Threat Hunter/Purple Team Operator @SixGen, Inc.
All Others
Salary unspecified
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted Today

[Hiring] Threat Hunter/Purple Team Operator @SixGen, Inc.

Today - SixGen, Inc. is hiring a remote Threat Hunter/Purple Team Operator. πŸ’Έ Salary: unspecified πŸ“Location: USA

Role Description

SIXGEN is seeking a mid-level Threat Hunter / Purple Team Operator to identify threats that evade existing detection methods, develop and test hunting hypotheses, and feed findings back into detection engineering. This role will combine remote threat hunting and on-site purple team coordination in direct support of red team engagements to secure systems, strengthen the defenders, and build and validate detection methods that can catch offensive traffic in real time.

This role requires comfort working independently through remote hunts as well as the ability to translate adversary tradecraft into defensive guidance.

  • Conduct hypothesis-driven and intelligence-led threat hunts across endpoints, networks, and cloud telemetry for several weeks prior to each red team engagement.
  • Analyze logs, alerts, and historical data for indicators of compromise (IOCs), anomalous behavior, and adversary TTPs mapped to the MITRE ATT&CK from partner-provided sources (EDR, SIEM, authentication/identity logs).
  • Document hunt coverage and methodology, findings, detection recommendations, and any confirmed or suspected compromise, escalating immediately if active adversary activity is found.
  • Deliver a threat hunt summary and determine if the customer environment is clear prior to red team assessments.
  • Partner with blue teams during the purple portion of the engagement to assist in detecting, tuning, and validating controls against red team TTPs in real-time.
  • Brief technical and non-technical stakeholders on hunt result and purple team detection outcomes.
  • Serve as a Trusted Agent during the red team assessment and maintain strict confidentiality and operational security with insight into both red and blue team activity.

Technology proficiency includes:

  • SIEM platforms (e.g., Splunk, Microsoft Sentinel, Elastic).
  • EDR/XDR tooling (e.g. CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne, Carbon Black).
  • Network detection and traffic analysis tools (e.g. Zeek, Suricata, full packet capture).
  • Log aggregation and correlation across endpoint, network, cloud, and identity sources (e.g., Azure AD/Entra ID, AWS CloudTrail, Microsoft 365).
  • MITRE ATT&CK framework for mapping hunts and detections to adversary TTPs.
  • Query and scripting languages for hunting and automation (e.g. KQL, SPL, Python).
  • Familiarity with common red team tooling and tradecraft (e.g., Cobalt Strike, Havoc, and other C2 traffic patterns) to help recognize and detect it.

Qualifications

  • 3 – 5+ years of experience in threat hunting, SOC/detection engineering, incident response, or a closely related defensive security role.
  • Hand-on experience working with a major SIEM and EDR platform.
  • Working knowledge of the MITRE ATT&CK framework and how to map observed activity to adversary TTPs.
  • Understanding of common adversary tradecraft and red team testing methodology to help close detection gaps.
  • Strong written and verbal communication skills with the ability to produce clear, customer-facing findings and an β€œall clear” determination.
  • Comfortable operating independently in remote, customer-facing roles.
  • U.S. citizenship, with eligibility to obtain and maintain a U.S. government security clearance.

Requirements

  • Industry certifications such as GCFA, GCIH, GNFA, GCTI, CySA+, or equivalent.
  • Prior experience performing threat hunting and/or purple team role working directly alongside a red team.
  • Scripting and automation experience to streamline hunting workflows (e.g., Python, PowerShell).
  • Prior experience working with multiple partner organizations or client environments.
  • Active TS/SCI clearance.

Benefits

  • Employer-paid health insurance premiums, including medical, dental, and vision coverage, for employees and their families.
  • Employer-paid short- and long-term disability insurance and basic life and AD&D insurance.
  • 401(k) plan with a 4% employer contribution.
  • Professional-development reimbursement options for training, certifications, and education.
  • Flexible and remote-work policies for most positions.
  • Flexible paid time off and holiday schedule.
Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Threat Hunter/Purple Team Operator @SixGen, Inc.
All Others
Salary unspecified
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted Today
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 130,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 130,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 130,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 131,105+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later