‑date knowledge of IT security trends, frameworks, and standards (ISO 27001/27002, SANS CAG, NIST, FISMA, COBIT, COSO, ITIL).
Accessiblity Entergy provides reasonable accommodations for online applicants. Requests may be made orally or in writing.
Equal Employment Opportunity Statement The Entergy System of Companies provides equal employment opportunities to all employees and applicants. It complies with applicable federal, state, and local laws governing non‑discrimination. This policy applies to all terms and conditions of employment, including recruiting, hiring, promotion, termination, compensation, and training.
Work Authorization Authorization to work in the United States is a precondition to employment. Entergy does not sponsor work visas for this position.
#J-18808-Ljbffr
Sprachkenntnisse
- English
Hinweis für Nutzer
Dieses Stellenangebot wurde von einem unserer Partner veröffentlicht. Sie können das Originalangebot einsehen hier.