Назад
Company hidden
5 дней назад

Cyber Threat Hunter

80 000 - 110 000$
Формат работы
remote (только USA)/hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Cyber Threat Hunter (Cybersecurity): Running proactive, hypothesis-driven hunts across endpoint, identity, cloud, and network telemetry with an accent on threat intelligence, adversary tradecraft, and detection gaps. Focus on mapping findings to MITRE ATT&CK, building durable detection packages, validating security-posture gaps, and documenting long-horizon investigations.

Location: Remote work is available only in the USA for residents of CA, CO, CT, FL, GA, IL, KS, MA, MD, ME, NJ, NC, NY, OH, OR, TN, TX, VA, and WA. Hybrid work is available from offices in Austin, Texas, or Tampa, Florida. Onsite interviews may be required. Chicago city residents are not eligible unless they reside outside the city proper or are willing to self-relocate.

Base salary: $80,000–$110,000 per year for roles based in California, Colorado, Maryland, New Jersey, Washington, or New York.

Company

hirify.global provides a unified IT operations platform for endpoint management, patching, backup, and remote access, serving nearly 40,000 customers in more than 140 countries.

What you will do

  • Plan and run intelligence-led, TTP-led, and behavior-led hunts across endpoint, identity, cloud, and network telemetry.
  • Use CTI and red-team or purple-team findings to prioritize hunts against relevant adversary behaviors.
  • Map hunts and findings to MITRE ATT&CK to track coverage and identify blind spots.
  • Translate findings into detection logic, enrichment requirements, SOP guidance, and operational detection packages.
  • Partner with red-team resources to validate configuration faults and security-posture gaps.
  • Document hypotheses, methods, outcomes, and threat context for reusable hunting and incident-response artifacts.

Requirements

  • 5+ years in security operations, detection engineering, cyber threat intelligence, or incident response with hands-on threat-hunting experience.
  • Experience running hypothesis-driven hunts from formulation through telemetry analysis and conclusion.
  • Strong knowledge of adversary tactics, techniques, procedures, and the MITRE ATT&CK framework.
  • Proficiency querying and pivoting across SIEM and/or EDR/XDR telemetry using KQL, SPL, or equivalent query languages.
  • Understanding of endpoint, identity, cloud, and network telemetry, detection lifecycles, and signal-to-noise quality.
  • Must be a U.S. citizen or lawful permanent resident; visa sponsorship is not available.

Nice to have

  • Red-team or purple-team experience, detection-as-code workflows, or version-controlled detection content.
  • Python scripting for automation and enrichment.
  • Cloud-native and SaaS telemetry experience, including CloudTrail, Entra ID/Azure AD, and SaaS audit logs.
  • Experience with threat intelligence platforms, structured intelligence workflows, or incident-response teams.
  • Relevant GIAC, OSCP, or cloud security certifications.

Culture & Benefits

  • Collaborative, kind, and curious working environment.
  • Full-time hybrid-remote work with flexibility.
  • Medical, dental, and vision insurance.
  • 401(k), life insurance, PTO, and unlimited vacation.
  • Opportunities for growth and advancement.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →