Principal Threat Hunter

V
VulnCheckCybersecurity threat intelligence
This role is fully remote and open to candidates based anywhere in the United States.Full-TimePrincipal
Salary not disclosed
Apply NowOpens the employer's application page

Job Details

Required Skills
Linux

Requirements

  • Demonstrate a track record of communicating technical security research through public writing, threat intelligence reports, blogs, presentations, or other published work.
  • Bring experience in threat hunting, attacker activity analysis, threat intelligence research, or closely related security research.
  • Be able to read and analyze PCAPs and reason about network traffic and protocols.
  • Have experience developing and tuning detections, including Suricata and/or Snort rules.
  • Have experience writing Nuclei templates or other scanners to identify vulnerabilities, exposed services, or attacker infrastructure.
  • Have strong programming or scripting ability and be comfortable reading and writing code in multiple languages.
  • Have experience working with Linux systems, networking, and internet-facing infrastructure.
  • Be able to analyze malware, payloads, scripts, and other investigation artifacts.
  • Have experience working with large datasets and developing queries or tooling to find meaningful activity.
  • Be able to pivot across technical data sources and follow an investigation from an initial indicator to broader infrastructure or activity.
  • Be able to identify research questions and pursue them independently without a predefined playbook.

Responsibilities

  • Hunt for emerging exploitation activity, attacker infrastructure, and novel attacker behavior across VulnCheck's data.
  • Investigate exploitation attempts, attacker payloads, binaries, infrastructure, and post-exploitation activity.
  • Develop rules, queries, tooling, and automation that turn discoveries into durable detection improvements.
  • Pivot across vulnerabilities, hosts, IPs, domains, payloads, and other infrastructure to uncover broader activity.
  • Turn research findings into actionable threat intelligence for VulnCheck customers.
  • Write customer-facing threat intelligence reports and technical blog posts.
  • Present research at conferences and other industry events.
  • Work with vulnerability researchers and the research team to connect observed exploitation with vulnerability intelligence.
  • Use VulnCheck data and products to identify detection and investigation gaps and help drive improvements.
  • Help shape the direction, methodology, and capabilities of VulnCheck's threat hunting function.
View Full Description & ApplyYou'll be redirected to the employer's site
View details
Apply Now