
Are you ready to make an impact at DTCC?
Do you want to work on innovative projects, collaborate with a dynamic and supportive team, and receive investment in your professional development? At DTCC, we are at the forefront of innovation in the financial markets. We are committed to helping our employees grow and succeed. We believe that you have the skills and drive to make a real impact. We foster a thriving internal community and are committed to creating a workplace that looks like the world that we serve.
The Information Technology group delivers secure, reliable technology solutions that enable DTCC to be the trusted infrastructure of the global capital markets. The team delivers high-quality information through activities that include development of essential, building infrastructure capabilities to meet client needs and implementing data standards and governance.
Pay and Benefits:
The Impact you will have in this role:
Being a member of CISO Team and as a Threat Hunt Senior Associate, you will execute hypothesis-driven hunts across endpoint, identity, network, and cloud telemetry; track and document hunt activity end-to-end; and translate findings into actionable improvements, detections, response playbooks, hardening tasks, and prioritized engineering work.
This role is hands-on and requires a practitioner mindset: you’ll spend your time asking better questions of the data, validating what “normal” looks like in complex systems, and proving or disproving attacker behaviors using repeatable methods. You’ll also provide surge support to incident response during investigations where hunt techniques accelerate containment and root cause analysis.
This is a mid-level role for someone who can operate independently on scoped hunts, communicate clearly, and contribute to a sustained, measurable hunting program.
Your Primary Responsibilities:
Hunt Execution & Documentation (Core)
Investigative Workflows & Telemetry Correlation
Detection Engineering & Continuous Improvement
Purple Teaming & Adversary Simulation
**NOTE: The Primary Responsibilities of this role are not limited to the details above. **
Qualifications:
Talents Needed for Success:
Certifications (any of the following are valued):
Tools & Technologies
You won’t need every item day one—but you should be comfortable learning quickly and working across a modern stack.
EDR/XDR: Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne (or equivalent)
SIEM / Analytics: Microsoft Sentinel (KQL), Splunk (SPL), Elastic (EQL/KQL), Chronicle/Google SecOps
Cloud & Identity: Azure/AWS logs, Entra ID/Azure AD, Okta (or equivalent), CloudTrail/Activity Logs, IAM telemetry
Containers: Kubernetes audit logs, container runtime signals, registry, and CI/CD telemetry
Detection Content: Sigma, YARA, ATT&CK mappings, custom IOAs, correlation rules
Workflow: Case management, runbooks/playbooks, SOAR tooling, structured reporting, and metrics
The salary range is indicative for roles at the same level within DTCC across all US locations. Actual salary is determined based on the role, location, individual experience, skills, and other considerations. We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, sex, gender, gender expression, sexual orientation, age, marital status, veteran status, or disability status. We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.

With over 50 years of experience, DTCC is the premier post-trade market infrastructure for the global financial services industry. From 21 locations around the world, DTCC, through its subsidiaries, automates, centralizes, and standardizes the processing of financial transactions, mitigating risk, increasing transparency, enhancing performance and driving efficiency for thousands of broker/dealers, custodian banks and asset managers. Industry owned and governed, the firm innovates purposefully, simplifying the complexities of clearing, settlement, asset servicing, transaction processing, trade reporting and data services across asset classes, bringing enhanced resilience and soundness to existing financial markets while advancing the digital asset ecosystem. In 2024, DTCC’s subsidiaries processed securities transactions valued at U.S. $3.7 quadrillion and its depository subsidiary provided custody and asset servicing for securities issues from over 150 countries and territories valued at U.S. $99 trillion. DTCC’s Global Trade Repository service, through locally registered, licensed, or approved trade repositories, processes more than 25 billion messages annually. To learn more, please visit us at www.dtcc.com or connect with us on LinkedIn, X, YouTube, Facebook and Instagram.
View our Social Media Community Rules of Engagement: https://www.dtcc.com/press-room/social-media-rules-of-engagement