Jobs Companies Huntress Senior Detection Engineering & Threat Hunting Analyst

Über diese Senior Detection Engineering & Threat Hunting Analyst Stelle bei Huntress

Huntress · Vor Ort · United States of America

Reports to: Sr. Manager, Detection Engineering & Threat Hunting

Location: Remote US

Compensation Range: $150,000 to $170,000 base plus bonus and equity

 

What We Do:

Cybercrime is growing, and more businesses are getting hit by threats that used to target only the biggest organizations. That pushes defenders like us to operate at the highest level, and it deepens our need for good people who want to make a meaningful impact.

Founded in 2015 by former NSA cyber operators, Huntress is a remote-first team working to make enterprise-grade cybersecurity accessible to businesses of all sizes. We work closely with security teams and service providers protecting complex environments, often without the time or headcount to handle it all. That’s why we build our technology in-house and back it with a 24/7 human-led Security Operations Center (SOC). As a result, our platform is never disconnected from the experts who manage it, ensuring our customers' protection.

Huntress now secures more than 5M+ endpoints and 15M+ identities worldwide. Those numbers keep growing because more businesses rely on us to help carry the load and operate with more confidence. Every day, you can see that commitment in how we stand with our customers and how we show up for each other.

What You’ll Do: 

Members of the Huntress DE&TH team wake up every morning with the honor of impeding threat actors through a combination of detection engineering and threat hunting. This team sits alongside our 24x7 Security Operations Center and our Adversary Tactics & Tactical Response function, and plays a pivotal role in detecting threat actors before they can impact our partner environments. 

As a Senior Detection Engineering and Threat Hunting (DE&TH) Analyst, you should be drawn to the hard problems: detecting stealthy intrusions, managing false positives and false negatives at scale, and uncovering clues that may expose an evolving campaign across Huntress partners. In this role, you will turn threat intelligence, or a hypothesis, into detections that help the SOC find real intrusions faster. While the SOC is responding to alerts within minutes, this team is developing detections and reviewing more ambiguous signs of attacker activity on a daily & weekly basis.

On the Detection Engineering side of the role, you will play a part in designing, building, and maintaining a resilient, scalable, and high-fidelity detection portfolio that enables the SOC to rapidly identify and respond to adversary activity. This will involve working with engineering and other adjacent teams to achieve a shared goal across multiple domains, which includes identities and endpoints.

On the Threat Hunting side of the role, you will get to research new attacker tradecraft, test new theories, and review hunting data at scale for millions of endpoints to proactively hunt for and disrupt stealthy threat actor techniques that evade initial defenses.

If you love Detection Engineering and Threat Hunting at scale, whilst in the environment and energy of a SOC, this is the role for you!

Responsibilities: 

  • Contribute to all parts of the detection lifecycle by creating new rules, testing them before deployment, monitoring efficacy, and tuning, promoting, or retiring rules based on their performance.
  • Develop rules across a variety of Huntress products and operating systems, including Identity Threat Detection and Response (ITDR), Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), Windows, Linux, and macOS.
  • Manage any DE&TH requests raised internally or escalated from our partners.
  • Undertake hypothesis-driven hunts across Huntress telemetry, prioritizing techniques and tradecraft that may evade high-fidelity detections and initial SOC review.
  • Consume threat intelligence and translate IOCs, TTPs, and internal findings into new or refined detections through Git-based workflows.
  • Build and refine hunting dashboards or queries required to surface potential intrusions.
  • Review ambiguous signs of attacker activity across Huntress products, and surface likely intrusions that require deeper investigation.
  • Investigate or escalate likely intrusions identified to ensure partners receive clear incident reports with accurate advice.
  • Contribute findings to community-driven projects and create Huntress content such as blogs, social posts, videos, podcasts, and webinars.
  • Use AI-assisted workflows to prototype queries, enrich analysis, and develop a scaffolding for detection rules, ensuring you apply sound judgment to validate the AI output. We expect everyone at Huntress to be able to use AI as a real part of how they work, not occasionally, but genuinely embedded in core workflows.

What You Bring To The Team: 

  • 2+ years of experience in detection engineering, threat hunting, SOC, MDR, or incident response.
  • Intermediate knowledge of Windows internals.
  • Working knowledge of Linux, macOS, Microsoft 365, Azure, and Google Workspace.
  • Experience developing, testing, tuning, and documenting detections or analytics from threat intelligence, IOCs, hypotheses, or real-world investigations.
  • Ability to communicate findings through clear written reports.
  • Strong familiarity with detection languages such as Sigma, Suricata, Snort, or YARA, and query languages such as KQL, EQL, ES|QL, or Splunk SPL.
  • A sound understanding of adversary tradecraft, including techniques used for persistence, privilege escalation, defense impairment, lateral movement, discovery, and collection on a system.
  • A sound understanding of the roles different threat actors play and their associated goals, such as initial access brokers, ransomware affiliates, and state-sponsored entities.
  • Ability to orchestrate reusable AI workflows that improve threat hunting, detection development, or analysis, and can verify AI-generated outputs before they reach production environments.

