Senior Detection Engineering & Threat Hunting Analyst @Huntress
All Others
Salary usd 150,000 - 1..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 1wk ago

[Hiring] Senior Detection Engineering & Threat Hunting Analyst @Huntress

1wk ago - Huntress is hiring a remote Senior Detection Engineering & Threat Hunting Analyst. πŸ’Έ Salary: usd 150,000 - 170,000 per year πŸ“Location: USA

Role Description

Members of the Huntress DE&TH team wake up every morning with the honor of impeding threat actors through a combination of detection engineering and threat hunting. This team sits alongside our 24x7 Security Operations Center and our Adversary Tactics & Tactical Response function, playing a pivotal role in detecting threat actors before they can impact our partner environments.

As a Senior Detection Engineering and Threat Hunting (DE&TH) Analyst, you should be drawn to the hard problems:

  • Detecting stealthy intrusions
  • Managing false positives and false negatives at scale
  • Uncovering clues that may expose an evolving campaign across Huntress partners

In this role, you will turn threat intelligence, or a hypothesis, into detections that help the SOC find real intrusions faster. While the SOC is responding to alerts within minutes, this team is developing detections and reviewing more ambiguous signs of attacker activity on a daily & weekly basis.

On the Detection Engineering side of the role, you will:

  • Design, build, and maintain a resilient, scalable, and high-fidelity detection portfolio
  • Work with engineering and other adjacent teams to achieve a shared goal across multiple domains, including identities and endpoints

On the Threat Hunting side of the role, you will:

  • Research new attacker tradecraft
  • Test new theories
  • Review hunting data at scale for millions of endpoints to proactively hunt for and disrupt stealthy threat actor techniques

If you love Detection Engineering and Threat Hunting at scale, whilst in the environment and energy of a SOC, this is the role for you!

Qualifications

  • 2+ years of experience in detection engineering, threat hunting, SOC, MDR, or incident response
  • Intermediate knowledge of Windows internals
  • Working knowledge of Linux, macOS, Microsoft 365, Azure, and Google Workspace
  • Experience developing, testing, tuning, and documenting detections or analytics from threat intelligence, IOCs, hypotheses, or real-world investigations
  • Ability to communicate findings through clear written reports
  • Strong familiarity with detection languages such as Sigma, Suricata, Snort, or YARA, and query languages such as KQL, EQL, ES|QL, or Splunk SPL
  • A sound understanding of adversary tradecraft, including techniques used for persistence, privilege escalation, defense impairment, lateral movement, discovery, and collection on a system
  • A sound understanding of the roles different threat actors play and their associated goals, such as initial access brokers, ransomware affiliates, and state-sponsored entities
  • Ability to orchestrate reusable AI workflows that improve threat hunting, detection development, or analysis, and can verify AI-generated outputs before they reach production environments

Requirements

  • Contribute to all parts of the detection lifecycle by creating new rules, testing them before deployment, monitoring efficacy, and tuning, promoting, or retiring rules based on their performance
  • Develop rules across a variety of Huntress products and operating systems, including Identity Threat Detection and Response (ITDR), Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), Windows, Linux, and macOS
  • Manage any DE&TH requests raised internally or escalated from our partners
  • Undertake hypothesis-driven hunts across Huntress telemetry, prioritizing techniques and tradecraft that may evade high-fidelity detections and initial SOC review
  • Consume threat intelligence and translate IOCs, TTPs, and internal findings into new or refined detections through Git-based workflows
  • Build and refine hunting dashboards or queries required to surface potential intrusions
  • Review ambiguous signs of attacker activity across Huntress products, and surface likely intrusions that require deeper investigation
  • Investigate or escalate likely intrusions identified to ensure partners receive clear incident reports with accurate advice
  • Contribute findings to community-driven projects and create Huntress content such as blogs, social posts, videos, podcasts, and webinars
  • Use AI-assisted workflows to prototype queries, enrich analysis, and develop a scaffolding for detection rules, ensuring you apply sound judgment to validate the AI output

Benefits

  • 100% remote work environment - since our founding in 2015
  • Generous paid time off policy, including vacation, sick time, and paid holidays
  • 12 weeks of paid parental leave
  • Highly competitive and comprehensive medical, dental, and vision benefits plans
  • 401(k) with a 5% contribution regardless of employee contribution
  • Life and Disability insurance plans
  • Stock options for all full-time employees
  • One-time $500 reimbursement for building/upgrading home office
  • Annual allowance for education and professional development assistance
  • $75 USD/month digital reimbursement
  • Access to the BetterUp platform for coaching, personal, and professional growth
Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior Detection Engineering & Threat Hunting Analyst @Huntress
All Others
Salary usd 150,000 - 1..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 1wk ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 120,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 120,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 120,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 121,921+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later