Adversary Threat Hunter
Job Description
At Southern Company, our core objective is to provide a safe, reliable computing environment for the consumers of our services, both internally and externally. Our complex environment requires continual innovation and effective use of evolving technologies. Protecting the network helps ensure our users remain connected to critical applications, products, and services.
Position Overview:
Southern Company is seeking a knowledgeable, hands-on Adversary Threat Hunter to join our Cyber Security team. This role leads proactive threat hunting engagements to identify suspicious behavior, adversary activity, and unauthorized access across Southern Company networks and systems. The position also supports incident response, detection engineering, investigative processes, and recommendations for security technologies and controls that improve the company’s defensive posture.
The ideal candidate will have a strong cybersecurity and security operations background, with forensic, investigative, analytical, threat intelligence, and technical skills.
Qualifications:
Job Responsibilities:
Plan and conduct structured, hypothesis-driven threat hunting engagements
Collect and analyze data from multiple sources and tools to identify anomalies, suspicious activity, and potential adversary behavior
Maintain awareness of the current threat landscape through intelligence reports, internet research, and sector-specific sources
Partner with the Cyber Threat Intelligence team to understand threat actor behavior, tactics, techniques, procedures, and emerging threats
Support detection engineering and security monitoring by recommending improved SIEM detections, alert logic, and related capabilities
Recommend and support implementation of security controls and solutions based on lessons learned from hunting engagements
Partner with Threat Analysis and Incident Response teams to evaluate adversary techniques and improve defensive capabilities
Support incident response, remediation, recovery, threat scenario development, and response playbooks
Job Requirements:
Must pass NERC CIP and Insider Threat Protection background checks
Ability to work independently and as part of a team
Ability to understand business requirements, communicate technical findings, and recommend appropriate solutions
Strong critical thinking, independent judgment, and creative problem-solving skills
Occasional travel to local and regional locations in support of job duties and requirements
Desired certifications (one or more of the following):
Offensive Security Certified Professional (OSCP)
GIAC Security Essentials (GSEC)
GIAC Certified Forensic Examiner (GCFE)
GIAC Certified Incident Handler (GCIH)
GIAC Certified Intrusion Analyst (GCIA)
Copyright © 2026 Grabjobs Pte.Ltd. All Rights Reserved.