Threat Hunting Engineer Lead

Posted 10 Hours Ago
Be an Early Applicant
Carrollton, TX, USA
In-Office
Senior level
Healthtech • Logistics • Pharmaceutical
We are united in our responsibility to create healthier futures
The Role
Leads proactive threat hunting within a Security Operations Center, investigating adversarial activity and improving detection, response, monitoring, and security controls. Responsibilities include researching emerging threats, developing SIEM, EDR, and SOAR detection methodologies, performing security gap assessments, correlating security data, supporting incident response and recovery, enhancing alerting, and briefing stakeholders on critical risks.
Summary Generated by Built In
Our team members are at the heart of everything we do. At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential to us being able to deliver on that purpose. If you want to make a difference at the center of health, come join our innovative company and help us improve the lives of people and animals everywhere. Apply today!
Job Details
The Threat Hunting Engineer Lead is a technical leader in the Cencora Security Operations Center who applies their knowledge of adversarial tactics and techniques and their experience with security controls, infrastructure, and networking to proactively investigate potential cyber threats. They will use their findings to improve detection, response, and security controls.
RESPONSIBILITIES:
  • Conduct threat hunting to identify, classify, prioritize, and report on cyber threats following industry best practices.
  • Conduct research on emerging security threats; Provide correlation and trending of cyber incident activity.
  • Craft methodologies for monitoring , detection, and analytics for SIEM, EDR, SOAR, and other platforms.
  • Provide security gap analysis and effectiveness assessments of security platform technologies.
  • Formulates methodologies to monitor for as well as respond to security related events.
  • Identification of and correlation with other data sources to enhance security event detection, monitoring and response capabilities.
  • Collaborates across multiple teams on the response to information security incidents, investigation, countermeasures, and recovery.
  • Analysis of security incidents for further enhancement of alerting schema.
  • Provides security briefings to advise on critical issues that may affect the enterprise.

EDUCATION & QUALIFICATIONS:
  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or equivalent work experience
  • 7+ years of progressive experience in cybersecurity, with at least 4 years dedicated to incident response, forensics, threat hunting, threat detection, or related role.
  • Expertise with common threat detection and logging platforms for SIEM, EDR, SOAR, etc.
  • Strong understanding of network protocols, operating system internals (Windows, Linux, MacOS), cloud security, and defensive security technologies.
  • Familiarity with intelligence frameworks such as MITRE ATT&CK.
  • Hands-on experience with at least one scripting or programming language for tooling and automation (e.g., Python, Go, Powershell).
  • Strong written and verbal communication skills, with the ability to articulate complex technical findings to a non-technical audience.

PREFERRED CERTIFICATIONS:
  • GIAC GCFA - Certified Forensic Analyst
  • GIAC GCFR - Cloud Forensics Responder
  • GIAC GNFA - Network Forensic Analyst
  • GIAC GCIA - Certified Intrusion Analyst
  • GIAC GCDA - Certified Detection Analyst
  • GIAC GDAT - Defending Advanced Threats

Bachelor's degree in cyber security, computer science, information technology, information systems, or a related field, or equivalent experience required. Master's degree in cyber security, computer science, information technology, information systems, or a related field, or equivalent experience preferred. 6+ years of experience in cyber threat intelligence, cyber security, security operations, incident response, threat analysis, or a related field required. Certified in Cybersecurity (CC) or equivalent certification preferred. Certified Threat Intelligence Analyst (CTIA) or equivalent certification preferred. Certified Ethical Hacker (CEH) or equivalent certification preferred.
What Cencora offers
We provide compensation, benefits, and resources that enable a highly inclusive culture and support our team members' ability to live with purpose every day. In addition to traditional offerings like medical, dental, and vision care, we also provide a comprehensive suite of benefits that focus on the physical, emotional, financial, and social aspects of wellness. This encompasses support for working families, which may include backup dependent care, adoption assistance, infertility coverage, family building support, behavioral health solutions, paid parental leave, and paid caregiver leave. To encourage your personal growth, we also offer a variety of training programs, professional development resources, and opportunities to participate in mentorship programs, employee resource groups, volunteer activities, and much more. For details, visit https://www.virtualfairhub.com/cencora
Full time
Equal Employment Opportunity
Cencora is committed to providing equal employment opportunity without regard to race, color, religion, sex, sexual orientation, gender identity, genetic information, national origin, age, disability, veteran status or membership in any other class protected by federal, state or local law.
The company's continued success depends on the full and effective utilization of qualified individuals. Therefore, harassment is prohibited and all matters related to recruiting, training, compensation, benefits, promotions and transfers comply with equal opportunity principles and are non-discriminatory.
Cencora is committed to providing reasonable accommodations to individuals with disabilities during the employment process which are consistent with legal requirements. If you wish to request an accommodation while seeking employment, please call 888.692.2272 or email [email protected]. We will make accommodation determinations on a request-by-request basis. Messages and emails regarding anything other than accommodations requests will not be returned
Affiliated Companies
Affiliated Companies: AmerisourceBergen Services Corporation

