Cyber Threat Hunter

Jobvite, Inc.

Austin, Tampa (TX, FL)

Hybrid

USD 90,000 - 120,000

Full time

6 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Medical Insurance
Dental Insurance
Vision Insurance
401(k) Plan
Unlimited PTO
Growth Opportunities

Job summary

NinjaOne is seeking a Threat Hunter to join the Cyber Threat Intelligence function and drive proactive, hypothesis-led hunts across our environment. You’ll translate intelligence into durable detections and detection packages for operationalization by the tooling team and consumption by the SOC.

In this role you will surf across endpoint, identity, cloud, and network telemetry, map hunts to MITRE ATT&CK, and communicate findings with clear documentation.

Qualifications

  • 5+ years in a security operations, detection engineering, CTI, or incident response role with meaningful hands-on threat-hunting responsibility.
  • Demonstrated experience running hypothesis-driven hunts, testing against telemetry, and concluding outcomes, not just triage.
  • Strong working knowledge of adversary TTPs and practical fluency with the MITRE ATT&CK framework.
  • Proficiency querying and pivoting across security telemetry at scale in a SIEM/EDR/XDR (KQL, SPL, or equivalent).
  • Solid understanding of endpoint, identity, cloud, and network telemetry and normal vs. abnormal patterns.
  • Ability to turn a hunt finding into a detection recommendation with context and fidelity considerations.
  • Understanding of the detection lifecycle and the importance of signal-to-noise quality for SOC.
  • Clear written communication for documentation, detection packages, and SOPs.
  • Plan and sustain long-horizon hunt campaigns with limited day-to-day direction.

Responsibilities

  • Plan and run hypothesis-driven hunts across endpoint, identity, cloud, and network telemetry.
  • Consume CTI and red-team findings to prioritize hunts against relevant adversary behaviors.
  • Map hunts to MITRE ATT&CK to track coverage and identify gaps.
  • Translate hunt findings into detection packages and SOP guidance for tooling teams.
  • Partner with red teamers on purple validation of configuration faults and gaps.
  • Surface posture gaps discovered during hunts and drive remediation actions.
  • Document hypotheses, methods, and outcomes for reusable hunting knowledge.
  • Contribute threat context during Sev 1 incidents in an advisory capacity.
  • Other duties as needed.

Skills

Adversary mindset
Patience and persistence
Analytical thinking
Detections documentation
Effective communication
Curiosity

Tools

KQL
SPL
Python

Job description

About the Role

We are looking for a Threat Hunter to join our Cyber Threat Intelligence function and run proactive, hypothesis-driven hunts across our environment. This is a dedicated hunting role at the front of a detection pipeline: you will turn intelligence and adversary tradecraft into concrete hunts and turn what you find into detection packages that our tooling team operationalizes and our SOC consumes as tuned, documented alerts.

You will sit at the intersection of threat intelligence, detection engineering, and offensive validation. Working from CTI and from our red teamer's findings, you will hunt for activity that never trips an existing alert, novel techniques, living-off-the-land tradecraft, misconfiguration abuse, and long-dwell intrusions, and close those gaps by feeding durable detections and configuration fixes back into the organization. It is a role for a curious, methodical hunter who is energized by long-horizon investigation rather than the pace of the alert queue.

Location: We are flexible on remote working from home, if you are located in the USA and reside in one of the following states: CA, CO, CT, FL, GA, *IL, KS, MA, MD, ME, NJ, NC, NY, OH, OR, TN, TX, VA, and WA. We have physical offices in Austin, TX and Tampa, FL, if you prefer a hybrid option.

*Onsite interviews may be required for this role.

What You'll Be Doing
  • Plan and run hypothesis-driven hunts (intel-led, TTP-led, and behavior-led) across endpoint, identity, cloud, and network telemetry
  • Consume CTI and red-team/purple-team findings to prioritize hunts against the adversary behaviors most relevant to us
  • Map hunts and findings to MITRE ATT&CK to track coverage and expose blind spots
  • Translate hunt findings into detection packages and recommendations, including detection logic, required context and enrichment, and draft SOP guidance, for the tooling team to operationalize
  • Partner with the red teamer on purple validation of configuration faults and security-posture gaps
  • Surface configuration faults and posture gaps discovered during hunts, and drive recommendations to close them
  • Document hypotheses, methods, and outcomes so hunting knowledge lives in reusable artifacts rather than in one person's head
  • Contribute threat context and hunt-derived intelligence during declared Sev 1 incidents, in an advisory (non-primary) capacity
  • Other duties as needed
Required Qualifications
  • 5+ years in a security operations, detection engineering, CTI, or incident response role, with meaningful hands-on threat-hunting responsibility
  • Demonstrated experience running hypothesis-driven hunts, forming a hypothesis, testing it against telemetry, and driving it to a conclusion, not solely alert triage
  • Strong working knowledge of adversary tactics, techniques, and procedures, and practical fluency with the MITRE ATT&CK framework
  • Proficiency querying and pivoting across security telemetry at scale in a SIEM and/or EDR/XDR (e.g., KQL, SPL, or equivalent query languages)
  • Solid understanding of endpoint, identity, cloud, and network telemetry, and a sense of what normal and abnormal look like in each
  • Ability to turn a hunt finding into a detection recommendation, including logic, supporting context, and fidelity/signal-to-noise considerations
  • Understanding of the detection lifecycle and why signal-to-noise quality matters to a SOC
  • Clear written communication for documentation, detection packages, and SOP recommendations
  • Able to plan and sustain long-horizon hunt campaigns with limited day-to-day direction
Preferred Qualifications
  • Experience consuming red-team or purple-team output to drive and prioritize hunts
  • Scripting for automation and enrichment (Python preferred)
  • Familiarity with detection-as-code workflows and version-controlled detection content
  • Depth in cloud-native and SaaS telemetry (CloudTrail, Entra ID/Azure AD, SaaS audit logs)
  • Experience with a threat intelligence platform (TIP) and structured intel workflows
  • Exposure to an IR-capable or standing-response team environment
  • Relevant certifications, one or more (preferred, not required):
    • GCTI, GCFA, GCDA, GCIA, or similar GIAC certifications
    • OSCP or comparable (for offensive-tradecraft awareness)
    • Cloud security certifications (AWS, Azure, or GCP), or equivalent
Key Skills
  • Adversary mindset, thinks in behaviors and TTPs, not indicators alone
  • Patience and persistence for long-horizon threads that may not pay off immediately
  • Strong analytical and data-pivoting skills across large, varied datasets
  • Translates findings into durable, reusable detections and clear documentation
  • Communicates effectively across CTI, tooling, and SOC audiences
  • Curiosity and a genuine drive to find what existing alerting misses
About Us

