Huntress

Huntress

Huntress is a managed cybersecurity platform that protects small and mid-market businesses from cybercriminals. Their services include managed endpoint protection, detection and response, Microsoft 365 identity protection, and security awareness traini...

Professional Services
251-1K
Founded 2015
$160M raised

Description

  • Triage, investigate, respond to, and remediate alerts coming in from the Huntress platform.
  • Review EDR telemetry, log sources, and forensic artifacts to determine attack root cause and required remediations.
  • Perform tactical malware analysis during alert investigation and triage.
  • Investigate suspicious Microsoft M365 activity and provide remediation guidance.
  • Assist with escalations from the Product Support team on threat-related and SOC-relevant questions.
  • Contribute to detection engineering creation and tuning efforts.
  • Support projects aimed at improving outcomes for analysts and partners.
  • Collaborate within a mentored SOC team and contribute to cross-functional learning.

Requirements

  • 2+ years of experience in a SOC or Digital Forensics (DFIR) role.
  • Demonstrated experience with Windows, Linux, and MacOS as an attack surface.
  • Demonstrated experience with threat actor tools and techniques, including MITRE ATT&CK, PowerShell, Command Prompt, WMIC, Scheduled Tasks, SCM, enumeration, lateral movement, persistence, and defense evasion.
  • Demonstrated experience with static and dynamic malware analysis concepts.
  • Working knowledge of Windows Administration or Enterprise Domain Administration, including Active Directory, Group Policy, and Domain Trusts.
  • Working knowledge of core networking concepts, including common ports/protocols, NAT, public/private IPs, and VLANs.
  • Working knowledge of web technologies and concepts, including web servers/applications and OWASP Top 10.
  • Effective communication skills with the ability to explain complex events to less technical audiences.
  • A strong sense of curiosity and genuine excitement for learning.
  • Previous experience in an MSP/MSSP/MDR role is preferred.
  • Linux and MacOS investigative experience is preferred.
  • Experience with scripting languages such as PowerShell, Python, Bash, PHP, JavaScript, or Ruby is preferred.
  • Hands-on experience with platforms such as HackTheBox, TryHackMe, or Blue Team Labs Online is preferred.
  • Experience with cloud-based investigations such as M365, Azure, AWS, or GCP is preferred.
  • Participation in cybersecurity competitions such as CTFs or the Collegiate Cyber Defense Competition is preferred.
  • Familiarity with MSP tools such as RMMs is preferred.

Benefits

  • $100,000-$125,000 base salary plus bonus and equity.
  • May be eligible for on-call/call-in pay in addition to base pay.
  • 100% remote work environment.
  • Generous paid time off, including vacation, sick time, and paid holidays.
  • 12 weeks of paid parental leave.
  • Comprehensive medical, dental, and vision insurance.
  • 401(k) with a 5% company contribution regardless of employee contribution.
  • Life and disability insurance.
  • Stock options for all full-time employees.
  • One-time $500 home office reimbursement.
  • Annual education and professional development allowance.
  • $75 USD/month digital reimbursement.
  • Access to BetterUp coaching for personal and professional growth.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Insider Threat Analyst

SpaceX 10K-50K Aerospace & Defense

SpaceX is hiring an Insider Threat Analyst to investigate anomalous activity and help protect its personnel, assets, intellectual property, and operations across a fast-paced advanced technology environment.

Splunk
3 hours, 7 minutes ago

Vulnerability Analyst

Coalfire 251-1K Internet Software & Services

Coalfire is hiring a remote Vulnerability Analyst to support federal cloud advisory services by managing vulnerability monitoring, compliance evidence, and remediation reporting across regulated environments.

AWS Azure Bash Burp Suite CI/CD Cybersecurity DevSecOps GCP Kubernetes PowerShell Prisma Python
12 hours, 32 minutes ago

L1 Analyst

Appgate 251-1K Professional Services

GFC Operations is hiring an L1 Analyst to serve as the first line of defense, investigating and mitigating cybersecurity events for clients in a highly analytical, curiosity-driven operations environment.

Cybersecurity HTML Linux
1 day, 1 hour ago

French Speaking Digital Trust and Safety Analyst - Work In Sofia

Mercier Consultancy Professional Services

Mercier Consultancy MD is hiring a French Speaking Digital Trust and Safety Analyst in Sofia to monitor, investigate, and manage online content and policy compliance to help maintain a safe digital environment.

1 day, 7 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers