Skip to content

Open nowPosted 10 days ago

Cyber Security Threat Management Senior Associate

DTCC44 open roles

Where
Tampa, FL, United States
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowCyber Security Threat Management Senior AssociateDTCC · Tampa, FL, United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on DTCC's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market. DTCC postings stay open a median of 4 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.6%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.0%30 days
This job: posted 10 days ago

DTCC median: 4 days open

The posting

Job Description

Are you ready to make an impact at DTCC?

Do you want to work on innovative projects, collaborate with a dynamic and supportive team, and receive investment in your professional development? At DTCC, we are at the forefront of innovation in the financial markets. We are committed to helping our employees grow and succeed. We believe that you have the skills and drive to make a real impact. We foster a thriving internal community and are committed to creating a workplace that looks like the world that we serve.

The Information Technology group delivers secure, reliable technology solutions that enable DTCC to be the trusted infrastructure of the global capital markets. The team delivers high-quality information through activities that include development of essential, building infrastructure capabilities to meet client needs and implementing data standards and governance.

Pay and Benefits:

  • Competitive compensation, including base pay and annual incentive
  • Comprehensive health and life insurance and well-being benefits, based on location
  • Pension / Retirement benefits
  • Paid Time Off and Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
  • DTCC offers a flexible/hybrid model of 3 days onsite and 2 days remote (onsite Tuesdays, Wednesdays and a third day unique to each team or employee).

The Impact you will have in this role:

As a Threat Hunt Senior Associate, you will execute hypothesis-driven hunts across endpoint, identity, network, and cloud telemetry; track and document hunt activity end-to-end; and translate findings into actionable improvements, detections, response playbooks, hardening tasks, and prioritized engineering work.

This role is hands-on and requires a practitioner mindset: you’ll spend your time asking better questions of the data, validating what “normal” looks like in complex systems, and proving or disproving attacker behaviors using repeatable methods. You’ll also provide surge support to incident response during investigations where hunt techniques accelerate containment and root cause analysis.

This is a mid-level role for someone who can operate independently on scoped hunts, communicate clearly, and contribute to a sustained, measurable hunting program.

Key Responsibilities

Hunt Execution & Documentation (Core)

Execute hypothesis-based threat hunts mapped to MITRE ATT&CK tactics/techniques, focusing on realistic adversary behaviors (credential access, persistence, lateral movement, defense evasion, and cloud abuse).

Use behavioral analytics and anomaly detection to identify suspicious patterns across endpoint + identity + cloud + network telemetry, then validate with deeper artifact review.

Perform, track, and record hunt activity in a structured way: hypotheses, datasets queried, query versions, findings (positive/negative), evidence, confidence, and follow-up actions.

Maintain clean, audit-ready hunt notes that allow another analyst to reproduce your work and understand decisions made under uncertainty.

Investigative Workflows & Telemetry Correlation

Correlate logs across EDR/XDR, SIEM, cloud control plane logs, identity logs, and container/Kubernetes telemetry to build a coherent narrative from partial signals.

Investigate attacker tradecraft such as:

Credential theft and replay (token theft, OAuth abuse, suspicious refresh patterns)

“Living off the land” execution (PowerShell, WMI, LOLBins on Windows; bash/curl/wget/systemd on Linux)

Persistence mechanisms (scheduled tasks/cron, service modifications, registry run keys, launch agents)

Command-and-control behaviors and egress anomalies (beaconing, domain fronting indicators, unusual TLS fingerprints where available)

Cloud and Kubernetes abuse (suspicious role assumptions, unusual API call sequences, kubeconfig access, container escape precursors)

Triage and deepen suspicious signals into defensible findings: timeline, scope, impact, root cause, and containment recommendations.

Detection Engineering & Continuous Improvement

Translate hunt results into durable controls: new detections, tuning improvements, telemetry onboarding, or gaps to address (instrumentation, logging coverage, parsing, enrichment).

Draft and iterate detection logic (e.g., Sigma/YARA, SIEM analytics rules, EDR custom IOAs) with measurable success criteria: false-positive rate, time-to-detect improvements, and coverage mapped to ATT&CK.

Partner with SOAR/automation engineers to operationalize repetitive enrichment and triage steps into playbooks.

Purple Teaming & Adversary Simulation

Collaborate with Red Team / Purple Team efforts to validate detection coverage, refine alerts, and ensure hunts align to current and relevant TTPs.

