Senior Detection Engineering & Threat Hunting Analyst
H
HuntressCybersecurity
Remote USFull-TimeSenior
Salary$150,000 to $170,000 base plus bonus and equity
Apply NowOpens the employer's application page
Job Details
- Experience
- 2+ years of experience
- Required Skills
- AzureLinuxGoogle Workspace
Requirements
- 2+ years of experience in detection engineering, threat hunting, SOC, MDR, or incident response.
- Intermediate knowledge of Windows internals.
- Working knowledge of Linux, macOS, Microsoft 365, Azure, and Google Workspace.
- Experience developing, testing, tuning, and documenting detections or analytics from threat intelligence, IOCs, hypotheses, or real-world investigations.
- Ability to communicate findings through clear written reports.
- Strong familiarity with detection languages such as Sigma, Suricata, Snort, or YARA.
- Strong familiarity with query languages such as KQL, EQL, ES|QL, or Splunk SPL.
- Sound understanding of adversary tradecraft (e.g., persistence, privilege escalation, lateral movement).
- Ability to orchestrate reusable AI workflows.
Responsibilities
- Contribute to all parts of the detection lifecycle by creating new rules, testing them before deployment, monitoring efficacy, and tuning, promoting, or retiring rules based on their performance.
- Develop rules across a variety of Huntress products and operating systems, including ITDR, SIEM, EDR, Windows, Linux, and macOS.
- Manage any DE&TH requests raised internally or escalated from our partners.
- Undertake hypothesis-driven hunts across Huntress telemetry, prioritizing techniques and tradecraft that may evade high-fidelity detections and initial SOC review.
- Consume threat intelligence and translate IOCs, TTPs, and internal findings into new or refined detections through Git-based workflows.
- Build and refine hunting dashboards or queries required to surface potential intrusions.
- Use AI-assisted workflows to prototype queries, enrich analysis, and develop a scaffolding for detection rules.
View Full Description & ApplyYou'll be redirected to the employer's site