Kohler Co. is seeking a SOC Analyst / Threat Hunter to strengthen detection investigation and response capability across the enterprise. This is a hands-on operationally focused role. You will go beyond alert triage to investigate real threats perform proactive hunting and directly improve how the SOC detects and responds. You will work closely with cybersecurity architecture engineering and platform teams with real influence on visibility detection quality and operational outcomes. The role is well-suited to someone who is technically curious thinks like an attacker and wants meaningful work rather than ticket throughput. You will investigate threats that include automation and AI-assisted attack techniques and will work with analytics and AI-supported capabilities within security tooling part of a deliberate move toward a more intelligent agentic security operations model. This role operates within standard business hours with an on-call rotation.
Key Responsibilities
Detection & Incident Response Monitor triage and investigate security alerts across endpoint identity network cloud and SaaS environmentsmoving quickly from initial signal to understanding scope and impact. Lead and support incident investigations by developing clear timelines identifying affected assets and driving toward containment. Execute and oversee containment and response actions (including via automated and agentic workflows) in line with established playbooks using sound judgment when situations fall outside defined procedures. Produce clear concise documentation of investigations and incidents to support post-incident review and continuous improvement.
Threat Hunting Perform proactive hypothesis-driven threat hunting based on attacker techniques observed behavior and current threat intelligence. Develop and test hunt hypotheses mapped to MITRE ATT&CK (or equivalent frameworks) translating them into structured queries and analysis. Identify weak signals and suspicious patterns that fall below existing detection thresholds. Feed hunt findings back into detection engineeringimproving rule quality and closing visibility gaps over time.
Detection & Signal Improvement Assist with tuning and improving SIEM and EDR detections. Reduce false positives while strengthening high-confidence alerts. Work with architecture and engineering teams to improve telemetry and visibility.
Attacker & TTP Awareness Actively follow the evolving threat landscape including emerging attacker tooling techniques and campaigns and bring relevant intelligence into day-to-day detection and hunting activity Map detections and hunts to real-world attack behavior. Proactively identify and prioritize detection gaps based on current threat actor behavior.
Operational Maturity Contribute to the development and refinement of SOC procedures and playbooks. Contribute to automation and orchestration efforts to improve response speed and consistency. Provide operational feedback to improve security architecture and tooling decisions.
Kohler Co. is seeking a SOC Analyst / Threat Hunter to strengthen detection investigation and response capability across the enterprise. This is a hands-on operationally focused role. You will go beyond alert triage to investigate real threats perform proactive hunting and directly improve how the SOC detects and responds. You will work closely with cybersecurity architecture engineering and platform teams with real influence on visibility detection quality and operational outcomes. The role is well-suited to someone who is technically curious thinks like an attacker and wants meaningful work rather than ticket throughput. You will investigate threats that include automation and AI-assisted attack techniques and will work with analytics and AI-supported capabilities within security tooling part of a deliberate move toward a more intelligent agentic security operations model. This role operates within standard business hours with an on-call rotation.
Key Responsibilities Detection & Incident Response Monitor triage and investigate security alerts across endpoint identity network cloud and SaaS environmentsmoving quickly from initial signal to understanding scope and impact. Lead and support incident investigations by developing clear timelines identifying affected assets and driving toward containment. Execute and oversee containment and response actions (including via automated and agentic workflows) in line with established playbooks using sound judgment when situations fall outside defined procedures. Produce clear concise documentation of investigations and incidents to support post-incident review and continuous improvement.
Threat Hunting Perform proactive hypothesis-driven threat hunting based on attacker techniques observed behavior and current threat intelligence. Develop and test hunt hypotheses mapped to MITRE ATT&CK (or equivalent frameworks) translating them into structured queries and analysis. Identify weak signals and suspicious patterns that fall below existing detection thresholds. Feed hunt findings back into detection engineeringimproving rule quality and closing visibility gaps over time.
Detection & Signal Improvement Assist with tuning and improving SIEM and EDR detections. Reduce false positives while strengthening high-confidence alerts. Work with architecture and engineering teams to improve telemetry and visibility.
