The Senior Threat Hunt Engineer is an advanced and highly trusted role supporting the enterprise cybersecurity program. As a member of Northwestern Mutual's Threat Hunting Program under the Threat Intelligence umbrella, the Senior Threat Hunt Engineer is primarily responsible for developing and maintaining the operational and technical foundation of the program including automation, tooling integration, detection handoff pipelines, and AI-assisted hunt workflows. Grounded in threat intelligence and hunt experience, the Senior Threat Hunt Engineer also executes proactive and signal-driven hunts across endpoint, network, cloud, and identity telemetry, translating findings into durable detections and institutional knowledge.
This role works closely with internal technical teams - including Threat Intelligence, Detection & Response, Detection Engineering, Adversarial Simulation, Purple Team, Incident Command, and Governance, Risk & Compliance - and with peer organizations, industry-sharing groups, and law enforcement affiliations where appropriate. The Senior Threat Hunt Engineer supports the hunt community across Cyber Defense, contributes engineering rigor to hunt artifacts, and ensures repeatable, version-controlled hunt processes as the program matures from manual to increasingly automated operations.
What You'll Do:
- Maintain and mature the operational hunt framework used across Cyber Defense. Build, document, and refine the templates, integrations, and standards hunters from multiple teams follow.
- Design, build, and maintain integrations and automation across the hunt lifecycle - spanning work-tracking, collaboration, ticketing, knowledge management, SIEM, EDR, threat intelligence platforms, and reporting.
- Execute hunts and support the hunt community across teams. Perform proactive and signal-driven hunts, respond to hunt questions from hunters across Cyber Defense, and partner with Threat Intelligence to translate hunt-informed analysis into actionable intelligence. Synthesize hunt outcomes into cross-hunt correlations, control gap identification, and inputs to future hunts and detections.
- Partner with detection engineering to translate hunt findings into production rules and analytics. Contribute detection candidates through the established handoff pipeline.
- Consume and apply threat intelligence to hunt activity. Track adversary and threat cluster TTPs relevant to Northwestern Mutual, prioritize what matters, and translate intel into hunt hypotheses.
- Mentor analysts and junior hunters. Pair on investigations, lead technical deep-dives, and grow the hunt capability across teams.
- Report on program outcomes. Communicate findings to internal stakeholders - what was found, what was contained, where detection coverage gaps exist, and what was changed as a result.
- Evaluate, integrate, and maintain security tooling used by the Threat Hunting Program, including threat intelligence platforms, enrichment services, and hunt-supporting analytical tools.
- Evaluate and integrate AI to accelerate hunt workflows, including hypothesis drafting, MITRE ATT&CK mapping suggestion, query generation, and summarization, with appropriate human review and tracking.
- Research current and emerging cyber threats facing the business and industry sector.
- Track threat actors, threat clusters, and associated malware families relevant to Northwestern Mutual and the financial services sector.
- Document threats into contextual reports outlining severity, urgency, and impact, and ensure they can be understood by both leadership and technical teams.
- Serve as a trusted advisor to maintain credibility with business unit leadership and technical teams.
- Actively inform and engage in security projects across the business to disrupt active or potential threats.
- Participate in collaborative threat analysis discussions with internal and external trusted entities.
- Perform other duties as assigned.
What You'll Bring to the Role:
- A minimum of 5-10 years in threat intelligence, threat hunting, incident response, or detection engineering, with meaningful experience across both threat intelligence and threat hunting disciplines.
- Bachelor's degree in computer science, cybersecurity, engineering, or a related field (or equivalent experience).
- Relevant certifications such as GCTI, GCIH, GCFA, GCIA, GCDA, OSCP, CEH, or CISSP are a plus. Cloud-focused security certifications (e.g., AWS Security Specialty, GCP Professional Cloud Security Engineer) are also valued.
- Deep hands-on experience running proactive and signal-driven hunts across SIEM, EDR, network, cloud, and identity telemetry in enterprise environments.
