College Board

College Board

Engineer III, Cyber Threat Hunter

Remote - USA · Mid · Full-time

No sponsorship$128k-$139kDetected 30 days ago
PythonBashPowerShellAWSCloud PlatformsKubernetesCI/CDCybersecuritySIEMSOC OperationsDetection EngineeringIncident ResponseLeadershipCommunicationCollaborationProblem SolvingMentoring

About the role

  • The Cyber Security Operations team is critical to the strategic foundation of our products, most notably the secure delivery of our Digital SAT and AP programs.
  • We are a highly motivated group of cyber security experts who take a proactive approach to ensuring a strong security posture.
  • College Board is committed to creating an inclusive environment where all team members feel valued, respected, and supported in their work.

Responsibilities

  • Build, tune, and maintain SIEM detections focused on high-risk behaviors such as IAM misuse, persistence, privilege escalation, and data access or exfiltration.
  • Support investigation and containment of security incidents, performing log analysis, scoping impact, and documenting findings.
  • Participate in periodic tabletop or fire drill exercises to validate readiness and improve response coordination.
  • Participate in purple team exercises to validate detection effectiveness and help prioritize remediation of identified gaps.
  • Partner with offensive testing and engineering teams to translate findings into improved detections and hardened configurations.
  • Develop lightweight automation and scripts to improve investigation speed, enrichment, and reporting consistency.
  • Maintain well-documented detection logic, hunt results, and response procedures to improve repeatability and team scalability.
  • At College Board, we offer more than just a paycheck-we provide a meaningful career, a supportive team, and a comprehensive package designed to help you thrive.

Nice to have

  • 3 to 5 years of progressive experience in cyber defense, including threat hunting, detection engineering, and incident response in enterprise environments.
  • Experience with Sumo Logic is strongly preferred.
  • Experience supporting high-severity incident response, including triage, scoping, containment guidance, and deeper analysis, with comfort serving as an escalation point for complex investigations.
  • Experience planning or participating in purple team and detection validation activities to evaluate control effectiveness and improve alerting and response outcomes.
  • Strong automation and scripting skills (for example Python, PowerShell, Bash) to streamline investigations, enrich alerts, and improve repeatability across hunting and response workflows.
  • Excellent written and verbal communication skills, including producing after-action reports, threat briefings, and clear, actionable remediation guidance for technical and non-technical stakeholders.
  • A collaborative mindset with experience partnering across engineering, architecture, and development teams, and mentoring junior analysts or engineers to raise team capability.
  • Relevant certifications (for example GCIA, GCIH, GNFA, AWS Security Specialty, Security+).

Skills

  • Contribute to the development and refinement of incident response playbooks for common cloud and identity-based scenarios.
  • Identify opportunities to strengthen logging, telemetry coverage, and control effectiveness across cloud and enterprise systems.

Compensation

  • We're a self-sustaining nonprofit that believes in fair and competitive compensation, grounded in your qualifications, experience, impact, and the market.

Benefits

  • You'll have open, transparent conversations about compensation, benefits, and what it's like to work at College Board throughout your hiring process.
  • Reduce alert noise through structured tuning, baselining, and enrichment while preserving meaningful coverage.

Company info

  • We partner across the organization to mature our Threat Management and Incident Response procedures and are constantly seeking and experimenting with new technologies.
  • We are currently using a variety of cutting-edge tools that provide comprehensive cyber security operations for the College Board's critical infrastructure in support of the College Board's mission to connect students to college success and opportunity.
  • We welcome individuals from diverse backgrounds and experiences to join our team and contribute to our ongoing success.
  • About the Opportunity
  • As a Cyber Threat Hunter, you will play a hands-on role in defending the cloud and enterprise environments that power the Digital SAT, AP, and other high-stakes programs.
  • You will work in an AWS-heavy environment at national scale, where detection quality, investigation speed, and clear documentation directly support exam integrity and student trust.
  • This role exists to strengthen our detection and response capabilities.
  • You will build and improve SIEM detections, execute structured threat hunts, and help validate controls through purple team exercises.
  • You will contribute to incident investigations, refine response playbooks, and use automation to make our workflows faster and more reliable.
  • You will partner closely with engineers, architects, and product teams to close visibility gaps and reduce risk in practical, measurable ways.
  • Success in this role means fewer blind spots, higher fidelity alerts, and a cyber defense program that is proactive rather than reactive.

Visa & Work Authorization

  • Candidates must be authorized to work in the United States for any employer and should possess clear and concise communication skills, both written and verbal.

This listing is sourced directly from College Board's careers page and normalized into a canonical job model.