Help design and execute controlled simulations (atomic tests, adversary emulation plans), then close the loop by updating detections, documentation, and response procedures.

Incident Support (When Needed)

Provide incident surge support: rapid scoping queries, hunting for related activity, identifying patient-zero candidates, and strengthening containment decisions with evidence.

Contribute to post-incident reviews by identifying detection gaps, improving playbooks, and capturing lessons learned as backlog items.

Required Qualifications

3-6 years in Threat Hunting, Detection Engineering, Incident Response, or SOC investigations in a production environment (financial services/fintech experience is a plus but not required).

Demonstrated experience running hypothesis-driven hunts and documenting outcomes in a way that supports repeatability and measurement.

Strong log analysis skills and comfort working across multiple telemetry sources (endpoint, identity, network, cloud).

Practical detection and query experience in one or more:

KQL (Microsoft Sentinel / Defender)

Splunk SPL

Elastic/Kibana (EQL/KQL/Lucene)

Chronicle/Google SecOps query language or equivalent

Solid operating system fundamentals:

Windows internals basics (process ancestry, services, scheduled tasks, registry persistence)

Linux fundamentals (systemd, cron, auth logs, process/network inspection)

Familiarity with attacker tradecraft and investigative methods aligned to MITRE ATT&CK; ability to map raw evidence to techniques without forcing it.

Ability to communicate clearly—writeups that separate observation from inference, quantify confidence, and identify next steps.

Proven ability to prioritize: know when you have enough evidence to escalate vs. when to keep iterating.

Preferred Qualifications

Experience hunting across cloud + containerized environments (AWS/Azure/GCP; Kubernetes; CI/CD telemetry).

Experience developing or tuning detections using Sigma, YARA, EDR custom detections, or SIEM correlation rules.

Familiarity with NIST CSF / NIST 800-61 incident response concepts and how hunting feeds detection/response maturity.

Experience with SOAR automation, enrichment pipelines, and case management workflows.

Certifications (any of the following are valued):

GCFA, GCIH, GCIA

OSCP (useful signal for investigative depth; not required)

CISSP (helpful for program maturity context; not required)

Comfortable scripting for analysis and automation (Python, PowerShell, Bash) and using tools like jq, osquery, CyberChef.

Tools & Technologies

You won’t need every item day one—but you should be comfortable learning quickly and working across a modern stack.

EDR/XDR: Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne (or equivalent)

SIEM / Analytics: Microsoft Sentinel (KQL), Splunk (SPL), Elastic (EQL/KQL), Chronicle/Google SecOps

Cloud & Identity: Azure/AWS logs, Entra ID/Azure AD, Okta (or equivalent), CloudTrail/Activity Logs, IAM telemetry

Containers: Kubernetes audit logs, container runtime signals, registry, and CI/CD telemetry

Detection Content: Sigma, YARA, ATT&CK mappings, custom IOAs, correlation rules

Workflow: Case management, runbooks/playbooks, SOAR tooling, structured reporting, and metrics

What Success Looks Like in This Role

In your first 90 days, you will:

Run multiple scoped hunts end-to-end and document them to a reproducible standard (hypothesis → data sources → queries → findings → actions).

Demonstrate strong signal-to-noise judgment: reduce false positives through evidence-based tuning, not guesswork.

Produce at least a few measurable outcomes—new detections, improved parsers/enrichment, or closed telemetry gaps—that improve detection coverage.

Build credibility with IR and engineering partners by bringing clear findings, not speculation, and by turning results into tractable follow-up work.

By 6–12 months, you will:

Consistently deliver ATT&CK-mapped hunt outcomes and contribute to a backlog that meaningfully improves coverage and response speed.

Help mature the hunt program’s operational rigor: tracking, metrics, documentation quality, and repeatable hunt playbooks.

Be trusted to lead hunts on complex topics (cloud identity abuse, Kubernetes attack paths, cross-domain lateral movement) and mentor junior analysts informally through your writeups and methods.

The salary range is indicative for roles at the same level within DTCC across all US locations. Actual salary is determined based on the role, location, individual experience, skills, and other considerations. We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, sex, gender, gender expression, sexual orientation, age, marital status, veteran status, or disability status. We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against DTCC's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on DTCC's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    DTCC's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.