
Cyber Threat Hunter
Posted 4 days ago

Posted 4 days ago
This is a fully remote position, open to applicants in California, +17 more states.
• Design and execute hypothesis-driven hunts across endpoint, identity, cloud, and network telemetry.
• Leverage CTI and findings from red-team/purple-team activities to prioritize hunts effectively.
• Align hunts and findings with the MITRE ATT&CK framework to monitor coverage and identify blind spots.
• Convert hunt findings into detection packages and actionable recommendations for the tooling team.
• Collaborate with the red team on purple validation to identify configuration issues and security posture deficiencies.
• Highlight configuration issues and posture gaps, driving recommendations to resolve them.
• Document hypotheses, methodologies, and outcomes in reusable artifacts.
• Provide threat context and intelligence derived from hunts during declared Sev 1 incidents in an advisory role.
• Over 5 years of experience in security operations, detection engineering, CTI, or incident response roles, with significant hands-on threat-hunting responsibilities.
• Proven experience in conducting hypothesis-driven hunts and successfully concluding investigations.
• Strong understanding of adversary tactics, techniques, and procedures.
• Practical knowledge of the MITRE ATT&CK framework.
• Proficient in querying and pivoting across security telemetry at scale using SIEM and/or EDR/XDR technologies, such as KQL or SPL.
• Familiarity with endpoint, identity, cloud, and network telemetry.
• Ability to translate hunt findings into detection recommendations, considering logic, context, and accuracy.
• Understanding of the detection lifecycle and the quality of SOC signal-to-noise ratio.
• Excellent written communication skills for documentation, detection packages, and SOP recommendations.
• Capacity to plan and maintain long-term hunt campaigns with minimal day-to-day guidance.
• Skills in scripting for automation and enrichment, preferably in Python.
• Knowledge of detection-as-code workflows and version-controlled detection content.
• Experience with cloud-native and SaaS telemetry, including CloudTrail, Entra ID/Azure AD, and SaaS audit logs.
• Familiarity with a threat intelligence platform and structured intelligence workflows.
• Exposure to an incident-response-capable or standing-response team environment.
• Relevant certifications are preferred but not mandatory, such as GCTI, GCFA, GCDA, GCIA, OSCP, or cloud security certifications.
• Must be a U.S. citizen or lawful permanent resident.
• Must reside in an eligible U.S. state; this role is not available within the city limits of Chicago.
• This position is not eligible for visa sponsorship.
• A comprehensive benefits package that includes medical, dental, and vision insurance.
• 401(k) plan.
• Unlimited PTO.
• Life insurance coverage.
• Opportunities for growth and advancement.
• A collaborative, kind, and curious community.
• Flexible hybrid-remote work arrangement.
Everstream Analytics
Kodex
Muck Rack
Fifth Third Bank
Get handpicked remote jobs straight to your inbox weekly.