
REMOTE - Security Engineer II (Threat Hunter)
Ross Stores, Inc. · United States
- Hybrid
- Full-time
- $156,675 / year
- United States
Job highlights
- Proactively hunt advanced threats and malware.
- Analyze threat intelligence from multiple sources.
- Create and automate detection rules.
- Report findings to leadership effectively.
- Collaborate across IT teams.
About the role
About the Role
Join Ross, a leading off-price retail chain with over 2,200 stores, and be part of a team that values you! We are seeking a Security Engineer II (Threat Hunter) to proactively hunt for threats, analyze cyber intelligence, and enhance our security posture. This role is crucial in identifying emerging threats and mitigating risks in a complex environment.
What You'll Do
- Proactively hunt for advanced persistent threats (APTs), malware, and other malicious activities across networks, systems, and applications, identifying hidden threats that evade traditional security measures.
- Synthesize large volumes of data from multiple sources to develop clear, actionable intelligence and create detailed threat intelligence reports for technical teams and senior leadership.
- Create, optimize, and automate detection rules and enrichment logic using scripting languages like Python and SQL.
- Respond to escalation requests from the Helpdesk, NOC, junior analysts, or other IT representatives.
- Contribute to the monthly Cyber Defense dashboard with relevant performance indicators and security threat assessments.
- Develop and implement automated workflows and playbooks to streamline threat detection, analysis, and response processes, ensuring quick and effective mitigation of identified threats.
- Map adversary behaviors using the MITRE ATT&CK framework to understand attack vectors and predict potential threats.
- Participate in 24x7 on-call duties on a rotational basis.
About the Team & Company
Ross Stores, Inc. is a Fortune 500 company committed to providing an inclusive work environment with continuous learning opportunities and development for our teams. Our corporate headquarters are in Dublin, CA, with additional offices and distribution centers nationwide. We focus on bringing customers high-quality brands at extraordinary savings through an exciting treasure hunt experience. Our values emphasize people, success, career growth, teamwork, and a commitment to Diversity, Equality & Inclusion.
Qualifications
- Minimum of 8+ years of experience in cybersecurity, with at least 5+ years focused on threat intelligence analysis and cyber threat hunting.
- Proven experience leading or mentoring CTI analysts.
- Strong expertise in threat intelligence platforms (TIPs), SIEM tools, and endpoint detection technologies.
- Proficiency in collecting, analyzing, and disseminating threat intelligence from OSINT, internal sources, and commercial threat feeds.
- Hands-on experience with automated workflows, playbook development, and advanced threat hunting techniques.
- Deep understanding of attack methodologies, APTs, malware, ransomware, and other cyber threats.
- Familiarity with the MITRE ATT&CK framework and indicators of compromise (IoCs).
- Ability to synthesize complex data and produce actionable, clear intelligence for both technical and non-technical audiences.
- Strong communication skills for reporting and briefing leadership on emerging threats.
- Security certifications such as CISSP, GCTI, or equivalent are highly preferred.
- Experience working in large enterprise environments with complex infrastructures and multiple overlapping tools.
- Proficiency in scripting languages such as Python and SQL for data analysis and automation.
- Knowledge of STIX/TAXII protocols for automated sharing and ingestion of structured threat intelligence data.
- Strong understanding of dark web marketplaces, threat actor infrastructures, ransomware groups, and emerging cybercriminal tactics, techniques, and procedures (TTPs).
Key skills/competency
- Threat Hunting
- Cyber Threat Intelligence
- SIEM
- Endpoint Detection
- Python
- SQL
- MITRE ATT&CK
- OSINT
- Security Engineering
- Incident Response
Skills & topics
- Security Engineer
- Threat Hunter
- Cybersecurity
- Threat Intelligence
- SIEM
- Endpoint Detection
- Python
- SQL
- MITRE ATT&CK
- OSINT
How to get hired
- Tailor your resume: Highlight 8+ years cybersecurity experience, 5+ in threat intelligence/hunting, and relevant certifications (CISSP, GCTI).
- Showcase technical skills: Emphasize proficiency in SIEM, EDR, Python, SQL, and MITRE ATT&CK framework.
- Demonstrate threat intelligence expertise: Detail experience with TIPs, OSINT, and analyzing complex data for actionable insights.
- Prepare for interviews: Be ready to discuss complex enterprise environments, mentoring experience, and rapid threat mitigation strategies.
Technical preparation
Behavioral questions
Frequently asked questions
- What is the salary range for the Security Engineer II (Threat Hunter) role at Ross Stores, Inc.?
- The base salary range for the Security Engineer II (Threat Hunter) position at Ross Stores, Inc. is $108,800 - $204,550. This range is dependent on factors such as experience, skills, qualifications, education, certifications, seniority, and location. The total compensation package may include other rewards in addition to base salary.
- Is the Security Engineer II (Threat Hunter) role at Ross Stores, Inc. remote?
- Yes, the Security Engineer II (Threat Hunter) position at Ross Stores, Inc. can be performed remotely anywhere within the United States.
- What are the key technical skills required for the Security Engineer II (Threat Hunter) position?
- Key technical skills for this role include expertise in threat intelligence platforms (TIPs), SIEM tools, endpoint detection technologies, proficiency in Python and SQL for automation, and a deep understanding of the MITRE ATT&CK framework. Experience with STIX/TAXII protocols is also beneficial.
- What is the minimum experience required for the Security Engineer II (Threat Hunter) role at Ross Stores, Inc.?
- The minimum requirement is 8+ years of experience in cybersecurity, with at least 5 of those years specifically focused on threat intelligence analysis and cyber threat hunting.
- Does Ross Stores, Inc. require specific security certifications for the Security Engineer II (Threat Hunter) role?
- While not strictly mandatory, security certifications such as CISSP, GCTI, or equivalent are highly preferred for the Security Engineer II (Threat Hunter) position at Ross Stores, Inc.
- What does 'proactive threat hunting' mean in the context of the Security Engineer II role at Ross Stores?
- Proactive threat hunting involves actively searching for advanced persistent threats (APTs), malware, and other malicious activities that may have bypassed traditional security measures. It requires analyzing data from various sources to uncover hidden threats before they can cause significant damage.
- Will the Security Engineer II (Threat Hunter) need to work on-call at Ross Stores, Inc.?
- Yes, this role includes 24x7 on-call duties on a rotational basis, ensuring continuous coverage and response to security incidents.