UNFI logo
UNFI
Posted 24 days agoVerified live 1d ago

Cybersecurity Threat Engineer - Remote

Brief overview

Remote
UndergradOr in progress
$84k–$153k/yrStated range
PythonPowerShellSIEMEDRThreat MonitoringThreat HuntingThreat IntelligenceIncident ResponseMITRE ATT&CKAPIsWindows and Linux/UnixCloud SecurityWritten and Verbal Communication

About the company

UNFI is North America’s Premier Food Wholesaler.

Job description

Summary

UNFI is seeking a Cybersecurity Threat Engineer to support the creation, tuning, and optimization of security detections that identify potential threats. The role assists with alert analysis, threat research, detection validation, security monitoring, SOAR playbook development, and automated response workflows while collaborating with multiple cybersecurity teams.

Responsibilities

  • Develop, tune, and maintain threat detection use cases, correlation rules, and analytics across SIEM, EDR, and cloud security platforms
  • Perform detection validation, gap analysis, and continuous optimization to improve detection coverage, reduce false positives, and enhance security monitoring effectiveness
  • Partner with internal Threat Intelligence team to research emerging threats, adversary tactics, techniques, and procedures (TTPs), and translate intelligence into actionable detections aligned with the MITRE ATT&CK framework
  • Participate in purple team exercises with offensive (red) and defensive (blue) teams to simulate real-world adversary TTPs, validate detection effectiveness, identify monitoring and response gaps, and support improvements to security controls and processes
  • Design, develop, and maintain SOAR playbooks to automate incident response, threat enrichment, alert triage, and remediation workflows
  • Build and maintain integrations between security technologies, cloud services, ticketing systems, and enterprise platforms using APIs and custom automation
  • Develop scalable automation solutions that improve operational efficiency, reduce manual effort, and support end-to-end security operations processes
  • Share learnings and contribute to SOC knowledge articles, job aids, and peer discussions on hunt methodology, adversary TTP analysis, detection tuning, and related techniques
  • Collaborate with Threat Intelligence, Threat Emulation, GRC, Cybersecurity Architecture, Security Operations, and Engineering teams
  • Stay current with industry trends through research, training, certifications, knowledge sharing, and conferences where applicable
  • Support threat assessment and modeling activities by documenting threats and contributing to resiliency initiatives that require broader non-SOC business partner awareness
  • Support security tooling assessments as assigned
  • Monitor and evaluate third-party hunt activities and summarize findings or recommendations for review by senior team members
  • Maintain a shared library of threat research integrated with threat intelligence and detection libraries
  • Perform analysis on specific threats, such as tracking ransomware group activity, with guidance from senior team members
  • Correlate internal telemetry, including SIEM, logs, and EDR data, with external threat intelligence
  • Apply intelligence to support use case development and detection rule creation through collaboration across teams
  • Participate in tabletop exercises or simulations based on current threat actor behavior
  • Participate in intelligence-sharing collaborations, such as with ISACs, government, or vendors, as appropriate for the role
  • Develop and maintain basic security tools, scripts, and automation to support threat hunting and incident response
  • Create and update security documentation, procedures, and threat models as needed
  • Compile and analyze data for management reporting and metrics as directed
  • Performs other duties as assigned

Skills

  • 0-3 years of professional experience in cybersecurity, security operations, infrastructure, systems administration, networking, software engineering, or related technology fields
  • 0-3 years of experience or demonstrated exposure to threat monitoring, threat hunting, threat intelligence, incident response, vulnerability management, or security operations
  • 0-3 years of working experience with Powershell, Python or other object-oriented scripting languages
  • Comfortable interacting with APIs and performing data transformation, enrichment, and analysis to support business and security objectives
  • Working knowledge of Windows and Linux/Unix platforms
  • Able to manage assigned work, follow priorities, and escalate when timelines or risks require attention
  • Strong written and verbal communication skills. Communicates clearly, accurately, and in a timely manner, adapting technical information for technical and non-technical audiences with guidance as needed
  • Collaborative and respectful of diverse people, thinking, and styles
  • Familiarity with testing, validating, or documenting detection rules in SIEM platforms
  • Foundational understanding of MITRE ATT&CK, Cyber Kill Chain, Pyramid of Pain, and Detection as code principles
  • Foundational understanding of cloud infrastructure and cloud security
  • Foundational understanding of software development tools and methodologies, ex. SDLC, Version Control (Git)
  • Developing technical and investigative skills, strong attention to detail, and a genuine interest in cybersecurity are essential for this role
  • Ability to multitask and prioritize work effectively
  • Highly motivated and willing to learn
  • Demonstrates ownership of assigned work and follows tasks through to completion
  • Developing critical thinking and security analysis skills
  • Clear written and verbal communication skills for technical and non-technical audiences
  • Ability to translate technical risk details into understandable language with guidance as needed
  • Foundational knowledge of threat research and adversary tactics and techniques frameworks, such as MITRE ATT&CK matrices, Cyber Kill Chain
  • Ability to contribute to briefings, presentations, and reports that convey analysis, threat trends, threat actor profiles, indicator bulletins, vulnerability details, and defensive strategies to varied audiences
  • Awareness of current and emerging cyber adversaries and their techniques, tactics, and procedures (TTPs)
  • Good judgment, sound escalation practices, and adherence to established procedures are required; the role generally operates with close supervision by management and senior team members
  • This position is classified as remote where the associate will perform remote work from their primary residence
  • This position may require the associate to travel to company offices, distribution centers, or other locations for specific meetings or other business reasons
  • Incumbent may sit for long periods of time at a desk or computer terminal
  • While performing the duties of this job, the employee is regularly required to sit; use hands to finger, handle, or feel; reach with hands and arms; and talk or hear
  • Incumbent may use calculators, keyboards, telephones, and other office equipment in the course of a normal workday
  • Stooping, bending, twisting, and reaching may be required in the completion of job duties
  • Bachelor's Degree in Computer Science, Cybersecurity, Information Technology, or a related discipline desired; equivalent education, training, certifications, or relevant IT/cybersecurity experience may be considered
  • Industry cybersecurity certifications such as Security+, GSEC, GISF, GCIH; certifications are preferred but not required
  • Preferred exposure to SIEM, EDR, web proxy, email security, and security testing platforms or frameworks
  • Preferred entry-level or practitioner cybersecurity certifications such as Security+, CEH, GSEC, GCIH, GCIA, or equivalent