Attacker & TTP Awareness Actively follow the evolving threat landscape including emerging attacker tooling techniques and campaigns and bring relevant intelligence into day-to-day detection and hunting activity Map detections and hunts to real-world attack behavior. Proactively identify and prioritize detection gaps based on current threat actor behavior.
Operational Maturity Contribute to the development and refinement of SOC procedures and playbooks. Contribute to automation and orchestration efforts to improve response speed and consistency. Provide operational feedback to improve security architecture and tooling decisions.
Experience & Skills 2 years of experience in a SOC or threat-focused security role with demonstrable exposure to proactive threat hunting and a clear drive to develop further in that discipline. Hands-on experience with: SIEM platforms and log analysis. Endpoint detection and response (EDR) tools(Palo Rapid Microsoft). Identity-based attacks and lateral movement techniques. Cloud and SaaS security signals. Strong analytical and investigative mindset. Able to work effectively in fast-moving and evolving environments. Hands-on experience working with AI-assisted security tooling with a drive to build and mature agentic workflows that automate detection investigation and response activity at scale. Query and scripting languages relevant to security analysis (KQL SPL or Python).
Education & Certifications (Preferred) Bachelors degree in Information Security Computer Science or equivalent experience. Security certifications (GIAC/SANS GCIA GNFA OSCP or similar) are beneficial but not required.
Why Choose Kohler We empower each associate to #BecomeMoreAtKohler with a competitive total rewards package to support your health and wellbeing access to career growth and development opportunities a diverse and inclusive workplace and a strong culture of innovation. With more than 30000 bold leaders across the globe were driving meaningful change in our mission to help people live gracious healthy and sustainable lives.
About Us It is Kohlers policy to recruit hire and promote qualified applicants without regard to race creed religion age sex sexual orientation gender identity or expression marital status national origin disability or status as a protected veteran. If as an individual with a disability you need reasonable accommodation during the recruitment process please contact . Kohler Co. is an equal opportunity/affirmative action employer.
Required Experience:
IC
Cybersecurity Analyst - Threat HunterWork Mode: Hybrid Juarez Nuevo LeónLocation: Hybrid Juarez Nuevo LeónOpportunityKohler Co. is seeking a SOC Analyst / Threat Hunter to strengthen detection investigation and response capability across the enterprise.This is a hands-on operationally focused role. ...
Cybersecurity Analyst - Threat Hunter
Work Mode: Hybrid Juarez Nuevo León
Location: Hybrid Juarez Nuevo León
Opportunity
Kohler Co. is seeking a SOC Analyst / Threat Hunter to strengthen detection investigation and response capability across the enterprise. This is a hands-on operationally focused role. You will go beyond alert triage to investigate real threats perform proactive hunting and directly improve how the SOC detects and responds. You will work closely with cybersecurity architecture engineering and platform teams with real influence on visibility detection quality and operational outcomes. The role is well-suited to someone who is technically curious thinks like an attacker and wants meaningful work rather than ticket throughput. You will investigate threats that include automation and AI-assisted attack techniques and will work with analytics and AI-supported capabilities within security tooling part of a deliberate move toward a more intelligent agentic security operations model. This role operates within standard business hours with an on-call rotation.
Key Responsibilities
Detection & Incident Response Monitor triage and investigate security alerts across endpoint identity network cloud and SaaS environmentsmoving quickly from initial signal to understanding scope and impact. Lead and support incident investigations by developing clear timelines identifying affected assets and driving toward containment. Execute and oversee containment and response actions (including via automated and agentic workflows) in line with established playbooks using sound judgment when situations fall outside defined procedures. Produce clear concise documentation of investigations and incidents to support post-incident review and continuous improvement.
Threat Hunting Perform proactive hypothesis-driven threat hunting based on attacker techniques observed behavior and current threat intelligence. Develop and test hunt hypotheses mapped to MITRE ATT&CK (or equivalent frameworks) translating them into structured queries and analysis. Identify weak signals and suspicious patterns that fall below existing detection thresholds. Feed hunt findings back into detection engineeringimproving rule quality and closing visibility gaps over time.
Detection & Signal Improvement Assist with tuning and improving SIEM and EDR detections. Reduce false positives while strengthening high-confidence alerts. Work with architecture and engineering teams to improve telemetry and visibility.
