← Back to results

threat-hunting jobs in San Diego

$105,400 – $207,800 · Posted 2 days ago

Design and implement secure, scalable Google SecOps architectures for SIEM and SOAR deployments aligned with enterprise security policies and regulatory requirements (GDPR, PCI DSS). Lead log ingestion pipelines using data fabric technologies, develop threat detection content, translate security operations into automated SOAR playbooks, and mentor junior team members.… Requires 7+ years in security operations or threat detection engineering, hands-on experience with Google Chronicle/Siemplify, Python automation, Logstash/Gostash, ETL technologies (Cribl, Bindplane, Kafka), and familiarity with security frameworks like MITRE ATT&CK.

San DiegoLast seen 1 day ago
Posted 2 days ago

Lead high-severity incident investigations, mentor L1/L2 analysts, and drive detection engineering at a cybersecurity services firm. Responsibilities include threat hunting, malware analysis, digital/network forensics, SIEM/EDR tuning (KQL, SPL, Sigma, YARA), playbook development, and automation scripting in Python/PowerShell/Bash.… This is a 5+ year senior incident responder role requiring deep hands-on expertise across the full incident response lifecycle, MITRE ATT&CK, and client-facing technical briefings.

San DiegoLast seen 1 day ago
$118,500 – $207,750 · Posted 7 days ago

Lead the design and implementation of enterprise security enforcement technologies, including SIEM platforms, endpoint security, threat detection, and incident response systems. Develop and maintain a forward-looking cybersecurity technology roadmap aligned with NIST frameworks and business objectives, evaluating emerging threats and technologies to strengthen organizational security capabilities.… Conduct threat hunting, penetration testing, and detection engineering activities while driving automation of security controls, policy enforcement, and response across complex technology environments. Mentor cybersecurity teams and influence enterprise security strategy across large organizations, with demonstrated experience securing AI-enabled solutions and understanding AI-specific security considerations.

San DiegoLast seen 5 days ago
$129,986 – $216,609 · Posted 27 days ago

Lead a team of security engineers responsible for the operational effectiveness and innovation of security engineering controls across LPL Financial. Manage day-to-day operations and maintenance of critical security infrastructure including SIEM, EDR, DLP, vulnerability management, IAM systems, and network security appliances.… Drive continuous improvement initiatives, develop incident response playbooks, collaborate with engineering teams on security integration, and provide technical leadership and mentorship to junior engineers. Requires 10+ years in information security with at least 5 years in a security operations or engineering leadership role.

San DiegoLast seen 25 days ago
Posted 1 month ago

Security Operations Analyst role monitoring and triaging alerts across endpoint, cloud, identity, network, and SaaS using enterprise SIEM and XDR platforms. Responsibilities include investigating alerts, performing root-cause analysis, tuning detections, owning initial response for mid-tier incidents, participating in on-call rotation, running targeted threat hunts, and contributing to playbooks and post-incident reviews.… Requires 2–5 years of hands-on SecOps, SOC, or incident response experience; proficiency with enterprise SIEM query languages, EDR tooling, and scripting in Python/PowerShell/Bash; and solid understanding of MITRE ATT&CK and network fundamentals.

San DiegoLast seen 1 month ago
$113,200 – $141,500 · Posted 1 month ago

This Cybersecurity Manager role owns vulnerability and exposure management, leads penetration testing, threat hunting, and threat intelligence programs. The position integrates AI and machine learning into security operations to enhance threat detection and anomaly identification, manages security tools and incident response, and ensures the security of AI/ML systems across the enterprise.… The candidate will develop automation scripts and SOAR workflows, conduct forensic investigations, and drive continuous improvement in the security posture. Required qualifications include 5+ years of cybersecurity experience, a relevant bachelor's degree, and an industry-recognized certification (Security+, SSCP, CCNP Security, CISSP, or equivalent).

San DiegoLast seen 1 month ago
Posted 1 month ago

Lead detection operations, incident response, and security operations maturation for a growing security team. Operate SIEM/XDR across endpoint, cloud, identity, network, and SaaS telemetry; conduct complex investigations; tune detections; and drive root-cause analysis and post-incident improvements.… Require 6+ years of hands-on security operations, detection engineering, or incident response experience with deep proficiency in SIEM/XDR query languages, EDR platforms, scripting (Python, PowerShell, Bash), and MITRE ATT&CK framework application. Mentor analysts, define playbooks and runbooks, lead threat hunts, and own SecOps metrics and operational-readiness reporting.

San DiegoLast seen 1 month ago
Posted 1 month ago

This is a hands-on security engineering role focused on running Saronic's cyber threat intelligence program. The engineer will track nation-state and advanced criminal adversaries targeting the defense industrial base, operationalize indicators and TTPs into detections and hunts, produce finished intelligence products, and fuse external threat feeds with internal telemetry to prioritize real exposures.… The role requires 4+ years in cyber threat intelligence, threat hunting, detection engineering, or intrusion analysis with demonstrable experience tracking sophisticated or state-sponsored adversaries.

San DiegoLast seen 1 month ago