Qualifications

Must Haves

  • 0-3 years of professional experience in cybersecurity, security operations, infrastructure, systems administration, networking, software engineering, or related technology fields
  • 0-3 years of experience or demonstrated exposure to threat monitoring, threat hunting, threat intelligence, incident response, vulnerability management, or security operations
  • 0-3 years of working experience with Powershell, Python or other object-oriented scripting languages
  • Comfortable interacting with APIs and performing data transformation, enrichment, and analysis to support business and security objectives
  • Working knowledge of Windows and Linux/Unix platforms
  • Able to manage assigned work, follow priorities, and escalate when timelines or risks require attention
  • Strong written and verbal communication skills. Communicates clearly, accurately, and in a timely manner, adapting technical information for technical and non-technical audiences with guidance as needed
  • Collaborative and respectful of diverse people, thinking, and styles
  • Familiarity with testing, validating, or documenting detection rules in SIEM platforms
  • Foundational understanding of MITRE ATT&CK, Cyber Kill Chain, Pyramid of Pain, and Detection as code principles
  • Foundational understanding of cloud infrastructure and cloud security
  • Foundational understanding of software development tools and methodologies, ex. SDLC, Version Control (Git)
  • Developing technical and investigative skills, strong attention to detail, and a genuine interest in cybersecurity are essential for this role
  • Ability to multitask and prioritize work effectively
  • Highly motivated and willing to learn
  • Demonstrates ownership of assigned work and follows tasks through to completion
  • Developing critical thinking and security analysis skills
  • Clear written and verbal communication skills for technical and non-technical audiences
  • Ability to translate technical risk details into understandable language with guidance as needed
  • Foundational knowledge of threat research and adversary tactics and techniques frameworks, such as MITRE ATT&CK matrices, Cyber Kill Chain
  • Ability to contribute to briefings, presentations, and reports that convey analysis, threat trends, threat actor profiles, indicator bulletins, vulnerability details, and defensive strategies to varied audiences
  • Awareness of current and emerging cyber adversaries and their techniques, tactics, and procedures (TTPs)
  • Good judgment, sound escalation practices, and adherence to established procedures are required; the role generally operates with close supervision by management and senior team members
  • This position is classified as remote where the associate will perform remote work from their primary residence
  • This position may require the associate to travel to company offices, distribution centers, or other locations for specific meetings or other business reasons
  • Incumbent may sit for long periods of time at a desk or computer terminal
  • While performing the duties of this job, the employee is regularly required to sit; use hands to finger, handle, or feel; reach with hands and arms; and talk or hear
  • Incumbent may use calculators, keyboards, telephones, and other office equipment in the course of a normal workday
  • Stooping, bending, twisting, and reaching may be required in the completion of job duties

Nice to Haves

  • Bachelor's Degree in Computer Science, Cybersecurity, Information Technology, or a related discipline desired; equivalent education, training, certifications, or relevant IT/cybersecurity experience may be considered
  • Industry cybersecurity certifications such as Security+, GSEC, GISF, GCIH; certifications are preferred but not required
  • Preferred exposure to SIEM, EDR, web proxy, email security, and security testing platforms or frameworks
  • Preferred entry-level or practitioner cybersecurity certifications such as Security+, CEH, GSEC, GCIH, GCIA, or equivalent

Benefits

  • For Washington positions (or positions that may be performed remotely from Washington), Washington-specific paid time off details apply.
  • Paid Time Off
  • Sick Time
  • Paid holidays
  • Parental leave
  • 401K Program
  • Medical insurance
  • Dental insurance
  • Vision insurance
  • Life insurance
  • Accidental death and dismemberment insurance
  • Short-term disability insurance program
  • Long-term disability insurance program
  • Flexible Spending Account and/or Health Savings Account, subject to meeting the eligibility requirements and the terms and conditions of these programs, and subject to any requirements under applicable collective bargaining agreements.

More jobs like this