← Back to jobs

Remote job

Threat Hunter/Purple Team Operator

Other Full-time Permanent Remote

Job details

Not specified Salary
Remote Eligibility
Mid level Experience
Full-time Employment

About this role

Role overview

Lead defensive security hunts before red team assessments, then work alongside defenders to improve their ability to detect and respond to adversary activity. The role combines independent analysis of endpoint, network, cloud, and identity data with on-site collaboration, clear reporting, and real-time validation of security controls.

Responsibilities

- Develop intelligence-led hunting hypotheses and investigate telemetry for suspicious behavior, indicators of compromise, and adversary techniques. - Correlate logs and alerts across security monitoring, endpoint, network, cloud, and identity sources; map findings to a common adversary behavior framework. - Record hunt methods, coverage, findings, and detection recommendations, escalating promptly if active compromise is suspected. - Summarize results and assess whether an environment is clear before a red team assessment begins. - Work with defensive teams during exercises to tune and validate detections against simulated adversary techniques. - Brief technical and nontechnical stakeholders, while maintaining confidentiality across red and blue team activity.

Requirements

- Around 3–5 or more years in threat hunting, security operations, detection engineering, incident response, or related defensive work. - Hands-on experience with a major security information and event management platform and an endpoint detection and response platform. - Working knowledge of adversary tactics and techniques, red team methods, and how to use them to identify detection gaps. - Ability to work independently in remote, customer-facing settings and communicate findings clearly in writing and verbally. - U.S. citizenship and eligibility to obtain and maintain a U.S. government security clearance; the position specifies an active Top Secret clearance with SCI eligibility.

Nice to have

- Experience in a purple team role or partnering directly with red teams; familiarity with network traffic analysis, cloud and identity logs, and hunting query or scripting languages. - Relevant security certifications, automation experience, or work across multiple customer environments.

Benefits and work setup

Full-time, primarily remote work with travel to customer sites and test locations as needed. Benefits listed include employer-paid medical, dental, vision, disability, and basic life coverage; a retirement plan with a 4% employer contribution; professional development reimbursement; and flexible paid time off and holidays.

Skills detected in the listing

TypeScriptPythonStakeholder ManagementInformation SecurityAWSAzure
Detected Oct 10, 2026
Last verified Not yet verified

Hidden Jobs Access

Unlock application links

Read the full job details for free. An active Hidden Jobs Access subscription is required to open the original application link.

Weekly

FREE $6.99/week after trial
  • Original application links
  • Daily or weekly job alerts
  • Premium filters and CV matching
  • Cancel anytime before day 7

Monthly

$35.99 $17.99 /month
  • 35% cheaper than weekly
  • Original application links
  • Daily or weekly job alerts
  • Premium filters and CV matching

Lifetime

$99.99 $49.99 /forever
  • One-time payment
  • Original application links
  • Daily or weekly job alerts
  • Premium filters and CV matching
Hidden Jobs gives subscribers direct access to original application links
Offer ends in 00:00:00 Your profile-fit rate expires at midnight