- Strong scripting and automation skills; Python required, with additional experience in PowerShell, Bash, or equivalent a plus.
- Deep hands-on experience with enterprise SIEM search languages, including advanced query development, dashboard building, saved searches, alerting, and query optimization at enterprise scale.
- Hands-on experience developing and consuming REST APIs across security tooling - including work-tracking, collaboration, ticketing, SIEM, EDR, and threat intelligence platforms.
- Demonstrated experience building event-driven automation using webhooks or similar integration patterns.
- Experience building, integrating, and maintaining security tooling and workflows at enterprise scale.
- Working knowledge of version control workflows, branching strategies, and code review practices.
- Ability to write clear technical documentation for automation and integrations, including runbooks for maintenance and troubleshooting.
- Ability to communicate complex findings clearly to both technical and leadership audiences.
- Advanced analytical reasoning skills.
- Applicable knowledge of adversary tactics, techniques, and procedures (TTPs), the MITRE ATT&CK framework, the unified kill chain, and open-source intelligence (OSINT).
- Hands-on experience with SIEM, intrusion detection/prevention systems, threat intelligence platforms, and security orchestration and automation platforms.
- Ability to analyze host, network, cloud, and identity telemetry; strong understanding of operating system internals; working knowledge of malware behavior, vulnerabilities, and exploitation techniques.
- Experience with incident collaboration, adversary tooling, and threat-informed defense methodology.
- Capable of working with diverse teams across Cyber Defense; comfortable operating in a cross-team enablement role rather than a single-team hunt queue.
- Demonstrated understanding of network, host, cloud, and identity cybersecurity solutions.
- Ability to maintain a high level of integrity, trustworthiness, and confidence, with the highest level of professionalism.
- Strong project management, multitasking, and organizational skills with minimum guidance.
- Ability to preserve credibility with the team and external constituents through sustained industry knowledge.
- Self-starter requiring minimal supervision.
What Sets you apart
- Threat Awareness-Uses knowledge of common and emerging security threats to identify potential risks and understand the protections needed against them.
- Detection Engineering-Observes and correlates activity across platforms and systems to identify risks, threats, and suspicious behavior, using intelligence from multiple security sources to generate alerts.
- Triage-Investigates technical problems through a systematic, hypothesis-driven approach to understand the context, determine the cause, and identify an appropriate solution.
- Scripting & Integration-Applies scripting knowledge to automate tasks and integrate systems that support areas such as records maintenance, inventory management, process analytics, and administration.
- Security Logging & Monitoring-Records and collects events across organizational systems and networks using appropriate collection strategies and established priorities.
- Attack Method Countermeasures-Creates controls that reduce threats and respond to automated or manual attacks by preventing, eliminating, or minimizing potential damage.
- Cross Functional Partnering & Planning-Facilitates collaboration, communication, coordination, and planning among teams with different areas of expertise to achieve shared goals.
#LI-Remote
Compensation Range:
Pay Range - Start:
$118,960.00
Pay Range - End:
$178,440.00
Geographic Specific Pay Structure:
Structure 110:
Structure 115:
We believe in fairness and transparency. It's why we share the salary range for most of our roles. However, final salaries are based on a number of factors, including the skills and experience of the candidate; the current market; location of the candidate; and other factors uncovered in the hiring process. The standard pay structure is listed but if you're living in California, New York City or other eligible location, geographic specific pay structures, compensation and benefits could be applicable, click here to learn more.
Job Posting End Date:
The timeline for this job posting may be shortened or extended based on organizational needs.
Grow your career with a best-in-class company that puts our clients' interests at the center of all we do. Get started now!
Northwestern Mutual is an equal opportunity employer that welcomes talented individuals of all backgrounds. We are committed to creating and maintaining an environment in which each employee can contribute creative ideas, seek challenges, assume leadership and continue to focus on meeting and exceeding business and personal objectives.
