Huntress logo
Huntress·

Security Operations Analyst - Huntress

Fully remoteFull-timeMid-level$100K - $125KUTC-8–-4US#soc#dfir#powershellEquityBonusHealthDentalVision401kPTOParental leave

About Huntress

Huntress is a fully remote, global team of cybersecurity experts on a mission to break down the barriers to cybersecurity. Founded in 2015 by former NSA cyber operators, Huntress protects all businesses—not just the 1%—with enterprise-grade, fully owned, and managed cybersecurity products at the price of an affordable SaaS application.

We protect over 4 million endpoints and 7 million identities worldwide, elevating under-resourced IT teams with protection that works as hard as they do.

Role Overview

As a Security Operations Center (SOC) Analyst, you will triage, investigate, respond to, and remediate a variety of intrusions on a daily basis. The Huntress SOC is an elite team focused on combating threat actors in real-time, giving you daily opportunities to advance your analysis skills at the forefront of the threat landscape.

Note: The initial training period for this position will be Monday–Friday. Following training, the work schedule is subject to change and may include weekends or a 4x10 shift depending on business requirements. This role may be eligible for on-call/call-in pay in addition to base pay.

Key Responsibilities

  • Triage, investigate, and respond to alerts incoming from the Huntress platform.
  • Perform tactical review of EDR telemetry, log sources, and forensic artifacts to determine attack root causes and provide remediation steps.
  • Conduct tactical malware analysis as part of alert investigation and triaging.
  • Investigate suspicious Microsoft M365 activity and provide appropriate remediation.
  • Assist the Product Support team with threat-related and SOC-relevant escalations.
  • Contribute to detection engineering creation, tuning efforts, and internal team projects.
  • Engage in a collaboratively mentored team environment to share knowledge and elevate colleagues.

What You Bring

  • Experience: 2+ years of experience in a SOC or Digital Forensics and Incident Response (DFIR) role.
  • OS Expertise: Demonstrated experience with Windows, Linux, and macOS as attack surfaces.
  • Threat Intelligence: Hands-on experience with Threat Actor tools and techniques (MITRE ATT&CK Framework, PowerShell, Command Prompt, WMIC, Scheduled Tasks, SCM, Active Directory/host enumeration, lateral movement, persistence, defense evasion).
  • Malware Analysis: Solid understanding of static and dynamic malware analysis concepts.
  • Domain & Networking: Working knowledge of Windows/Enterprise Domain Administration (Active Directory, Group Policy, Domain Trusts) and core networking concepts (ports/protocols, NAT, public/private IPs, VLANs).
  • Web Concepts: Understanding of web technologies and common vulnerabilities (web servers/applications, OWASP Top 10).
  • Communication: Ability to articulate complex security events clearly to non-technical stakeholders and cross-functional teams.

Preferred Qualifications

  • Previous experience working in an MSP, MSSP, or MDR environment.
  • Linux and macOS investigative experience.
  • Experience with scripting languages (PowerShell, Python, Bash, PHP, JavaScript, or Ruby).
  • Hands-on experience on platforms such as HackTheBox, TryHackMe, or Blue Team Labs Online.
  • Cloud investigation experience (M365, Azure, AWS, GCP).
  • Active participation in cybersecurity CTFs or CCDC competitions.
  • Familiarity with MSP tools such as RMMs.

What We Offer

  • 100% remote work environment (since 2015)
  • Generous paid time off policy (vacation, sick time, and paid holidays)
  • 12 weeks of paid parental leave
  • Competitive medical, dental, and vision benefit plans
  • 401(k) with a 5% company contribution (regardless of employee contribution)
  • Life and disability insurance coverage
  • Stock options for all full-time employees
  • $500 one-time home office setup/upgrade reimbursement
  • $75/month digital/internet reimbursement
  • Annual education and professional development allowance
  • Coaching and personal growth via the BetterUp platform

Timezone overlap

UTC-8–-4

Open to

US

Sign in to track applications and earn points.

More roles at Huntress

Similar remote roles