
REMOTE - Security Engineer II (Threat Hunter)
Ross Stores, Inc. · United States
- Hybrid
- Full-time
- $150,000 / year
- United States
Job highlights
- Proactively hunt for advanced threats and analyze intelligence.
- Develop and automate detection rules using Python/SQL.
- Collaborate with teams on threat mitigation strategies.
- Create detailed reports for leadership and technical teams.
- Requires 8+ years cybersecurity experience, 5+ in threat hunting.
About the role
About the Role
Ross Stores, Inc. is seeking a Security Engineer II (Threat Hunter) to join their team. This remote position focuses on proactive threat hunting and cyber threat intelligence analysis to identify emerging threats, mitigate risks, and enhance the organization's security posture. The role requires advanced technical expertise in cybersecurity tools, threat detection technologies, and cyber threat intelligence analysis. You will be responsible for collecting, analyzing, and disseminating cyber threat intelligence from various sources including OSINT, Threat Intelligence platforms, SIEM, and endpoint detection systems to detect advanced persistent threats (APTs), malware, and other malicious activities. Experience in complex environments, applying structured analysis processes, and collaborating with cross-functional teams is essential.
Key Responsibilities
- Proactively hunt for advanced persistent threats (APTs), malware, and other malicious activities across networks, systems, and applications, identifying hidden threats that evade traditional security measures.
- Synthesize large volumes of data from multiple sources to develop clear, actionable intelligence and create detailed threat intelligence reports for technical teams and senior leadership.
- Create, optimize, and automate detection rules and enrichment logic using scripting languages like Python and SQL.
- Respond to escalation requests from the Helpdesk, NOC, junior analysts, or other IT representatives.
- Contribute to monthly Cyber Defense dashboards with relevant performance indicators and security threat assessments.
- Develop and implement automated workflows and playbooks to streamline threat detection, analysis, and response processes, ensuring quick and effective mitigation of identified threats.
- Map adversary behaviors using the MITRE ATT&CK framework to understand attack vectors and predict potential threats.
- Participate in 24x7 on-call duties on a rotational basis.
What We Offer
- Join a team that values its people and fosters a winning culture of excellence, learning, and evolution.
- Experience career growth as we develop industry-leading talent, with opportunities for professional development.
- Engage in teamwork to solve complex problems and find the right solutions.
- Contribute to a company committed to Diversity, Equality & Inclusion and making a positive community impact.
Qualifications and Skills
- Minimum of 8+ years of experience in cybersecurity, with at least 5+ years focused on threat intelligence analysis and cyber threat hunting.
- Proven experience leading or mentoring CTI analysts.
- Strong expertise in threat intelligence platforms (TIPs), SIEM tools, and endpoint detection technologies.
- Proficiency in collecting, analyzing, and disseminating threat intelligence from OSINT, internal sources, and commercial threat feeds.
- Hands-on experience with automated workflows, playbook development, and advanced threat hunting techniques.
- Deep understanding of attack methodologies, APTs, malware, ransomware, and other cyber threats.
- Familiarity with the MITRE ATT&CK framework and indicators of compromise (IoCs).
- Ability to synthesize complex data and produce actionable, clear intelligence for both technical and non-technical audiences.
- Strong communication skills for reporting and briefing leadership on emerging threats.
- Security certifications such as CISSP, GCTI, or equivalent are highly preferred.
- Experience working in large enterprise environments with complex infrastructures and multiple overlapping tools.
- Excellent reporting and communication skills with the ability to present technical findings to varied audiences.
- Proficiency in scripting languages such as Python and SQL for data analysis and automation.
- Knowledge of STIX/TAXII protocols for automated sharing and ingestion of structured threat intelligence data across systems.
- Strong understanding of dark web marketplaces, threat actor infrastructures, ransomware groups, and emerging cybercriminal tactics, techniques, and procedures (TTPs).
Key Skills/Competency
- Threat Hunting
- Cyber Threat Intelligence
- SIEM
- Endpoint Detection
- Python
- SQL
- MITRE ATT&CK
- OSINT
- Incident Response
- Security Engineering
Skills & topics
- Security Engineer
- Threat Hunter
- Cybersecurity
- Threat Intelligence
- SIEM
- Endpoint Detection
- Python
- SQL
- MITRE ATT&CK
- OSINT
- Remote
How to get hired
- Tailor your resume: Highlight your 8+ years of cybersecurity experience, specifically 5+ years in threat intelligence and hunting, and showcase proficiency in SIEM, EDR, Python, and SQL.
- Showcase threat hunting expertise: Emphasize your experience with the MITRE ATT&CK framework, OSINT, and developing automated workflows.
- Demonstrate leadership: Mention any experience leading or mentoring Cyber Threat Intelligence (CTI) analysts.
- Prepare for technical interviews: Be ready to discuss advanced threat hunting techniques, APTs, malware analysis, and scripting capabilities.
- Understand the company: Research Ross Stores' commitment to technology and security within the retail sector.
Technical preparation
Behavioral questions
Frequently asked questions
- What is the salary range for the Security Engineer II Threat Hunter role at Ross Stores?
- The base salary range for this Security Engineer II Threat Hunter position at Ross Stores is $108,800 - $204,550 annually. This range is subject to factors such as experience, skills, qualifications, education, certifications, seniority, and location.
- Is the Security Engineer II Threat Hunter position at Ross Stores remote?
- Yes, the Security Engineer II Threat Hunter position at Ross Stores can be performed remotely anywhere within the United States.
- What are the key technical skills required for the Security Engineer II Threat Hunter job at Ross Stores?
- Key technical skills include at least 8 years of cybersecurity experience with 5+ years in threat intelligence and hunting, proficiency in SIEM, endpoint detection, Python, SQL, OSINT, and familiarity with the MITRE ATT&CK framework. Experience with automated workflows and playbook development is also crucial.
- What kind of experience is needed to be considered for the Threat Hunter role at Ross Stores?
- The role requires a minimum of 8 years in cybersecurity, with a strong focus on threat intelligence analysis and cyber threat hunting for at least 5 of those years. Experience leading or mentoring CTI analysts is also highly valued.
- Are there any specific certifications preferred for the Security Engineer II Threat Hunter position at Ross Stores?
- While not strictly required, security certifications such as CISSP, GCTI, or equivalent are highly preferred for the Security Engineer II Threat Hunter role at Ross Stores.
- Does the Security Engineer II Threat Hunter role at Ross Stores involve on-call duties?
- Yes, the Security Engineer II Threat Hunter position at Ross Stores does involve 24x7 on-call duties on a rotational basis.
- What is the importance of the MITRE ATT&CK framework for this role at Ross Stores?
- Familiarity with the MITRE ATT&CK framework is important for the Security Engineer II Threat Hunter role at Ross Stores as it's used to map adversary behaviors, understand attack vectors, and predict potential threats.
- How does Ross Stores support career growth for its Security Engineers?
- Ross Stores emphasizes career growth by developing industry-leading talent, believing that company growth is tied to employee development. They offer continuous learning opportunities and development for their teams.
Similar roles
Open positions we recommend based on this role.