
Role & Schedule
- Reports to: Manager, Security Operations Center
- Location: Remote, US
- Compensation: $100,000–$125,000 base pay + bonus + equity. This role may be eligible for on-call/call-in pay in addition to base pay.
- Schedule: Initial training is Monday–Friday. Following training, the schedule is a 4x10 shift (either Wednesday–Saturday or Sunday–Wednesday). Weekend shift hours are 7:00 AM – 5:00 PM PST.
About Huntress
Huntress is a fully remote, global team of passionate experts and ethical badasses on a mission to break down the barriers to cybersecurity. Founded in 2015 by former NSA cyber operators, Huntress protects all businesses with enterprise-grade, fully owned, and managed cybersecurity products.
We protect 4M+ endpoints and 7M+ identities worldwide, elevating underresourced IT teams with protection that works as hard as they do.
What You'll Do
In this role, you will triage, investigate, respond to, and remediate a variety of intrusions on a daily basis within our Security Operations Center (SOC).
Responsibilities
- Triage, investigate, and respond to alerts coming in from the Huntress platform.
- Perform tactical review of EDR telemetry, log sources, and forensic artifacts to determine the root cause of attacks and provide required remediations.
- Perform tactical malware analysis as part of investigating and triaging alerts.
- Investigate suspicious Microsoft M365 activity and provide remediations.
- Assist in escalations from the Product Support team for threat-related and SOC-relevant questions.
- Contribute to detection engineering creation and tuning efforts.
- Contribute to projects focused on driving better outcomes for our analysts and partners.
- Contribute to our collaboratively mentored team environment.
Qualifications
Required
- 2+ years of experience in a SOC or Digital Forensics and Incident Response (DFIR) role.
- Demonstrated experience with Windows, Linux, and macOS as an attack surface.
- Demonstrated experience with core Threat Actor tools and techniques (MITRE ATT&CK Framework, PowerShell & Command Prompt Terminals, WMIC, Scheduled Tasks, SCM, Windows Domain/host enumeration, lateral movement, persistence, defense evasion, and offensive/Red Team TTPs).
- Demonstrated experience with static and dynamic malware analysis concepts.
- Working knowledge of Windows Administration or Enterprise Domain Administration (Active Directory, Group Policy, Domain Trusts, etc.).
- Working knowledge of core networking concepts (common ports/protocols, NAT, Public/Private IPs, VLANs, etc.).
- Working knowledge of web technologies and concepts (web servers/applications, OWASP Top 10, etc.).
- Effective communication skills with the ability to explain complex events to non-technical audiences.
- Dedicated to prioritizing and addressing customer needs and concerns.
- Strong sense of curiosity and excitement for continuous learning.
Preferred
- Previous experience in an MSP, MSSP, or MDR role.
- Linux and macOS investigative experience.
- Experience with scripting languages (PowerShell, Python, Bash, PHP, JavaScript, or Ruby).
- Demonstrated hands-on experience on platforms such as HackTheBox, TryHackMe, Blue Team Labs Online, etc.
- Cloud-based investigative experience (M365, Azure, AWS, GCP, etc.).
- Participation in cybersecurity competitions (CTFs, CCDC, etc.).
- Familiarity with MSP tools such as RMMs.
What We Offer
- 100% remote work environment since 2015
- Generous paid time off policy (vacation, sick time, and paid holidays)
- 12 weeks of paid parental leave
- Comprehensive medical, dental, and vision benefit plans
- 401(k) with a 5% employer contribution (regardless of employee contribution)
- Life and Disability insurance plans
- Stock options for all full-time employees
- $500 one-time home office reimbursement
- $75/month digital/internet reimbursement
- Annual education and professional development allowance
- Access to the BetterUp coaching platform
Timezone overlap
UTC-8–-4
Benefits
Equity, Bonus, Health, Dental, Vision, 401k, PTO, Parental leave, Learning, Home office, Internet, Wellness
Open to
US
Sign in to track applications and earn points.