Senior Detection Engineering & Threat Hunting Analyst

35 minutes ago
Full-time
Senior
Cybersecurity
Huntress

Huntress

Huntress is a managed cybersecurity platform that protects small and mid-market businesses from cybercriminals. Their services include managed endpoint protection, detection and response, Microsoft 365 identity protection, and security awareness traini...

Professional Services
251-1K
Founded 2015
$160M raised

Description

  • Create, test, monitor, tune, promote, and retire detection rules throughout the detection lifecycle.
  • Develop detections across ITDR, SIEM, EDR, Windows, Linux, and macOS environments.
  • Manage internal and partner-escalated detection engineering and threat hunting requests.
  • Conduct hypothesis-driven hunts across Huntress telemetry to identify evasive attacker techniques.
  • Translate threat intelligence, IOCs, TTPs, and investigation findings into detections through Git-based workflows.
  • Build and refine hunting queries and dashboards to surface potential intrusions.
  • Review ambiguous attacker activity and investigate or escalate likely intrusions with clear incident reporting.
  • Contribute findings to community projects and create blogs, social posts, videos, podcasts, and webinars.
  • Use AI-assisted workflows to prototype queries, enrich analysis, and scaffold detection rules while validating outputs.

Requirements

  • 2+ years of experience in detection engineering, threat hunting, SOC, MDR, or incident response.
  • Intermediate knowledge of Windows internals.
  • Working knowledge of Linux, macOS, Microsoft 365, Azure, and Google Workspace.
  • Experience developing, testing, tuning, and documenting detections or analytics.
  • Ability to communicate findings through clear written reports.
  • Familiarity with Sigma, Suricata, Snort, or YARA and query languages such as KQL, EQL, ES|QL, or Splunk SPL.
  • Understanding of adversary tradecraft, including persistence, privilege escalation, defense impairment, lateral movement, discovery, and collection.
  • Understanding of threat actor roles and objectives, including initial access brokers, ransomware affiliates, and state-sponsored entities.
  • Ability to build reusable AI workflows and verify AI-generated outputs before production use.
  • Preferred: Linux and macOS internals, OSquery, Velociraptor, EDR/MDR/XDR platforms, forensic tools, and intermediate malware analysis skills.

Benefits

  • $150,000–$170,000 base salary plus bonus and equity.
  • 100% remote work environment.
  • Generous paid time off, including vacation, sick time, and holidays.
  • 12 weeks of paid parental leave.
  • Medical, dental, and vision insurance, plus life and disability coverage.
  • 401(k) with a 5% employer contribution regardless of employee contribution.
  • Stock options for all full-time employees.
  • Professional development support, BetterUp coaching, $500 home-office reimbursement, and $75 monthly digital reimbursement.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Binance Accelerator Program - Internal Audit (Technology)

Binance 5K-10K Capital Markets

Binance is hiring a Technology Audit Intern for its Internal Audit team to support technology control assessments, data analysis, and audit automation across its global blockchain ecosystem.

AWS Blockchain CI/CD Cybersecurity Encryption Kubernetes Python SQL
1 hour, 50 minutes ago

Information System Security Officer (ISSO)

Lever 251-1K Professional Services

Spry Methods is seeking a remote Information System Security Officer (ISSO) to support the Department of the Interior’s ISSLoB Cybersecurity Program by managing NIST RMF activities, security assessments, and authorization services for customer information systems.

Cybersecurity Encryption
2 hours, 5 minutes ago

Security & Technology Risk Analyst

Moniepoint 1K-5K Diversified Financial Services

Moniepoint is seeking a Security & Technology Risk Analyst to assess and manage security and technology risks across its fintech ecosystem, supporting regulatory compliance, operational resilience, and informed executive decision-making.

Network Security
2 days, 1 hour ago

Middle Information Security Access Specialist

GR8 Tech 251-1K IT Services

GR8_TECH is hiring an IAM and access management professional to secure and automate employee access across its global B2B iGaming technology organization.

Active Directory AWS Azure
3 days, 1 hour ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers