Principal Threat Hunting And Emulation Engineer - InfoSec (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Principal Threat Hunting And Emulation Engineer - InfoSec (Cybersecurity): Building and scaling proactive threat-hunting and adversary-emulation capabilities across cloud, SaaS, endpoint, and CI/CD environments with an accent on hypothesis-driven hunts, detection validation, and AI-assisted analysis. Focus on simulating real-world attacker techniques, closing visibility gaps, translating findings into durable detections, and supporting complex incident investigations.
Location: United States. Eligibility to work in Department of Defense Impact Level 4 or above cloud service environments is required. Export-control licensing requirements may apply to individuals located in or nationals of certain sanctioned countries and regions.
Salary: $159,800–$252,800 USD base salary. In select locations, including Seattle, Los Angeles, the San Francisco Bay Area, and the New York City Metro Area, the range is $191,900–$303,500 USD.
Company
develops the Search AI Platform and cloud-based search, security, and observability solutions.
What you will do
- Lead structured, hypothesis-driven threat hunts across cloud, SaaS, endpoint, and CI/CD environments.
- Develop and scale the threat-hunting program using threat intelligence, ATT&CK mappings, and environmental risk profiles.
- Design and execute adversary-emulation exercises and purple-team engagements to validate detection coverage.
- Build reusable attack simulations with Atomic Red Team, Caldera, Scythe, and custom tooling.
- Translate hunt findings into production-ready detections and identify log-source visibility gaps.
- Collaborate with Detection Engineering, Incident Response, Threat Intelligence, and Security Engineering on investigations and defensive improvements.
Requirements
- At least 8 years of information-security experience focused on threat hunting, detection engineering, incident response, or red/purple-team operations with the Stack.
- Experience conducting structured threat hunts and adversary-emulation exercises in complex enterprise or cloud-native environments.
- Knowledge of PEAK, TaHiTI, Sqrrl, MITRE ATT&CK, and real-world adversary tactics, techniques, and procedures.
- Experience using AI-assisted tooling or large language models for hypothesis generation, log summarization, or anomaly triage.
- Scripting or coding ability for automating hunt tasks and building custom tooling, plus strong technical documentation skills.
- Eligibility to work in Department of Defense Impact Level 4 or above cloud service environments.
Nice to have
- Experience across AWS, GCP, or Azure threat-hunting environments.
- Knowledge of CI/CD and developer supply-chain threats, including GitHub Actions and dependency confusion.
- Background spanning both detection engineering and incident response.
- Open-source threat-hunting contributions or public threat-research publications.
Culture & Benefits
- Distributed work environment with flexible locations and schedules for many roles.
- Competitive base pay and eligibility for ’s stock program.
- Health coverage for employees and families in many locations.
- Generous vacation allowance and at least 16 weeks of parental leave.
- Company-matched 401(k) contributions up to 6% of eligible earnings.
- Up to $2,000 in donation matching and 40 volunteer hours annually.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →