Cyber Security – Senior Threat Hunter
The opportunity:
We are looking for SOC L3 Threat Hunter is responsible for proactively identifying advanced, stealthy, and previously unknown threats across enterprise environments. This role operates beyond alert-driven SOC operations, focusing on hypothesis-based threat hunting, adversary behaviour analysis, and closing detection gaps across Microsoft Sentinel, Microsoft Defender for Endpoint, and Defender for IoT.
The role serves as a technical authority within the SOC, supporting L1/L2 analysts, partnering with Incident.Response and Detection Engineering teams, and continuously improving the organization’s threat visibility and SOC maturity.
Your key responsibilities:
· Conduct hypothesis-driven, TTP-centric threat hunts using telemetry from Microsoft
Sentinel and Microsoft Defender platforms.
· Develop hunt hypotheses based on:
Adversary campaigns
MITRE ATT&CK techniques
Threat intelligence
Observed environmental weaknesses
· Hunt for advanced attack behaviors.
· Validate findings with evidence and determine impact before escalation.
· Perform advanced KQL-based threat hunting across large data volumes in Microsoft
Sentinel.
· Identify detection blind spots, noisy analytics, and data quality issues.
· Conduct advanced endpoint hunting using Defender Advanced Hunting
· Correlate endpoint telemetry with SIEM data to reconstruct end-to-end kill chains.
· Perform threat hunting across IoT/OT and ICS environments using Microsoft Defender
for IoT telemetry where applicable
· Produce formal threat hunt reports detailing: Hunt Hypothesis, Data Sources, Findings
and evidence, MITRE ATT&CK mapping and recommended remediation
Skills and attributes for success:
· 4–7+ years in SOC, Threat Hunting, Incident Response, or Detection Engineering.
· Proven experience performing proactive threat hunting (not tool monitoring).
· Experience working in enterprise-scale SIEM and EDR environments.
· Advanced expertise in MS Sentinel and Defender Suites
· Strong mastery of KQL (Kusto Query Language)
· Deep understanding of MITRE ATT&CK, Adversary tradecraft, Malware and
post-exploitation techniques
· Strong skills in Endpoint telemetry analysis, Network traffic analysis, Log correlation
across multiple security layers
· Advanced analytical and critical-thinking skills
· Strong written and verbal communication
· Curiosity-driven, attacker-mindset analysis
· Ability to work independently on ambiguous, high-impact threats
Qualifications:
· Bachelor’s degree or a master’s degree in computer engineering, IT security, Computer
Science, Information Systems or other related fields.
· Highly proficient in English with good written and oral communication.
· Good analytical, problem solving and interpersonal skills.
What we offer
In EY GDS Spain, we’re committed to fostering a vibrant environment where every team member can thrive. We provide a space for continuous learning and the flexibility to define your own success, empowering you to make a meaningful impact in your own way. Our diverse and inclusive culture values who you are and encourages you to help others find their voice.
Additionally, here’s what makes us stand out:
Join us at EY GDS Spain, where your journey is supported, your contributions are celebrated, and your future is bright.
To learn more about what we offer, visit our Careers in Global Delivery Services | EY - Global
About EY GDS
EY Global Delivery Services (EY GDS) is a dynamic and truly global delivery network of over 75,000 people working across the world, to provide innovative and strategic business solutions to our clients worldwide. We play a vital role in growth strategy, helping our clients become agile and efficient, and helping fulfill our purpose to build a better working world.
From accountants to coders, we offer a wide variety of fulfilling career opportunities that span all business disciplines. We look for skills that are evergreen and our roles evolve with industry trends. We also work across Finance, Business Development, Technology, Talent, Procurement and Risk Management functions to help our teams operate as efficiently and effectively as possible.
Across our 10 locations and 21 cities, we work with teams from all service lines, geographies, and sectors. We operate in Argentina, Hungary, India, the Philippines, Poland, Sri Lanka, Mexico, Spain and the United Kingdom.
Our EY GDS Spain office is located at Malaga Technology Park and currently employs over 1000 people.
If you are interested in being part of our team, we kindly invite you to submit your CV in English to apply for this position.
The exceptional EY GDS experience. It’s yours to build.

EY is building a better working world by creating new value for clients, people, society, the planet, while building trust in the capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams in more than 150 countries work across a full spectrum of services in assurance, consulting, tax, strategy and transactions, strengthened by sector experience and diverse ecosystem partners.
Find out more about the EY global network: http://ey.com/en_gl/legal-statement