Skip to content

Open nowPosted 11 hours ago

Threat Hunting Lead

Aspenview Technology Partners58 open roles

Where
Bogotá, Medellín, Buenos Aires.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowThreat Hunting LeadAspenview Technology Partners · Bogotá, Medellín, Buenos Aires.
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Aspenview Technology Partners's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.0% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 8.0%7 days
  4. 15.0%14 days
  5. 34.2%30 days
This job: posted 11 hours ago

The posting

Build the Future with AspenView Technology Partners

At AspenView, we are passionate about transforming the way organizations approach technology. We specialize in creating high-performing, nearshore IT teams to help North American clients innovate faster and more efficiently.

As we continue to grow, we’re looking for exceptional people to join our team and help drive impactful change across industries.

Why Join AspenView?

At AspenView, we’re more than a nearshore IT partner—we’re a people-first, purpose-driven company that believes great culture drives great outcomes. We’re passionate about connecting talent and technology to deliver measurable value for clients—and meaningful career paths for our people.

Here’s what you can expect:

  • Competitive base
  • Flexible work model: hybrid, remote, or in-office
  • Real growth opportunities and leadership visibility
  • Inclusive, respectful culture that blends U.S. innovation with Colombian heart
  • A company that listens, invests in you, and celebrates wins together

We are seeking a Threat Hunting Lead to join the security operations team of a large US consumer lender in the financial services sector. You'll own the hunt plan and lead intelligence-driven hunts across endpoint, identity, network, email and AWS telemetry in Elastic, directing two Senior Threat Hunters and working daily with the US-based Detection Engineering Lead so that every good hunt ends as a working detection. This is a hands-on role for someone who has actually taken hunts from hypothesis to outcome and knows what living-off-the-land, credential abuse and lateral movement look like in real logs, not just someone who has triaged alerts from a queue.

What you will do:

Hunt Strategy & Planning

  • Own the hunt plan, building hypotheses from threat intel on US consumer finance, recent incidents and known telemetry gaps.
  • Decide which hypotheses get hunt time and set priorities for the team.
  • Help the client decide where GenAI-enabled capabilities add value to hunting and where they don't.

Hunt Execution

  • Run scheduled and ad hoc hunts across CrowdStrike, Defender, Okta, Palo Alto, Proofpoint and AWS data in Elastic.
  • Track living-off-the-land techniques, credential and session abuse, and lateral movement, mapped to MITRE ATT&CK.
  • Sweep the estate for related activity to support Incident Response during major incidents.

Detection Handoff & Client Reporting

  • Turn hunt outcomes into detection backlog items with Detection Engineering and make sure they ship.
  • Write clear client hunt reports covering what was tested, found, ruled out and couldn't be tested.
  • Present results directly to the client's security leadership.

Team Leadership

  • Direct and review the work of two Senior Threat Hunters.
  • Mentor the team on hypothesis design, tradecraft and query quality.

Tools & Technologies:

  • Platforms & Infrastructure: Elastic Security (EQL, ES|QL), Splunk or Sentinel, Palo Alto, Proofpoint, VDI-based client environment.
  • Security & Threat Intelligence: CrowdStrike Falcon, Microsoft Defender, SentinelOne, Okta, MITRE ATT&CK, MISP, OpenCTI, Recorded Future, FS-ISAC.
  • Cloud & Data Analysis: AWS telemetry, Python, Jupyter.

What you bring:

  • Experience: 4+ years in threat hunting, Tier 3 investigation or incident response, with hunts you can walk through from hypothesis to outcome.
  • Querying: Fluent SIEM or data-platform querying (Elastic, Splunk, Sentinel or equivalent) across large data sets.
  • Tradecraft: Solid MITRE ATT&CK knowledge and a sharp eye for LOTL, credential/session abuse and lateral movement in logs.
  • Consulting / Leadership: Experience leading or mentoring hunters or analysts, and confidence presenting to client security leadership.
  • Mindset: Hypothesis-driven, candid when a hunt comes up empty, and focused on getting detections shipped.
  • Language: English at B2 or above.
  • Nice to have: Elastic EQL/ES|QL, deep EDR experience, Okta and AWS hunting, threat intel platforms, Python/Jupyter, financial-sector threat knowledge (fraud, ransomware, BEC), detection writing, and GCTI, GDAT, GCIH or eCTHP certification.
  • Clearance: Must pass identity, criminal-background, employment and education checks, repeated periodically.
  • Location: On-site in Medellín, Bogotá or Buenos Aires, working US Eastern business hours.

Visa Sponsorship

AspenView does not sponsor employment visas for this role. Applicants must be permanently authorized to work in their country of residence and must not require visa sponsorship now or in the future.

Equal Opportunity Employer

AspenView is proud to be an equal opportunity employer. We believe in creating an environment where all employees feel welcome, valued, and empowered to succeed. We celebrate diversity and strive to build a culture of inclusion where all individuals, regardless of their race, color, gender, gender identity or expression, sexual orientation, disability, age, or any other characteristic, can thrive. We encourage applicants from all walks of life to join our team and make a lasting impact.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Aspenview Technology Partners's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Aspenview Technology Partners's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Aspenview Technology Partners's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.