NinjaOne unifies IT to simplify work for nearly 40,000 customers in 140+ countries. The NinjaOne Unified IT Operations Platform delivers endpoint management, autonomous patching, backup, and remote access in a single console to improve efficiency, increase resilience, and reduce spend. By automating IT and managing all endpoints, organizations give employees a great technology experience at work. NinjaOne is obsessed with customer success and has retained a 98% customer satisfaction score for more than 5 years.

What You'll Love
  • A collaborative, kind, and curious community
  • Full-time work that is hybrid remote, honoring your flexibility needs
  • A comprehensive benefits package, including medical, dental, and vision insurance
  • A 401(k) plan to help you prepare for your financial future
  • Unlimited PTO that prioritizes your work-life balance
  • Opportunity for growth and advancement
Additional Information

This position is NOT eligible for Visa sponsorship. Due to federal government security requirements associated with our FedRAMP-authorized environment, candidates must be U.S. citizens or lawful permanent residents.

Due to operational policies, NinjaOne is unable to hire for this role within the city limits of Chicago. We will consider all qualified candidates who reside outside of the city proper or are willing to self-relocate.

Starting pay for the successful applicant depends on a variety of job-related factors, including but not limited to location, market demands, experience, job-related knowledge, and skills. The benefits available for this position include medical, dental, vision, 401(k) plan, life insurance coverage, and PTO. For roles based in California, Colorado, Maryland, New Jersey, or Washington, the base salary hiring range for this position is $80,000 to $110,000 per year.

For roles based in New York, the base salary hiring range for this position is $80,000 to $110,000 per year.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, genetic information, marital status, veteran status, or any other status protected by applicable law. We are committed to providing an inclusive and diverse work environment.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Threat Hunter
Cyber Threat Hunter

Jobvite, Inc. • United States

On-site
USD 80,000 - 110,000
Hybrid remote work
Medical, dental, and vision insurance
401(k) plan
+2
Senior Software Engineer | Application Security Engineering
Senior Software Engineer | Application Security Engineering

NinjaOne • Austin (TX)

Hybrid
USD 170,000 - 230,000
Medical, dental, and vision insurance
401(k) plan
Unlimited PTO
+1
Senior Software Engineer | AI Security Engineering
Senior Software Engineer | AI Security Engineering

Jobvite, Inc. • Austin (TX), Tampa (FL)

Hybrid
USD 170,000 - 230,000
Medical, dental, and vision insurance
401(k) plan
Unlimited PTO
+1
Penetration Tester
Penetration Tester

Jobvite, Inc. • United States

Hybrid
USD 130,000 - 165,000
Medical, dental, vision
401(k) retirement plan
Unlimited PTO
+1
Senior Software Engineer | AI Security Engineering
Senior Software Engineer | AI Security Engineering

NinjaOne • Town of Florida (NY)

Hybrid
USD 170,000 - 230,000
Medical, dental, vision
401(k) plan
Unlimited PTO
+2
Senior Software Engineer | AI Security Engineering
Senior Software Engineer | AI Security Engineering

NinjaOne • Georgia

Hybrid
USD 170,000 - 230,000
Health insurance
401(k) plan
Unlimited PTO
+1
Penetration Tester
Penetration Tester

Jobvite, Inc. • Austin (TX)

Hybrid
USD 130,000 - 165,000
Medical, dental, vision insurance
401(k) plan
Unlimited PTO
+1
Senior Software Engineer | AI Security Engineering
Senior Software Engineer | AI Security Engineering

NinjaOne • California (MO)

Hybrid
USD 170,000 - 230,000
Medical, dental, and vision insurance
401(k) plan
Unlimited PTO
Senior Software Engineer | AI Security Engineering
Senior Software Engineer | AI Security Engineering

NinjaOne • North Carolina

Hybrid
USD 140,000 - 230,000
Hybrid remote
Medical, dental, and vision insurance
401(k) plan
+1
Principal DevOps Engineer, Continuous Delivery
Principal DevOps Engineer, Continuous Delivery

NinjaOne • Maine

Hybrid
USD 200,000 - 260,000
Medical, dental, vision
401(k) plan
Unlimited PTO
+1