
About Huntress
Founded in 2015 by former NSA cyber operators, Huntress is a remote-first team working to make enterprise-grade cybersecurity accessible to businesses of all sizes. We work closely with security teams and service providers protecting complex environments, often without the time or headcount to handle it all. That’s why we build our technology in-house and back it with a 24/7 human-led Security Operations Center (SOC).
Huntress now secures more than 5M+ endpoints and 15M+ identities worldwide.
What You’ll Do
As a Senior Detection Engineering and Threat Hunting (DE&TH) Analyst, you should be drawn to the hard problems: detecting stealthy intrusions, managing false positives and false negatives at scale, and uncovering clues that may expose an evolving campaign across Huntress partners. In this role, you will turn threat intelligence, or a hypothesis, into detections that help the SOC find real intrusions faster.
- Detection Engineering: Design, build, and maintain a resilient, scalable, and high-fidelity detection portfolio that enables the SOC to rapidly identify and respond to adversary activity across identities and endpoints.
- Threat Hunting: Research new attacker tradecraft, test new theories, and review hunting data at scale for millions of endpoints to proactively hunt for and disrupt stealthy threat actor techniques.
Responsibilities
- Contribute to all parts of the detection lifecycle by creating new rules, testing them before deployment, monitoring efficacy, and tuning, promoting, or retiring rules based on performance.
- Develop rules across a variety of Huntress products and operating systems, including Identity Threat Detection and Response (ITDR), SIEM, EDR, Windows, Linux, and macOS.
- Manage any DE&TH requests raised internally or escalated from our partners.
- Undertake hypothesis-driven hunts across Huntress telemetry, prioritizing techniques and tradecraft that may evade high-fidelity detections and initial SOC review.
- Consume threat intelligence and translate IOCs, TTPs, and internal findings into new or refined detections through Git-based workflows.
- Build and refine hunting dashboards or queries required to surface potential intrusions.
- Review ambiguous signs of attacker activity, surfacing likely intrusions that require deeper investigation.
- Investigate or escalate likely intrusions identified to ensure partners receive clear incident reports with accurate advice.
- Contribute findings to community-driven projects and create Huntress content such as blogs, social posts, videos, podcasts, and webinars.
- Use AI-assisted workflows to prototype queries, enrich analysis, and develop scaffolding for detection rules, applying sound judgment to validate outputs.
What You Bring To The Team
- 2+ years of experience in detection engineering, threat hunting, SOC, MDR, or incident response.
- Intermediate knowledge of Windows internals.
- Working knowledge of Linux, macOS, Microsoft 365, Azure, and Google Workspace.
- Experience developing, testing, tuning, and documenting detections or analytics from threat intelligence, IOCs, hypotheses, or real-world investigations.
- Ability to communicate findings through clear written reports.
- Strong familiarity with detection languages such as Sigma, Suricata, Snort, or YARA, and query languages such as KQL, EQL, ES|QL, or Splunk SPL.
- A sound understanding of adversary tradecraft, including persistence, privilege escalation, defense impairment, lateral movement, discovery, and collection.
- A sound understanding of adversary roles (initial access brokers, ransomware affiliates, state-sponsored entities).
- Ability to orchestrate reusable AI workflows that improve threat hunting, detection development, or analysis, and verify outputs.
Bonus Points For:
- Intermediate knowledge of Linux and MacOS internals.
- Hands-on experience using tools to remotely discover evidence of compromise, such as OSquery, Velociraptor, and EDR/MDR/XDR platforms.
- Previous use of forensic tooling such as Eric Zimmerman's EZ Tools, RegRipper, Hayabusa, or Chainsaw to analyze endpoint artifacts.
- Intermediate malware analysis skills.
What We Offer
- 100% remote work environment
- Generous paid time off policy, including vacation, sick time, and paid holidays
- 12 weeks of paid parental leave
- Highly competitive and comprehensive medical, dental, and vision benefits plans
- 401(k) with a 5% contribution regardless of employee contribution
- Life and Disability insurance plans
- Stock options for all full-time employees
- One-time $500 reimbursement for building/upgrading home office
- Annual allowance for education and professional development assistance
- $75 USD/month digital reimbursement
- Access to the BetterUp platform for coaching, personal, and professional growth
Timezone overlap
UTC-8–-4
Benefits
Health, Dental, Vision, 401k, PTO, Parental leave, Equity, Home office, Learning, Internet, Mental health, Bonus
Open to
US
Sign in to track applications and earn points.