{"id":1159374,"url":"https://alion.io/job/cencora-threat-hunting-engineer-lead","title":"Threat Hunting Engineer Lead","company":{"id":1040788,"name":"Cencora","domain":"cencora.com","url":"https://alion.io/company/cencora","size_band":"5000+","is_staffing_agency":false,"is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":null},"role":"Security","role_family":"Security","seniority":"lead","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Plano, United States","Conshohocken, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":99000,"max_usd":216000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":182},"experience_years_min":7,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Linux","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"PowerShell","optional":false},{"name":"Python","optional":false},{"name":"SIEM","optional":false},{"name":"Windows","optional":false}],"status":"live","first_seen_at":"2026-09-22T00:00:00Z","employer_posted_date":"2026-09-22","last_verified_at":"2026-09-24T14:56:19Z","board_verified":true,"closed_at":null,"days_open":2,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":2},"description":"Our team members are at the heart of everything we do. At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential to us being able to deliver on that purpose. If you want to make a difference at the center of health, come join our innovative company and help us improve the lives of people and animals everywhere. Apply today!\nJob Details\nThe Threat Hunting Engineer Lead is a technical leader in the Cencora Security Operations Center who applies their knowledge of adversarial tactics and techniques and their experience with security controls, infrastructure, and networking to proactively investigate potential cyber threats. They will use their findings to improve detection, response, and security controls.\nRESPONSIBILITIES:\nConduct threat hunting to identify, classify, prioritize, and report on cyber threats following industry best practices.\nConduct research on emerging security threats; Provide correlation and trending of cyber incident activity.\nCraft methodologies for monitoring , detection, and analytics for SIEM, EDR, SOAR, and other platforms.\nProvide security gap analysis and effectiveness assessments of security platform technologies.\nFormulates methodologies to monitor for as well as respond to security related events.\nIdentification of and correlation with other data sources to enhance security event detection, monitoring and response capabilities.\nCollaborates across multiple teams on the response to information security incidents, investigation, countermeasures, and recovery.\nAnalysis of security incidents for further enhancement of alerting schema.\nProvides security briefings to advise on critical issues that may affect the enterprise.\nEDUCATION & QUALIFICATIONS:\nBachelor’s degree in Cybersecurity, Computer Science, Information Systems, or equivalent work experience\n7+ years of progressive experience in cybersecurity, with at least 4 years dedicated to incident response, forensics, threat hunting, threat detection, or related role.\nExpertise with common threat detection and logging platforms for SIEM, EDR, SOAR, etc.\nStrong understanding of network protocols, operating system internals (Windows, Linux, MacOS), cloud security, and defensive security technologies.\nFamiliarity with intelligence frameworks such as MITRE ATT&CK.\nHands-on experience with at least one scripting or programming language for tooling and automation (e.g., Python, Go, Powershell).\nStrong written and verbal communication skills, with the ability to articulate complex technical findings to a non-technical audience.\nPREFERRED CERTIFICATIONS:\nGIAC GCFA - Certified Forensic Analyst\nGIAC GCFR - Cloud Forensics Responder\nGIAC GNFA - Network Forensic Analyst\nGIAC GCIA - Certified Intrusion Analyst\nGIAC GCDA - Certified Detection Analyst\nGIAC GDAT - Defending Advanced Threats\nBachelor’s degree in cyber security, computer science, information technology, information systems, or a related field, or equivalent experience required.Master’s degree in cyber security, computer science, information technology, information systems, or a related field, or equivalent experience preferred.\n6+ years of experience in cyber threat intelligence, cyber security, security operations, incident response, threat analysis, or a related field required.\nCertified in Cybersecurity (CC) or equivalent certification preferred.\nCertified Threat Intelligence Analyst (CTIA) or equivalent certification preferred.\nCertified Ethical Hacker (CEH) or equivalent certification preferred.\nWhat Cencora offers\nWe provide compensation, benefits, and resources that enable a highly inclusive culture and support our team members’ ability to live with purpose every day. In addition to traditional offerings like medical, dental, and vision care, we also provide a comprehensive suite of benefits that focus on the physical, emotional, financial, and social aspects of wellness. This encompasses support for working families, which may include backup dependent care, adoption assistance, infertility coverage, family building support, behavioral health solutions, paid parental leave, and paid caregiver leave. To encourage your personal growth, we also offer a variety of training programs, professional development resources, and opportunities to participate in mentorship programs, employee resource groups, volunteer activities, and much more. For details, visit https://www.virtualfairhub.com/cencora\nFull timeEqual Employment Opportunity\nCencora is committed to providing equal employment opportunity without regard to race, color, religion, sex, sexual orientation, gender identity, genetic information, national origin, age, disability, veteran status or membership in any other class protected by federal, state or local law.\nThe company’s continued success depends on the full and effective utilization of qualified individuals. Therefore, harassment is prohibited and all matters related to recruiting, training, compensation, benefits, promotions and transfers comply with equal opportunity principles and are non-discriminatory.\nCencora is committed to providing reasonable accommodations to individuals with disabilities during the employment process which are consistent with legal requirements. If you wish to request an accommodation while seeking employment, please call 888.692.2272 or email . We will make accommodation determinations on a request-by-request basis. Messages and emails regarding anything other than accommodations requests will not be returned\nAffiliated Companies\nAffiliated Companies: AmerisourceBergen Services Corporation","description_format":"text","description_chars":5627,"description_truncated":false,"requirements":{"experience_years_min":7,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":["Parental leave","Professional development"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Threat Intelligence","Incident Response","Cell & Gene Therapy","Information Security"],"lifecycle":[{"event":"open","at":"2026-09-23T22:58:28Z"}],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":2,"expected_fill_days":18,"reasons":["conf:2","win:early","comp:brand"],"computed_at":"2026-09-24T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/cencora-threat-hunting-engineer-lead","json_url":"https://alion.io/job/cencora-threat-hunting-engineer-lead.json","meta":{"generated_at":"2026-09-24T18:35:09Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers"}}