Huntress

Huntress

Huntress is a managed cybersecurity platform that protects small and mid-market businesses from cybercriminals. Their services include managed endpoint protection, detection and response, Microsoft 365 identity protection, and security awareness traini...

Professional Services
251-1K
Founded 2015
$160M raised

Description

  • Triage, investigate, respond to, and remediate alerts coming in from the Huntress platform.
  • Review EDR telemetry, log sources, and forensic artifacts to determine attack root cause and required remediations.
  • Perform tactical malware analysis during alert investigation and triage.
  • Investigate suspicious Microsoft M365 activity and provide remediation guidance.
  • Assist with escalations from the Product Support team on threat-related and SOC-relevant questions.
  • Contribute to detection engineering creation and tuning efforts.
  • Support projects aimed at improving outcomes for analysts and partners.
  • Collaborate within a mentored SOC team and contribute to cross-functional learning.

Requirements

  • 2+ years of experience in a SOC or Digital Forensics (DFIR) role.
  • Demonstrated experience with Windows, Linux, and MacOS as an attack surface.
  • Demonstrated experience with threat actor tools and techniques, including MITRE ATT&CK, PowerShell, Command Prompt, WMIC, Scheduled Tasks, SCM, enumeration, lateral movement, persistence, and defense evasion.
  • Demonstrated experience with static and dynamic malware analysis concepts.
  • Working knowledge of Windows Administration or Enterprise Domain Administration, including Active Directory, Group Policy, and Domain Trusts.
  • Working knowledge of core networking concepts, including common ports/protocols, NAT, public/private IPs, and VLANs.
  • Working knowledge of web technologies and concepts, including web servers/applications and OWASP Top 10.
  • Effective communication skills with the ability to explain complex events to less technical audiences.
  • A strong sense of curiosity and genuine excitement for learning.
  • Previous experience in an MSP/MSSP/MDR role is preferred.
  • Linux and MacOS investigative experience is preferred.
  • Experience with scripting languages such as PowerShell, Python, Bash, PHP, JavaScript, or Ruby is preferred.
  • Hands-on experience with platforms such as HackTheBox, TryHackMe, or Blue Team Labs Online is preferred.
  • Experience with cloud-based investigations such as M365, Azure, AWS, or GCP is preferred.
  • Participation in cybersecurity competitions such as CTFs or the Collegiate Cyber Defense Competition is preferred.
  • Familiarity with MSP tools such as RMMs is preferred.

Benefits

  • $100,000-$125,000 base salary plus bonus and equity.
  • May be eligible for on-call/call-in pay in addition to base pay.
  • 100% remote work environment.
  • Generous paid time off, including vacation, sick time, and paid holidays.
  • 12 weeks of paid parental leave.
  • Comprehensive medical, dental, and vision insurance.
  • 401(k) with a 5% company contribution regardless of employee contribution.
  • Life and disability insurance.
  • Stock options for all full-time employees.
  • One-time $500 home office reimbursement.
  • Annual education and professional development allowance.
  • $75 USD/month digital reimbursement.
  • Access to BetterUp coaching for personal and professional growth.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Security & Technology Risk Analyst

Moniepoint 1K-5K Diversified Financial Services

Moniepoint is seeking a Security & Technology Risk Analyst to assess and manage security and technology risks across its fintech ecosystem, supporting regulatory compliance, operational resilience, and informed executive decision-making.

Network Security
20 hours, 13 minutes ago

Middle Information Security Access Specialist

GR8 Tech 251-1K IT Services

GR8_TECH is hiring an IAM and access management professional to secure and automate employee access across its global B2B iGaming technology organization.

Active Directory AWS Azure
1 day, 20 hours ago

Investigations Analyst

Turing 251-1K Internet Software & Services

Turing is hiring an Investigations Analyst to support its security investigations function by handling fraud and insider-threat cases from initial signal through resolution, protecting the company and its customers.

Python SIEM SQL
1 day, 21 hours ago

Investigations Analyst

Turing 251-1K Internet Software & Services

Turing is hiring an Investigations Analyst to support its security investigations function by resolving fraud and insider-threat cases and protecting the company and its customers.

Python SIEM SQL
1 day, 21 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers