Job Description
Help AG is looking for an experience Digital Threat Hunting Specialist who will be responsible for proactively identifying, investigating, and mitigating advanced cyber threats within the client environment through hypothesis-driven threat hunting activities. This position will focus on proactive threat hunting, advanced threat analysis, detection engineering, threat intelligence correlation, investigation of suspicious activities, and continuous improvement of cyber defense capabilities.
Responsibilities
❖ Proactively conduct hypothesis-driven threat hunting across enterprise networks, endpoints, cloud, and hybrid environments to identify advanced persistent threats (APTs) and hidden malicious activities.
❖ Investigate suspicious events and analyze attacker tactics, techniques, and procedures (TTPs) using the MITRE ATT&CK framework.
❖ Perform advanced analysis of security logs, endpoint telemetry, network traffic, authentication events, and cloud security data to identify indicators of compromise (IOCs) and indicators of attack (IOAs).
❖ Develop and refine threat hunting methodologies, playbooks, and standard operating procedures.
❖ Create and enhance detection use cases, analytics rules, and hunting queries within SIEM and EDR platforms.
❖ Support Incident Response teams by providing detailed investigative findings, root cause analysis, and threat attribution where applicable.
❖ Collaborate with Security Operations, Threat Intelligence, Vulnerability Management, and Infrastructure teams to strengthen the overall security posture.
❖ Prepare technical reports, threat hunting findings, executive summaries, and recommendations for continuous security improvement.
❖ Provide technical guidance on threat hunting best practices, detection strategies, and emerging attack techniques.
Qualifications & Skills
❖ Bachelor's degree in Computer Science, Cybersecurity, Information Technology, Information Security, Engineering, or a related field. Equivalent professional experience and relevant certifications may be considered in lieu of a degree.
❖ 7+ years of experience in cybersecurity operations, threat hunting, incident response, security monitoring, or detection/security engineering.
❖ Demonstrable, hands-on experience leading or performing proactive threat hunts in enterprise scale environments.
❖ Strong understanding of threat hunting methodologies, cyber kill chain, MITRE ATT&CK framework, and adversary TTPs.
❖ Experience with Endpoint Detection and Response (EDR) platforms such as Microsoft Defender for Endpoint, CrowdStrike, SentinelOne, Cortex XDR, or equivalent.
❖ Experience analyzing Windows, Linux, Active Directory, cloud, endpoint, and network security telemetry.
❖ Knowledge of threat intelligence platforms, IOC analysis, malware behavior, and advanced attack techniques.
❖ Experience developing detection rules, hunting queries (KQL, SPL, or equivalent), and SIEM use cases.
❖ Relevant certifications such as SC-200, GCTI, GCIH, GCFA, CISSP, CISM, CompTIA CySA+, or equivalent are preferred.
❖ Solid understanding of networking fundamentals, operating system internals, and common enterprise architectures (on-premises, cloud, and hybrid).
❖ Familiarity with security frameworks, standards, and regulatory requirements (e.g., NIST, ISO 27001, and relevant UAE/regional cybersecurity regulations).
❖ Ability to work effectively under pressure, manage multiple priorities, and operate with minimal
❖ supervision in a fast-paced operational environment.
❖ Strong stakeholder management and client-facing communication skills, with the ability to build trust and credibility with technical and business audiences.
❖ Fluency in English (written and spoken); Arabic language skills are an advantage.
Benefits
❖ Health insurance with one of the leading global providers for medical insurance.
❖ Career progression and growth through challenging projects and work.
❖ Employee engagement and wellness campaigns activities throughout the year.
❖ Annual Flight tickets to home country.
❖ Excellent learning and development opportunities.
❖ Flexible/Hybrid working environment.
❖ Inclusive and diverse working environment.
❖ Open door policy
About Us
Help AG present in the Middle East since 2004, was strategically acquired by e& (formerly Etisalat Group) in 2020, hence creating a cybersecurity and digital transformation powerhouse in the region.
Help AG has firmly established itself as the region's trusted IT security advisor by remaining vendoragnostic, trustworthy, independent, and maintaining its focus on all aspects of cybersecurity. With best of breed technologies from industry-leading vendor partners, expertly qualified service delivery teams and a state-of-the-art consulting practice, Help AG delivers unmatched value to its customers by
strengthening their cyber defenses and safeguarding their business.