Remote job
Senior Capabilities Hunter
Job details
About this role
Role overview This role focuses on adversary capability analysis targeting industrial control systems and operational technology networks. As a senior member of a threat hunt and research function, the position hunts for and analyzes the tools, techniques, and methodologies used by threat actors against critical infrastructure, building the analysis capability and tradecraft that inform detection strategies and customer advisories.
Responsibilities - Develop and maintain tools, scripts, and documentation for capability identification and analysis, working with threat hunt, research, intelligence, product, and engineering teams - Hunt for and analyze adversary capabilities across assigned threat groups, contributing to threat assessments, intelligence reporting, and customer-facing advisories - Apply analytical tooling such as NetFlow, Censys, VirusTotal, Joe Sandbox, and Shodan alongside query languages like Synapse and Storm to support tracking and investigation - Identify automation opportunities in analysis workflows and recommend solutions for telemetry or data-visibility gaps - Uphold engineering quality through robust code, testing frameworks, and independent debugging on complex defects - Represent the team externally through webinars, industry partnerships, and annual review initiatives - Provide hunting and triage support during surge events and incident response engagements
Requirements - 2–3 years of experience in capabilities development, threat hunting, network-based intrusion analysis, vulnerability analysis, and/or detections development - Software development experience in C#, Python, or similar languages - Familiarity with the Diamond Model, the full Kill Chain, and MITRE ATT&CK as analytic frameworks - Demonstrated knowledge of adversary threat groups, including their tactics, techniques, procedures, and lifecycle - Strong report-writing skills for both internal technical teams and external customer-facing audiences - Understanding of network analysis and common malware functionality and operations - Experience contributing to cross-functional projects with internal and external collaborators
Benefits and work setup - Base salary of $152,000, plus a competitive equity package and comprehensive benefits plan - Remote-first working model