College Board
Engineer III, Cyber Threat Hunter
Remote - USA · Mid · Full-time
No sponsorship$128k-$139kDetected 30 days ago
PythonBashPowerShellAWSCloud PlatformsKubernetesCI/CDCybersecuritySIEMSOC OperationsDetection EngineeringIncident ResponseLeadershipCommunicationCollaborationProblem SolvingMentoring
About the role
- The Cyber Security Operations team is critical to the strategic foundation of our products, most notably the secure delivery of our Digital SAT and AP programs.
- We are a highly motivated group of cyber security experts who take a proactive approach to ensuring a strong security posture.
- College Board is committed to creating an inclusive environment where all team members feel valued, respected, and supported in their work.
Responsibilities
- Build, tune, and maintain SIEM detections focused on high-risk behaviors such as IAM misuse, persistence, privilege escalation, and data access or exfiltration.
- Support investigation and containment of security incidents, performing log analysis, scoping impact, and documenting findings.
- Participate in periodic tabletop or fire drill exercises to validate readiness and improve response coordination.
- Participate in purple team exercises to validate detection effectiveness and help prioritize remediation of identified gaps.
- Partner with offensive testing and engineering teams to translate findings into improved detections and hardened configurations.
- Develop lightweight automation and scripts to improve investigation speed, enrichment, and reporting consistency.
- Maintain well-documented detection logic, hunt results, and response procedures to improve repeatability and team scalability.
- At College Board, we offer more than just a paycheck-we provide a meaningful career, a supportive team, and a comprehensive package designed to help you thrive.
Nice to have
- 3 to 5 years of progressive experience in cyber defense, including threat hunting, detection engineering, and incident response in enterprise environments.
- Experience with Sumo Logic is strongly preferred.
- Experience supporting high-severity incident response, including triage, scoping, containment guidance, and deeper analysis, with comfort serving as an escalation point for complex investigations.
- Experience planning or participating in purple team and detection validation activities to evaluate control effectiveness and improve alerting and response outcomes.
- Strong automation and scripting skills (for example Python, PowerShell, Bash) to streamline investigations, enrich alerts, and improve repeatability across hunting and response workflows.
- Excellent written and verbal communication skills, including producing after-action reports, threat briefings, and clear, actionable remediation guidance for technical and non-technical stakeholders.
- A collaborative mindset with experience partnering across engineering, architecture, and development teams, and mentoring junior analysts or engineers to raise team capability.
- Relevant certifications (for example GCIA, GCIH, GNFA, AWS Security Specialty, Security+).
Skills
- Contribute to the development and refinement of incident response playbooks for common cloud and identity-based scenarios.
- Identify opportunities to strengthen logging, telemetry coverage, and control effectiveness across cloud and enterprise systems.
Compensation
- We're a self-sustaining nonprofit that believes in fair and competitive compensation, grounded in your qualifications, experience, impact, and the market.
Benefits
- You'll have open, transparent conversations about compensation, benefits, and what it's like to work at College Board throughout your hiring process.
- Reduce alert noise through structured tuning, baselining, and enrichment while preserving meaningful coverage.
Company info
- We partner across the organization to mature our Threat Management and Incident Response procedures and are constantly seeking and experimenting with new technologies.
- We are currently using a variety of cutting-edge tools that provide comprehensive cyber security operations for the College Board's critical infrastructure in support of the College Board's mission to connect students to college success and opportunity.
- We welcome individuals from diverse backgrounds and experiences to join our team and contribute to our ongoing success.
- About the Opportunity
- As a Cyber Threat Hunter, you will play a hands-on role in defending the cloud and enterprise environments that power the Digital SAT, AP, and other high-stakes programs.
- You will work in an AWS-heavy environment at national scale, where detection quality, investigation speed, and clear documentation directly support exam integrity and student trust.
- This role exists to strengthen our detection and response capabilities.
- You will build and improve SIEM detections, execute structured threat hunts, and help validate controls through purple team exercises.
- You will contribute to incident investigations, refine response playbooks, and use automation to make our workflows faster and more reliable.
- You will partner closely with engineers, architects, and product teams to close visibility gaps and reduce risk in practical, measurable ways.
- Success in this role means fewer blind spots, higher fidelity alerts, and a cyber defense program that is proactive rather than reactive.
Visa & Work Authorization
- Candidates must be authorized to work in the United States for any employer and should possess clear and concise communication skills, both written and verbal.
Apply directly at College Board →Create a free account for alerts like thisView College Board immigration profile
This listing is sourced directly from College Board's careers page and normalized into a canonical job model.