Remote job
Threat Hunter
Job details
About this role
Role overview A remote, full-time opportunity for a principal-level threat hunter to lead proactive research into exploitation activity and attacker infrastructure. The role focuses on turning hands-on investigations into durable detection improvements and customer-facing intelligence, with substantial latitude to shape a newly formed function. It suits an independent researcher who can define their own areas of focus and build the tooling needed to support that work.
Responsibilities
- Hunt across internal datasets for novel exploitation, attacker infrastructure, and emerging attacker behavior - Investigate captured exploitation attempts, payloads, binaries, and post-exploitation activity using network and host telemetry - Build tooling, automation, and detection logic that supports large-scale analysis of attacker activity - Pivot across vulnerabilities, hosts, IPs, domains, and infrastructure to map relationships and broader campaigns - Produce written threat intelligence reports and technical blog posts explaining findings and their significance - Present research at industry conferences and external events - Collaborate with vulnerability researchers to connect observed exploitation with vulnerability intelligence - Identify gaps in current detection capabilities and help drive improvements to close them - Help define the methodology, direction, and operational shape of the threat hunting function as it grows
Requirements
- A substantial record of public security research, including blogs, reports, or presentations that have influenced the community - Hands-on experience with threat hunting, threat intelligence, exploitation research, or closely related security work - Working knowledge of networking and protocols, with the ability to read and reason about packet captures - Experience researching exploitation campaigns, malware families, or attacker infrastructure observed in the wild - Breadth across security disciplines such as vulnerability research, reverse engineering, malware analysis, or detection engineering - Strong programming or scripting ability across multiple languages, with comfort learning new ones as research demands - Experience with Linux systems and large datasets, including building queries or tooling to extract meaningful signal - Independence and judgment to pursue interesting questions without a predefined playbook
Nice to have
- Experience leading threat intelligence or security research initiatives, including setting direction, methodologies, or operational processes - Familiarity with internet-facing infrastructure, exposed services, and common attacker hosting patterns
Benefits and work setup
- Fully remote within the United States - Unlimited paid time off - 401(k) plan - Comprehensive healthcare coverage - Generous paid parental leave - Cell phone and internet expense reimbursement - Ongoing professional development, coaching, and learning resources - Flexible, remote-friendly working environment