Назад
Company hidden
2 дня назад

Senior Detection Engineering & Threat Hunting Analyst (Cybersecurity)

150 000 - 170 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Detection Engineering & Threat Hunting Analyst (Cybersecurity): Building and maintaining scalable, high-fidelity detections and conducting hypothesis-driven hunts across identity, endpoint, and security telemetry with an accent on threat intelligence, adversary tradecraft, and AI-assisted analysis. Focus on detecting stealthy intrusions across millions of endpoints, tuning false positives and false negatives, and translating IOCs and TTPs into production-ready rules.

Location: Remote US

Salary: $150,000–$170,000 base plus bonus and equity

Company

hirify.global builds cybersecurity technology backed by a 24/7 human-led Security Operations Center to protect businesses and service providers from cyber threats.

What you will do

  • Create, test, monitor, tune, promote, and retire detection rules across ITDR, SIEM, EDR, Windows, Linux, and macOS.
  • Conduct hypothesis-driven threat hunts across telemetry from millions of endpoints to identify stealthy attacker techniques.
  • Translate threat intelligence, IOCs, TTPs, and investigation findings into detections through Git-based workflows.
  • Build hunting dashboards and queries, review ambiguous attacker activity, and escalate likely intrusions for deeper investigation.
  • Collaborate with engineering, the SOC, and adjacent teams to maintain a scalable, high-fidelity detection portfolio.
  • Contribute findings to community projects and create technical content such as blogs, videos, podcasts, and webinars.

Requirements

  • 2+ years of experience in detection engineering, threat hunting, SOC, MDR, or incident response.
  • Intermediate knowledge of Windows internals and working knowledge of Linux, macOS, Microsoft 365, Azure, and Google Workspace.
  • Experience developing, testing, tuning, and documenting detections or analytics from threat intelligence, hypotheses, or investigations.
  • Familiarity with Sigma, Suricata, Snort, YARA, KQL, EQL, ES|QL, or Splunk SPL.
  • Understanding of adversary tradecraft, including persistence, privilege escalation, defense impairment, lateral movement, discovery, and collection.
  • Ability to validate AI-generated outputs and communicate findings through clear written reports.

Nice to have

  • Intermediate knowledge of Linux and macOS internals.
  • Experience with OSquery, Velociraptor, or EDR/MDR/XDR platforms.
  • Experience with endpoint forensic tools such as EZ Tools, RegRipper, Hayabusa, or Chainsaw.
  • Intermediate malware analysis skills.

Culture & Benefits

  • 100% remote work environment.
  • Paid vacation, sick time, holidays, and 12 weeks of paid parental leave.
  • Medical, dental, vision, life, and disability insurance plans.
  • 401(k) with a 5% contribution regardless of employee contribution.
  • Stock options for all full-time employees.
  • Home office reimbursement, monthly digital reimbursement, education assistance, and access to BetterUp coaching.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →