Remote job
Threat Hunter/Purple Team Operator
Job details
About this role
Role overview
Lead defensive security hunts before red team assessments, then work alongside defenders to improve their ability to detect and respond to adversary activity. The role combines independent analysis of endpoint, network, cloud, and identity data with on-site collaboration, clear reporting, and real-time validation of security controls.
Responsibilities
- Develop intelligence-led hunting hypotheses and investigate telemetry for suspicious behavior, indicators of compromise, and adversary techniques. - Correlate logs and alerts across security monitoring, endpoint, network, cloud, and identity sources; map findings to a common adversary behavior framework. - Record hunt methods, coverage, findings, and detection recommendations, escalating promptly if active compromise is suspected. - Summarize results and assess whether an environment is clear before a red team assessment begins. - Work with defensive teams during exercises to tune and validate detections against simulated adversary techniques. - Brief technical and nontechnical stakeholders, while maintaining confidentiality across red and blue team activity.
Requirements
- Around 3–5 or more years in threat hunting, security operations, detection engineering, incident response, or related defensive work. - Hands-on experience with a major security information and event management platform and an endpoint detection and response platform. - Working knowledge of adversary tactics and techniques, red team methods, and how to use them to identify detection gaps. - Ability to work independently in remote, customer-facing settings and communicate findings clearly in writing and verbally. - U.S. citizenship and eligibility to obtain and maintain a U.S. government security clearance; the position specifies an active Top Secret clearance with SCI eligibility.
Nice to have
- Experience in a purple team role or partnering directly with red teams; familiarity with network traffic analysis, cloud and identity logs, and hunting query or scripting languages. - Relevant security certifications, automation experience, or work across multiple customer environments.
Benefits and work setup
Full-time, primarily remote work with travel to customer sites and test locations as needed. Benefits listed include employer-paid medical, dental, vision, disability, and basic life coverage; a retirement plan with a 4% employer contribution; professional development reimbursement; and flexible paid time off and holidays.