Threat Hunting / Cyber Threat Hunting Analyst L2 (Langreo, ES)

Capgemini
Capgemini

IT

Langreo, Asturias, Spain

Posted on Jun 30, 2026

Choosing Capgemini means choosing a company where you will be empowered to shape your career in the way you’d like, where you’ll be supported and inspired by a collaborative community of colleagues around the world, and where you’ll be able to reimagine what’s possible. Join us and help the world’s leading organizations unlock the value of technology and build a more sustainable, more inclusive world.

Your rol

A dedicated and detail-oriented Threat Hunting Analyst with over 18 months of experience in cybersecurity operations, specializing in proactively looking for signs of attackers inside an organization’s environment—before alerts, incidents, or damage occur. Unlike traditional security roles that react to alarms, threat hunters assume compromise and actively search for hidden or stealthy threats.

A Threat Hunting Analyst must focus on searching for malicious behaviour that automated tools may miss, using human intuition, context, and hypotheses rather than waiting for alerts, in order to find advanced, persistent, and stealthy attackers.

Key responsibilities:

  • Proactively conduct threat hunts to identify malicious activity that bypassed automated detections, reducing attacker dwell time.
  • Develop hypothesis-driven hunts based on adversary tactics, techniques, and procedures (TTPs) using the MITRE ATT&CK framework.
  • Analyse endpoint, network, authentication, and log telemetry to detect indicators of compromise (IOCs) and anomalous behaviour.
  • Investigate suspicious activity involving credential misuse, lateral movement, persistence mechanisms, and living-off-the-land techniques.
  • Correlate data across SIEM, EDR/XDR, and network security tools to validate potential threats and scope impact.
  • Leverage threat intelligence reports and internal telemetry to identify emerging attacker behaviours relevant to the environment.
  • Escalate confirmed malicious activity to incident response teams with detailed findings, timelines, and supporting evidence.
  • Support incident investigations by providing root cause analysis and attacker activity reconstruction.

Your Profile:

  • SIEM / EDR query usage
  • Windows, Linux, and macOS internals
  • Networking fundamentals
  • Malware behaviour basics
  • Scripting and automation
  • Log analysis and query writing Analytical Skills
  • Pattern recognition
  • Hypothesis-driven investigation

Our Equality Plan and Code of Ethics ensure inclusive, non-discriminatory processes that foster talent in a multicultural environment accessible to people with disabilities (we positively value having a disability certificate).

Capgemini is a global business and technology transformation partner, helping organizations to accelerate their dual transition to a digital and sustainable world, while creating tangible impact for enterprises and society. It is a responsible and diverse group of 340,000 team members in more than 50 countries. With its strong over 55-year heritage, Capgemini is trusted by its clients to unlock the value of technology to address the entire breadth of their business needs. It delivers end-to-end services and solutions leveraging strengths from strategy and design to engineering, all fueled by its market leading capabilities in AI, generative AI, cloud and data, combined with its deep industry expertise and partner ecosystem.