
Principal Threat Hunter
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in United States.
• Develop and implement proactive threat hunting strategies across cloud and SaaS platforms (AWS, Azure, GCP, Okta, M365), based on current intelligence and ATT&CK-based adversary behaviors.
• Enhance and manage an ongoing threat intelligence reporting function, transforming intel into hunt leads, detection opportunities, and narratives for clients.
• Oversee incident response investigations during US business hours, from the initial scoping to root cause analysis; assume the Incident Commander role when necessary.
• Consistently monitor threat detections and provide responsive services through detailed event analysis and sound judgement.
• Assess and investigate security alerts across cloud and SaaS environments, distinguishing actual threats from false alarms, and identify detection gaps for the detection engineering team.
• Utilize automation and AI tools to amplify impact, while recommending enhancements for processes, workflows, products, and policies.
• Shape the team's approach to hunting, investigating, and responding to threats across cloud and SaaS environments on a large scale.
• Lead intricate investigations, propel threat intelligence initiatives, and contribute to the development of hunting methodologies.
• Raise technical standards, mentor colleagues, and assist in evolving detection and response capabilities.
• Over 5 years of experience in a security operations role, specifically in threat hunting and/or threat intelligence.
• Demonstrated experience in building or participating in a structured threat hunting and/or threat intelligence program.
• Experience in incident response with the capability to lead investigations autonomously; experience as an Incident Commander is a plus.
• Proficient understanding of cloud and SaaS environments (AWS, Azure, GCP, Okta, M365).
• Practical experience using automation or AI tools within security operations; proven application, not merely familiarity.
• Exceptional written and verbal communication skills, strong analytical and problem-solving abilities, highly self-motivated, and comfortable working in a fast-paced virtual environment.
• Health insurance (medical, dental, vision)
• 401k plan with matching contributions
• Unlimited paid time off (PTO)
• Reimbursement for cell phone expenses
• State-of-the-art equipment provided
TRM Labs
CrowdStrike
Instituto Hardware BR HBR
Cellebrite
Get handpicked remote jobs straight to your inbox weekly.