Attacker & TTP Awareness Actively follow the evolving threat landscape including emerging attacker tooling techniques and campaigns and bring relevant intelligence into day-to-day detection and hunting activity Map detections and hunts to real-world attack behavior. Proactively identify and prioritize detection gaps based on current threat actor behavior.
Operational Maturity Contribute to the development and refinement of SOC procedures and playbooks. Contribute to automation and orchestration efforts to improve response speed and consistency. Provide operational feedback to improve security architecture and tooling decisions.
Kohler Co. is seeking a SOC Analyst / Threat Hunter to strengthen detection investigation and response capability across the enterprise. This is a hands-on operationally focused role. You will go beyond alert triage to investigate real threats perform proactive hunting and directly improve how the SOC detects and responds. You will work closely with cybersecurity architecture engineering and platform teams with real influence on visibility detection quality and operational outcomes. The role is well-suited to someone who is technically curious thinks like an attacker and wants meaningful work rather than ticket throughput. You will investigate threats that include automation and AI-assisted attack techniques and will work with analytics and AI-supported capabilities within security tooling part of a deliberate move toward a more intelligent agentic security operations model. This role operates within standard business hours with an on-call rotation.
Key Responsibilities Detection & Incident Response Monitor triage and investigate security alerts across endpoint identity network cloud and SaaS environmentsmoving quickly from initial signal to understanding scope and impact. Lead and support incident investigations by developing clear timelines identifying affected assets and driving toward containment. Execute and oversee containment and response actions (including via automated and agentic workflows) in line with established playbooks using sound judgment when situations fall outside defined procedures. Produce clear concise documentation of investigations and incidents to support post-incident review and continuous improvement.
Threat Hunting Perform proactive hypothesis-driven threat hunting based on attacker techniques observed behavior and current threat intelligence. Develop and test hunt hypotheses mapped to MITRE ATT&CK (or equivalent frameworks) translating them into structured queries and analysis. Identify weak signals and suspicious patterns that fall below existing detection thresholds. Feed hunt findings back into detection engineeringimproving rule quality and closing visibility gaps over time.
Detection & Signal Improvement Assist with tuning and improving SIEM and EDR detections. Reduce false positives while strengthening high-confidence alerts. Work with architecture and engineering teams to improve telemetry and visibility.
Attacker & TTP Awareness Actively follow the evolving threat landscape including emerging attacker tooling techniques and campaigns and bring relevant intelligence into day-to-day detection and hunting activity Map detections and hunts to real-world attack behavior. Proactively identify and prioritize detection gaps based on current threat actor behavior.
Operational Maturity Contribute to the development and refinement of SOC procedures and playbooks. Contribute to automation and orchestration efforts to improve response speed and consistency. Provide operational feedback to improve security architecture and tooling decisions.
Experience & Skills 2 years of experience in a SOC or threat-focused security role with demonstrable exposure to proactive threat hunting and a clear drive to develop further in that discipline. Hands-on experience with: SIEM platforms and log analysis. Endpoint detection and response (EDR) tools(Palo Rapid Microsoft). Identity-based attacks and lateral movement techniques. Cloud and SaaS security signals. Strong analytical and investigative mindset. Able to work effectively in fast-moving and evolving environments. Hands-on experience working with AI-assisted security tooling with a drive to build and mature agentic workflows that automate detection investigation and response activity at scale. Query and scripting languages relevant to security analysis (KQL SPL or Python).
Education & Certifications (Preferred) Bachelors degree in Information Security Computer Science or equivalent experience. Security certifications (GIAC/SANS GCIA GNFA OSCP or similar) are beneficial but not required.
Why Choose Kohler We empower each associate to #BecomeMoreAtKohler with a competitive total rewards package to support your health and wellbeing access to career growth and development opportunities a diverse and inclusive workplace and a strong culture of innovation. With more than 30000 bold leaders across the globe were driving meaningful change in our mission to help people live gracious healthy and sustainable lives.
About Us It is Kohlers policy to recruit hire and promote qualified applicants without regard to race creed religion age sex sexual orientation gender identity or expression marital status national origin disability or status as a protected veteran. If as an individual with a disability you need reasonable accommodation during the recruitment process please contact . Kohler Co. is an equal opportunity/affirmative action employer.