Skills Required

  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Information Technology, or a related field, or equivalent experience
  • 7+ years of progressive cybersecurity experience
  • At least 4 years of experience in incident response, forensics, threat hunting, threat detection, or a related role
  • Expertise with SIEM, EDR, SOAR, and other threat detection and logging platforms
  • Strong understanding of network protocols, Windows, Linux, MacOS, cloud security, and defensive security technologies
  • Familiarity with intelligence frameworks such as MITRE ATT&CK
  • Hands-on experience with at least one scripting or programming language, such as Python, Go, or PowerShell
  • Strong written and verbal communication skills, including the ability to explain complex technical findings to non-technical audiences
  • Master's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related field, or equivalent experience
  • 6+ years of experience in cyber threat intelligence, cybersecurity, security operations, incident response, threat analysis, or a related field
  • Certified in Cybersecurity (CC) or equivalent certification
  • Certified Threat Intelligence Analyst (CTIA) or equivalent certification
  • Certified Ethical Hacker (CEH) or equivalent certification
  • GIAC GCFA, GCFR, GNFA, GCIA, GCDA, or GDAT certification

What the Team is Saying

Jason
Silvana
Paul Fritzsch
Denesha Thompson
Cindy Aviles
Denesha Thompson
Tina Martinez

Cencora Compensation & Benefits Highlights

  • Healthcare Strength Healthcare coverage is often described as comprehensive, with medical, dental, vision, mental health resources, and day‑one eligibility emphasized. Wellbeing initiatives and EAP resources further reinforce the strength of the core package.
  • Retirement Support Retirement offerings are seen as solid, featuring a 401(k) plan with company matching alongside HSAs/FSAs and an employee stock purchase program. The 401(k) match and tuition support are frequently cited as meaningful parts of total compensation.
  • Parental & Family Support Family-building and leave supports are highlighted, including paid parental and caregiver leave plus fertility, adoption, and surrogacy assistance. Backup child care and related resources add depth to the family support experience.

Cencora Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Conshohocken, PA
51,000 Employees
Year Founded: 2023

What We Do

Cencora is a leading pharmaceutical solutions organization centered on improving the lives of people and animals everywhere. With 46,000+ global team members, we have the opportunity to make a positive impact on healthcare in communities everywhere. Our team members are empowered to activate their careers through a collective of tools and resources designed to support individual career interests and aspirations. We value our listening culture that actions real outcomes and our team members appreciate and recognize one another for contributions that are making a meaningful global impact. No matter what your role is here, the work we do together has meaning. When you join our team, you become a crucial part of a greater purpose. We’re committed to supporting you personally and professionally, so we can achieve more together at the center of health. Protect yourself from job scams: Recruitment scams are on the rise. To protect yourself, we urge you to be vigilant and follow these guidelines > https://careers.cencora.com/us/en/job-scams

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

Cencora Teams

Team
Early Careers
Team
Information Technology
About our Teams

Cencora Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Typical time on-site: Flexible
Company Office Image
HQConshohocken, PA
Bolsover, GB
București, RO
Carrollton, TX
Chessington, GB
Dříteň, CZ
Feltham, GB
Gennevilliers, FR
Marseille, FR
Oakville, ON
Company Office Image
Pune, Maharashtra
Villanueva de Gállego, Zaragoza
Vilniaus miesto, LT
Woking, GB
Zaragoza, Zaragoza
Learn more

Similar Jobs

Cencora Logo Cencora

Engineer III, Red Team

Healthtech • Logistics • Pharmaceutical
In-Office
Carrollton, TX, USA
51000 Employees

Cencora Logo Cencora

CIAM Engineer II, IAM Platform Engineering

Healthtech • Logistics • Pharmaceutical
In-Office
Carrollton, TX, USA
51000 Employees

Cencora Logo Cencora

Information Security Intern

Healthtech • Logistics • Pharmaceutical
In-Office
Carrollton, TX, USA
51000 Employees

Cencora Logo Cencora

Engineer III, Vulnerability Management

Healthtech • Logistics • Pharmaceutical
In-Office
Carrollton, TX, USA
51000 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account