SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Snowbit, part of the Coralogix group, is seeking a Senior Threat Hunting & Incident Response Engineer to join the Managed Detection and Response (MDR) team. Coralogix is rebuilding observability by providing deep insights at scale for reduced cost. Snowbit offers managed detection and response services built on Israeli cybersecurity expertise.
You will lead proactive threat hunting and deliver log-based incident analysis across customer Coralogix environments. The role sits within the Threat Detection & Response (TDR) team, which owns threat hunting, incident response support, and threat intelligence. This is a build-and-investigate role where you form hypotheses, prove or disprove them in data, and turn findings into durable detection logic.
The role splits approximately 40% proactive hunting, 25% detection engineering, 20% incident analysis support and reporting, and 15% building agentic tooling that scales the first three. During active customer incidents, this mix shifts.
Proactive threat hunting involves developing and running hypothesis-driven hunts across cloud, identity, endpoint and network telemetry in customer Coralogix tenants. You will translate threat intelligence and MITRE ATT&CK techniques into testable hunt hypotheses, build and maintain a reusable hunt library, and establish baselines for normal behavior per environment.
Detection engineering includes writing, tuning and validating detection rules and alert definitions with documented logic and response guidance. You will measure detection coverage against ATT&CK and reduce alert noise by improving rule precision.
Incident response support involves performing log-based analysis during customer incidents: reconstructing timelines, scoping affected identities and assets, identifying indicators of compromise, and providing defensible evidence packages with clear recommendations.
Building agentic threat hunting means turning manual hunts into agentic ones by encoding hypotheses, queries, pivots and scoring into workflows that run repeatedly across tenants. You will build and extend the orchestration layer, connect models to security data through MCP servers, and define human checkpoints for agent autonomy.
You will also produce customer-facing analysis reports in clear language, feed detection gaps back into recommendations, and mentor less experienced analysts.
REQUIREMENTS:
- 4–8 years in threat hunting, detection engineering, SOC analysis or DFIR, with at least two years on proactive hunting or detection content rather than queue triage alone
- Fluency in a log query language (Dataprime, KQL, SPL, Lucene, SQL or equivalent); ability to write multi-stage aggregations, joins and time-window correlations
- Shipped something real with AI (an agent, MCP server/client, tool-calling workflow, LLM-driven enrichment or triage pipeline); experience automating hunts or investigations with AI is a plus
- Working command of MITRE ATT&CK as an analytic tool: mapping observed behavior to techniques and reasoning about coverage gaps
- Demonstrable incident analysis experience: timeline reconstruction, scoping, pivoting across sources, and separating what evidence proves from what it suggests
- Written communication that stands up to customer and auditor scrutiny; clarity, accurate hedging, and no unearned certainty
- Analytic discipline: state confidence levels, note what would disprove hypotheses, verify AI-generated conclusions against source data, and be comfortable concluding nothing was found
- Comfort working across multiple tenants with inconsistent data quality, partial log coverage, and no ability to change source systems
- This is a work-from-office role in Gurugram