Who We Are
At Kyndryl, we run and reimagine the mission-critical technology systems that drive advantage for the world’s leading businesses. We are at the heart of progress; with proven expertise and a continuous flow of AI-powered insight, enabling smarter decisions, faster innovation, and a lasting competitive edge. For our people—Kyndryls—that means doing purposeful work that powers human progress. Join us and experience a flexible, supportive environment where your well-being is prioritized and your potential can thrive.
The Role
The Role
We're looking for a Cyber Threat Hunting expert to proactively identify malicious activity that has evaded traditional security controls by leveraging intelligence-driven, behavioral, situational, and hypothesis-based hunting methodologies.
What You Will Do
The successful candidate will transform large-scale security telemetry, attacker tradecraft, and cyber threat intelligence into actionable hunting activities, detection opportunities, and security improvements that strengthen our customers' cyber resilience.
Working closely with Threat Intelligence, Detection Engineering, Incident Response and SOC teams, you will investigate emerging threats, uncover hidden adversary activity, and continuously improve detection coverage across enterprise environments.
Who You Are
Required Skills and Experience
- 5 years of relevant cyber security industry experience in roles such as Threat Hunting, Detection Engineering, Digital Forensics, Incident Response or Penetration tester.
- Strong capability in enterprise log analytics, with proficiency in platforms such as Microsoft Sentinel, Qradar, Elastic, Splunk, Palo Alto XSIAM or similar solutions.
- Demonstrable experience conducting hypothesis-driven threat hunts based on large-scale telemetry and security logs.
- Strong analytical skills and problem-solving thinking, combined with a structured, investigative approach.
- Deep understanding of Telemetry logs.
- Deep technical understanding of attacker TTPs, intrusion lifecycle, and lateral movement behaviors.
- Advanced query development skills using KQL, SPL, ES|QL, SQL, or equivalent data exploration and analytics languages.
Preferred Skills and Experience
- Demonstrated experience in hypothesis-driven hunting and investigative research against complex multi-domain telemetry data.
- Familiarity with MITRE ATT&CK, threat intelligence integration, malware analysis fundamentals, network forensics, and EDR/XDR platforms.
- Scripting or data analytics experience (Python, PowerShell, or equivalent).
- Comprehensive understanding of enterprise security controls, SIEM pipelines, and data correlation techniques.
- Relevant certifications such as GCFA, GCFE, eCTHP, GCIH, GCED, GNFA, OSCP, OSEP, OSWE, CRTO, GXPN, GPEN, GDAT or equivalent experience
Being You
The “Kyn” in Kyndryl means kinship, which represents the strong bonds we have with each other, our customers and our communities. We focus on ensuring all Kyndryls feel included and we welcome people of all cultures, backgrounds, and experiences. Even if you don’t meet every requirement, we encourage you to apply. We believe in growth, and we’re excited to see what you can bring. At Kyndryl, employee feedback has told us that our number one driver of employee engagement is belonging. That sense of belonging — being a valued, respected, trusted member of the team — is fundamental to our culture and fueling great experiences for our customers. This dedication to welcoming everyone into our company means that Kyndryl gives you the ability to thrive and contribute to our culture of empathy and shared success. That’s The Kyndryl Way.
What You Can Expect
Your career with us isn’t just a job—it’s an adventure with purpose. We offer a dynamic, hybrid-friendly culture that supports your well-being and empowers you to grow. Our Be Well programs are thoughtfully designed to support your financial, mental, physical, and social health—because we know that when you feel your best, you do your best.
From your very first day, you’ll dive into impactful work that powers the systems our customers rely on every day. You won’t just contribute—you’ll make a difference, tackling meaningful projects that sharpen your skills and fuel your growth.
We’re here to champion your journey. With powerful tools to chart your career path, personalized development goals aligned with your ambitions, and continuous feedback to keep you inspired and on track, you’ll have everything you need to thrive and evolve. You’ll develop in-demand skills to grow your career and achieve your ambitions with access to cutting-edge learning opportunities—from certifications with Microsoft, Google, and Amazon to coaching and hands-on experiences. And through it all, you’ll be part of a culture that values empathy, restless learning, and a devotion to shared success.
We want you to thrive here—and we’re committed to helping you do just that. Ready to make an impact? Join us and help shape what’s next.
Get Referred!
If you know someone that works at Kyndryl, when asked ‘How Did You Hear About Us’ during the application process, select ‘Employee Referral’ and enter your contact's Kyndryl email address.
Skills Required
- At least 5 years of relevant cybersecurity industry experience in threat hunting, detection engineering, digital forensics, incident response, or penetration testing
- Enterprise log analytics experience using platforms such as Microsoft Sentinel, QRadar, Elastic, Splunk, Palo Alto XSIAM, or similar
- Experience conducting hypothesis-driven threat hunts using large-scale telemetry and security logs
- Strong analytical, problem-solving, structured, and investigative skills
- Deep understanding of telemetry logs
- Deep technical understanding of attacker TTPs, intrusion lifecycles, and lateral movement behaviors
- Advanced query development using KQL, SPL, ES|QL, SQL, or equivalent analytics languages
- Experience with hypothesis-driven hunting and investigative research across complex, multidomain telemetry data
- Familiarity with MITRE ATT&CK, threat intelligence integration, malware analysis, network forensics, and EDR/XDR platforms
- Scripting or data analytics experience with Python, PowerShell, or equivalent
- Understanding of enterprise security controls, SIEM pipelines, and data correlation techniques
- Relevant certifications such as GCFA, GCFE, eCTHP, GCIH, GCED, GNFA, OSCP, OSEP, OSWE, CRTO, GXPN, GPEN, or GDAT
Kyndryl Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Kyndryl and has not been reviewed or approved by Kyndryl.
-
Fair & Transparent Compensation — Pay is considered good in some roles, with mentions of “good pay,” “great pay and benefits,” and an “acceptable salary range” paired with bonuses. Certain senior or consulting tracks are described as market-competitive.
-
Leave & Time Off Breadth — Vacation, paid time off, holidays, and a dedicated volunteer day are highlighted as positives. Parental leave exists companywide alongside sick leave and disability coverage.
-
Wellbeing & Lifestyle Benefits — Remote and hybrid flexibility is emphasized, including 100% remote roles and a formal flexible workplace policy. Well‑being resources such as the Be Well program and an EAP are available.
Kyndryl Insights
What We Do
We have the world’s best talent that design, run, and manage the most advanced and reliable technology infrastructure each day. Together, we think holistically about the health of these vital technology ecosystems. We are a focused, independent company that builds on our foundation of excellence by creating systems in new ways. Bringing in the right partners, investing in our business, and working side-by-side with our customers to unlock potential. We're raising the bar. Our experience speaks for itself: We have 90,000 highly skilled employees around the world serving 75 of the Fortune 100. But our purpose is what drives us: Advancing the vital systems that power human progress. Because when a digital ecosystem is healthy, it can more readily adapt and support continuous growth and that opens up a world of possibility for everyone.