Bonus Points for:

  • Intermediate knowledge of Linux and MacOS internals.
  • Hands-on experience using tools to remotely discover evidence of compromise, such as OSquery, Velociraptor, and EDR/MDR/XDR platforms.
  • Previous use of forensic tooling such as Eric Zimmerman's EZ Tools, RegRipper, Hayabusa, or Chainsaw to analyze endpoint artifacts.
  • Intermediate malware analysis skills.

What We Offer: 

  • 100% remote work environment - since our founding in 2015
  • Generous paid time off policy, including vacation, sick time, and paid holidays
  • 12 weeks of paid parental leave
  • Highly competitive and comprehensive medical, dental, and vision benefits plans 
  • 401(k) with a 5% contribution regardless of employee contribution
  • Life and Disability insurance plans
  • Stock options for all full-time employees 
  • One-time $500 reimbursement for building/upgrading home office
  • Annual allowance for education and professional development assistance 
  • $75 USD/month digital reimbursement
  • Access to the BetterUp platform for coaching, personal, and professional growth

  

Huntress is committed to creating a culture of inclusivity where every single member of our team is valued, has a voice, and is empowered to come to work every day just as they are. 

We do not discriminate based on race, ethnicity, color, ancestry, national origin, religion, sex, sexual orientation, gender identity, disability, veteran status, genetic information, marital status, or any other legally protected status.  

We do discriminate against hackers who try to exploit businesses of all sizes.

Accommodations: 

If you require reasonable accommodation to complete this application, interview, or pre-employment testing or participate in the employee selection process, please direct your inquiries to [email protected]. Please note that non-accommodation requests to this inbox will not receive a response. 

Huntress uses artificial intelligence tools to assist in reviewing and evaluating job applications, including resume screening, skills assessment, and candidate matching and comparisons. These AI tools support our human recruiters in the initial review process, but do not make final hiring decisions without human involvement. By submitting your application, you acknowledge this use of AI in our recruitment process. Please review our Candidate Privacy Notice for more details on our practices and your data privacy rights.

#BI-Remote 

Bereit, sich bei Huntress zu bewerben?
Bei Huntress bewerben

Über Huntress

Huntress is a fully remote, global team of passionate experts and ethical badasses on a mission to break down the barriers to cybersecurity. Whether creating purpose-built security solutions, hunting down hackers, or impacting our community, our people go above and beyond to change the security game and make a real difference. 

Founded in 2015 by former NSA cyber operators, Huntress protects all businesses—not just the 1%—with enterprise-grade, fully owned and managed cybersecurity products at the price of an affordable SaaS application. The Huntress difference is our One Team advantage: our technology is designed with our industry-defining Security Operations Center (SOC) in mind and is never separated from our service. 

We protect 4M+ endpoints and 8M+ identities worldwide, elevating underresourced IT teams with protection that works as hard as they do. As long as hackers keep hacking, Huntress keeps hunting.


With the number of recruiting scams on the rise, we encourage you to be wary and protect yourself by ensuring you’re actually communicating with Huntress. We communicate through both @huntress.com and @huntresslabs.com domains, so be vigilant when checking domains, as scammers may make minor adjustments to deceive you. Huntress will never ask our candidates for financial information or payments of any kind during our recruitment process.

 

If you want to verify whether a communication or career opportunity is legitimate, please contact [email protected] or check our careers page. (Resumes submitted to the careers email address will not receive a response.)

Alle Jobs bei Huntress ansehen →

Ähnliche Jobs

HU
Partner Success Manager
Huntress
⚡ Früh bewerben Australia Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 5 Std.
HU
Senior Product Manager, SOC Experience
Huntress
⚡ Früh bewerben United States of America Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 7 Std.
HU
Partner Success Manager
Huntress
⚡ Früh bewerben United States of America Vor Ort $72,000–$72,000
● Neu 👁 Gesehen ✓ Beworben vor 7 Std.
HU
Staff CSIRT Analyst
Huntress
⚡ Früh bewerben United States of America Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 7 Std.
HU
Channel Account Manager II, Service Provider
Huntress
⚡ Früh bewerben United States of America Vor Ort $90,000–$90,000
● Neu 👁 Gesehen ✓ Beworben vor 7 Std.
HU
QMS Manager
Huntress
⚡ Früh bewerben United States of America Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 7 Std.
HU
Staff Software Engineer - Detection Platform (GoLang)
Huntress
⚡ Früh bewerben United States of America Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 7 Std.
HU
Principal Security Researcher - EDR (Windows)
Huntress
⚡ Früh bewerben United States of America Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 7 Std.
HU
Director, Product Management, Identity
Huntress
⚡ Früh bewerben United States of America Vor Ort $260,000–$290,000
● Neu 👁 Gesehen ✓ Beworben vor 7 Std.

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei Huntress

Alle Jobs bei Huntress ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos