Remote job
Senior Detection Engineering & Threat Hunting Analyst
Job details
About this role
Role overview A senior security role on a Detection Engineering and Threat Hunting team that sits alongside a 24/7 Security Operations Center serving millions of endpoints worldwide. The position focuses on building high-fidelity detections, hunting for stealthy adversary activity, and turning threat intelligence and hypotheses into actionable signals that protect partner environments.
Responsibilities - Create, test, monitor, and tune detection rules across the full lifecycle, retiring or promoting rules based on efficacy. - Develop detections spanning ITDR, SIEM, and EDR products across Windows, Linux, and macOS environments. - Run hypothesis-driven threat hunts across large-scale telemetry, prioritizing techniques that may evade initial review. - Translate threat intelligence, IOCs, and TTPs into new or refined detections using Git-based workflows. - Build and refine hunting dashboards and queries that surface potential intrusions at scale. - Review ambiguous signs of attacker activity, escalate likely intrusions, and contribute to public-facing security content such as blogs, webinars, and podcasts. - Use AI-assisted workflows to prototype queries and accelerate detection development while validating outputs before production.
Requirements - 2+ years of experience in detection engineering, threat hunting, SOC, MDR, or incident response. - Intermediate knowledge of Windows internals and working knowledge of Linux, macOS, Microsoft 365, Azure, and Google Workspace. - Experience developing, testing, tuning, and documenting detections or analytics from threat intelligence, IOCs, hypotheses, or investigations. - Familiarity with detection languages such as Sigma, Suricata, Snort, or YARA, and query languages such as KQL, EQL, ES|QL, or Splunk SPL. - Sound understanding of adversary tradecraft across persistence, privilege escalation, defense evasion, lateral movement, discovery, and collection. - Clear written communication for incident reports, plus the ability to orchestrate reusable AI workflows and validate AI-generated outputs.
Nice to have - Intermediate Linux and macOS internals, hands-on experience with remote evidence-of-compromise tools such as OSquery, Velociraptor, and EDR/MDR/XDR platforms, and forensic tooling such as EZ Tools, RegRipper, Hayabusa, or Chainsaw.
Benefits and work setup - 100% remote work environment with a compensation range of $150,000 to $170,000 base plus bonus and equity. - Generous paid time off including vacation, sick time, and paid holidays, plus 12 weeks of paid parental leave. - Medical, dental, and vision benefits, 401(k) with employer contribution, life and disability insurance, and stock options for full-time employees. - $500 home office reimbursement, annual professional development allowance, $75/month digital reimbursement, and access to a coaching and growth platform.