Senior Threat Hunting & Incident Response Engineer
Full-time
Gurugram, Haryana, India
Description
Job Description
Snowbit is a cybersecurity technology innovator with a vision to empower organizations across the globe to quickly, efficiently, and cost-effectively ready themselves to address omnipresent cyber risk. Built off years of Israeli cybersecurity experience, Snowbit is looking to offer the broadest managed detection and response offering available today. Snowbit is part of the Coralogix group, with Coralogix rebuilding the path to observability by offloading the burden of indexing and providing deep insights, at an infinite scale, for less than half the cost.
Snowbit is looking for an experienced Senior Threat Hunting & Incident Response Engineer to join our Managed Detection and Response (MDR) team. This role requires expertise in incident response, threat hunting, with a strong emphasis on cloud environments and Kubernetes. You will lead efforts to protect our customers from advanced cyber threats while contributing to the continuous improvement of Snowbit’s methodologies, processes, and technology stack.
Role snapshot
We are hiring a senior engineer to run proactive threat hunts and deliver log-based incident analysis across our customers' Coralogix environments. The role sits in the Threat Detection & Response (TDR) team and exists because hunt coverage is constrained by analyst hours, not by data. We are closing that gap by building agentic hunting capability, so this hire both hunts and builds the systems that hunt.
About the team
TDR's scope is threat hunting, incident response support and threat intelligence. We own detection engineering and proactive hunting rather than queue-driven alert triage. This is a build-and-investigate role, where the work is forming the hypothesis, proving or disproving it in the data, and turning what we learn into durable detection logic.
We work across multiple customer Coralogix tenants, each with its own log sources, naming conventions and data quality. A hunt written once has to be adapted, validated and re-run per environment, which is where most of the craft lives.
Requirements
What you'll do
The role splits roughly 40% proactive hunting, 25% detection engineering, 20% incident analysis support and reporting, and 15% building the agentic tooling that makes the first three scale. That mix shifts during active customer incidents.
Proactive threat hunting
• Develop and run hypothesis-driven hunts across cloud, identity, endpoint and network telemetry in customer Coralogix tenants.
• Translate threat intelligence, MITRE ATT&CK techniques and post-incident lessons into testable hunt hypotheses with defined data requirements and success criteria.
• Build and maintain a reusable hunt library so a hunt proven in one environment can be re-run in another with known adaptations.
• Establish baselines for normal behaviour per environment and identify the deviations worth escalating.
Detection engineering
• Write, tune and validate detection rules and alert definitions, with documented logic, expected false-positive profile and response guidance.
• Measure detection coverage against ATT&CK and close the gaps that matter most for each customer's threat profile.
• Reduce alert noise by improving rule precision rather than raising thresholds, and evidence the improvement.
Incident response support
• Perform log-based analysis during customer incidents: reconstruct timelines, scope affected identities and assets, and establish what the evidence does and does not support.
• Identify indicators of compromise and pivot across data sources to find related activity.
• Hand the customer's IR team a defensible evidence package and clear, prioritised recommendations.
Building agentic threat hunting
• Turn manual hunts into agentic ones: encode a hypothesis, its queries, its pivots and its scoring into a workflow that runs repeatedly across tenants without an analyst driving each step.
• Build and extend the orchestration layer (specialist agents per log source, a correlation layer that links findings across identity, cloud and network telemetry, and a customer context layer that keeps each tenant's baselines distinct).
• Connect models to security data through MCP servers and clients, and package repeatable procedures as reusable skills the whole team can run.
• Define the human checkpoints: what an agent may do unattended, what requires analyst verification before it reaches a customer, and how every finding traces back to source evidence.
• Evaluate the system over time (false positives, unsupported conclusions, query and prompt drift) and improve it against that evidence rather than impressions.
Reporting and enablement
• Produce customer-facing analysis reports in clear, non-sensational language that distinguishes confirmed findings from assessments.
• Feed detection and logging gaps found during hunts back into onboarding and coverage recommendations.
• Mentor less experienced analysts on query technique, evidence handling and analytic rigour.
What you'll need
1. 4 – 8 years in threat hunting, detection engineering, SOC analysis or DFIR, with at least two spent on proactive hunting or detection content rather than queue triage alone.
2. Fluency in a log query language - Dataprime, KQL, SPL, Lucene, SQL or equivalent. You should be able to write multi-stage aggregations, joins and time-window correlations without reaching for a template.
3. You build with AI, not just alongside it. You have shipped something real (an agent, an MCP server or client, a tool-calling workflow, an LLM-driven enrichment or triage pipeline) and you can explain where it worked, where it failed and how you knew the difference. If you have automated a hunt or an investigation this way, lead with it.
4. Working command of MITRE ATT&CK as an analytic tool: mapping observed behaviour to techniques, and reasoning about coverage gaps, not just tagging rules after the fact.
5. Demonstrable incident analysis experience: timeline reconstruction, scoping, pivoting across sources, and separating what the evidence proves from what it suggests.
6. Written communication that stands up to customer scrutiny. You will write reports read by security leaders and sometimes by auditors. Clarity, accurate hedging and no unearned certainty.
7. Analytic discipline, you state your confidence level, you note what would disprove your hypothesis, you verify AI-generated conclusions against source data, and you are comfortable concluding that nothing was found.
8. Comfort working across multiple tenants with inconsistent data quality, partial log coverage and no ability to change the source systems.
9. This is a work from Office role in Gurugram.
Cultural Fit
We’re seeking candidates who are hungry, humble, and smart. Coralogix fosters a culture of innovation and continuous learning, where team members are encouraged to challenge the status quo and contribute to our shared mission. If you thrive in dynamic environments and are eager to shape the future of observability solutions, we’d love to hear from you.
Coralogix is an equal opportunity employer and encourages applicants from all backgrounds to apply.