Skills
Automation, Python Automation, Engineering Expertise & Practices (NM) - Intermediate, Cyber Threat Intelligence, Cyber Threat Hunting, Coaching & Mentoring (NM) - Beginner, Collaborative Partnerships
FIND YOUR FUTURE
We're excited about the potential people bring to Northwestern Mutual. You can grow your career here while enjoying first-class perks, benefits, and our commitment to a culture of belonging.
- Flexible work schedules
- Concierge service
- Comprehensive benefits
- Employee resource groups
Skills Required
- 5-10 years in threat intelligence, threat hunting, incident response, or detection engineering
- Bachelor's degree in computer science, cybersecurity, engineering, or related field (or equivalent experience)
- Relevant certifications such as GCTI, GCIH, GCFA, GCIA, GCDA, OSCP, CEH, or CISSP
- Deep hands-on experience running proactive and signal-driven hunts across SIEM, EDR, network, cloud, and identity telemetry
- Python scripting and automation (Python required)
- Experience with PowerShell, Bash, or equivalent scripting
- Advanced enterprise SIEM search language skills, query development, dashboard building, alerting, and query optimization
- Hands-on experience developing and consuming REST APIs across security tooling
- Experience building event-driven automation using webhooks or similar integration patterns
- Hands-on experience with intrusion detection/prevention systems, threat intelligence platforms, and security orchestration and automation platforms (SOAR)
- Working knowledge of version control workflows, branching strategies, and code review practices
- Ability to write clear technical documentation and runbooks for automation and integrations
- Ability to analyze host, network, cloud, and identity telemetry; knowledge of OS internals, malware behavior, vulnerabilities, and exploitation techniques
- Experience translating hunt findings into production detections and working with detection engineering
- Strong communication skills to convey complex findings to technical and leadership audiences
Northwestern Mutual Compensation & Benefits Highlights
-
Retirement Support — Retirement programs feature both a 401(k) and a company‑funded cash balance plan, with materials noting age+service‑based credits and periods when additional employer funding is directed to the pension‑style plan. Vesting timelines are specified for each plan, signaling a long‑term, security‑oriented design.
-
Healthcare Strength — Health coverage spans medical, dental, and vision with Lyra mental‑health support, on‑site Mutual Health Centers in select locations, virtual care options, and fitness reimbursement or on‑site gyms. This breadth positions core health benefits as comprehensive for eligible corporate employees.
-
Parental & Family Support — Programs include paid parental leave, caregiving leave, and family‑building supports such as fertility, adoption, and surrogacy assistance. These offerings extend beyond baseline benefits to cover key life stages for families.
Northwestern Mutual Insights
What We Do
You’ll Like It Here At Northwestern Mutual, we believe that our lives and our work matter. And that doing what’s right is good for everyone. We follow through by designing tech that improves the community and cultivating creative ways to make finance accessible anywhere. These guiding principles have allowed our company to grow for more than 160 years. Here, you’ll be with a team who emphasizes integrity and prioritizes security to design experiences that better everyone. You’ll work in cross functional teams to create optimal solutions that are rooted in innovative strategy and thoughtful execution. And you’re provided development tools and opportunities to become a leader all with the support of a collaborative team. You’ll be surrounded in a culture that values innovation and works to always evolve to stay ahead of trends and client needs. We are intentional in seeking out team members who will challenge us. Our employees choose us for the career opportunities, commitment to philanthropy and desire to have a meaningful impact in the lives of our clients. You have career passions and goals. We have ambition and opportunity for you to grow your future in tech. Discover today: https://careers.northwesternmutual.com/
Why Work With Us
We invest in our people. We know careers are about choices, so we provide intentional opportunity. Here you can build creative ways to make finance accessible anywhere and revolutionize traditional processes. As a mutual company, our focus is our people — whether professional development or investments in the community.
Gallery
Northwestern Mutual Teams
Northwestern Mutual Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
We offer a flexible, hybrid approach for our employees . Teams are in the office a few days a week and work from home the others.










