← Back to jobs

Remote job

Senior OT Threat Hunter

Other Full-time Permanent United States

Job details

$140,000 Salary
United States Eligibility
Senior Experience
Full-time Employment

About this role

Role overview

A senior threat hunter focused on operational technology (OT) and industrial control system (ICS) environments. The role leads hypothesis-driven hunting missions, serves as the top escalation point for high-severity detections, and acts as a trusted advisor to customers during critical security incidents. Work is remote, highly collaborative with intelligence and engineering peers, and centered on protecting the industrial networks that underpin utilities, manufacturing, and other critical infrastructure.

Responsibilities

- Lead proactive, hypothesis-driven threat hunts across industrial control networks, partnering with intelligence and engineering teams to surface adversary activity and uncover attack patterns missed by automated tooling. - Serve as the senior escalation point for high-severity alerts, mentoring junior hunters and analysts and briefing customers directly on findings, remediation steps, and technical follow-ups. - Configure and tune an OT-focused detection platform along with customer-specific hunt profiles to increase true positives and reduce alert fatigue. - Author new hunting hypotheses and detection content grounded in real operational outcomes, and feed structured feedback back to detection engineering and intelligence teams to sharpen indicators and reports. - Investigate suspicious network behavior, validate what triggers alerts, and produce clear incident summaries and custom reports for both technical and non-technical audiences. - Build scripts and workflow tooling to make hunting more repeatable, while mentoring teammates on OT protocols, adversary tactics, and threat intelligence practices.

Requirements

- Demonstrated experience in hypothesis-based threat hunting, from reasoning over an intelligence source through to a tested hunt and successful investigation. - Hands-on background analyzing network telemetry and identifying behavioral anomalies, with a focus beyond purely endpoint-centric signals. - Strong grasp of core networking concepts such as TCP/IP, firewalls, DNS, and packet-level analysis. - Practical experience with PCAP analysis, IDS/IPS, SIEM platforms, or comparable network traffic analysis tools applied to OT environments. - Working knowledge of adversary tactics, techniques, and procedures relevant to OT, including MITRE ATT&CK for ICS. - Familiarity with threat intelligence workflows, including consumption and feedback loops with intelligence and detection engineering teams. - Proven ability to communicate complex security findings to clients and internal stakeholders, both verbally and in writing. - Prior experience acting as a senior contributor or technical escalation point in a security operations or threat hunting setting. - Experience working in ICS/OT environments is strongly preferred.

Benefits and work setup

- Remote-first role with team members distributed across multiple regions. - Base salary listed at $140,000, alongside a competitive equity package and a comprehensive benefits plan.

Skills detected in the listing

Stakeholder ManagementInformation Security
Detected Sep 11, 2026
Last verified Sep 11, 2026

Hidden Jobs Access

Unlock application links

Read the full job details for free. An active Hidden Jobs Access subscription is required to open the original application link.

Weekly

FREE $6.99/week after trial
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching
  • Cancel anytime before day 7

Monthly

$35.99 $17.99 /month
  • 35% cheaper than weekly
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching

Lifetime

$99.99 $49.99 /forever
  • One-time payment
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching
Hidden Jobs gives subscribers direct access to original application links
Offer ends in 00:00:00 Your profile-fit rate expires at midnight