Cybersecurity Threat Hunter - REMOTE

Totem Market Valuations

Houston (TX)

Hybrid

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental and vision coverage
401k match
Remote-friendly environment
Training opportunities

Job summary

Binary Defense is a leading Managed Detection and Response (MDR) provider seeking a Threat Hunter to join our Threat Hunting Team. The role requires translating threat actor techniques into hunting and detection logic across client environments, with hands-on analysis and written communication.

You will work across EDR and SIEM platforms (Microsoft Defender, Defender for Cloud, Sentinel, Splunk, CrowdStrike), develop original research from observed TTPs, and deliver weekly client deliverables

Qualifications

  • Hands-on experience hunting for threat actor activity using EDR and SIEM platforms (Microsoft Defender, Sentinel, Splunk, CrowdStrike).
  • Ability to build and tune hunting/detection queries in KQL and SPL.
  • Excellent written and verbal communication, with ability to explain findings to clients/teammates.
  • Understanding of threat actor techniques, defense evasion, and current threat landscape.
  • Experience turning threat intel into deployable hunt/detection logic.
  • Familiarity with malware analysis techniques and applying results.
  • Experience with Windows environments; familiarity across Linux/macOS.
  • Strong research, analytical, and problem-solving skills.

Responsibilities

  • Track emerging threat actor techniques from research and intel reports; assess relevance to client environments.
  • Develop original research from observed malware and TTPs; extract IOCs and detection opportunities.
  • Build and tune client-facing hunts as queries across EDR/SIEM platforms.
  • Communicate hunt findings, methodology, and recommendations to improve client security posture.
  • Perform static/dynamic malware analysis to understand behavior and evasion techniques.
  • Analyze telemetry, logs, and alerts across Windows, Linux, and macOS.
  • Collaborate with Threat Hunters and SOC analysts to support investigations.
  • Stay current on threat actor techniques and cybersecurity developments.
  • Mentor junior team members as you grow in the role.

Skills

Threat hunting
EDR/SIEM experience
KQL
SPL
Communication
Threat actor techniques
Malware analysis
Network traffic analysis
Windows/ Linux/ macOS
Scripting (PowerShell/Python)

Education

Associate's degree or 2+ years related experience
Bachelor's/Master's preferred

Tools

Microsoft Defender
Sentinel
Splunk
CrowdStrike
PowerShell
Python

Job description

Description

Binary Defense is seeking a Threat Hunter to join our Threat Hunting Team. This role is built for someone who can hit the ground running: tracking threat actor techniques as they break, turning that intelligence into original research, and building the hunts that surface those threats across client environments.

The Threat Hunter position requires an experienced, analytical person who understands the techniques threat actors use to compromise systems and evade detection. A successful candidate will study those techniques, translate them into hunting and detection logic across multiple SIEM and EDR platforms, and clearly communicate findings to clients. The work spans researching breaking threat intelligence, hands‑on analysis, detection engineering, and written communication, in a client‑facing environment.

Hunts are delivered across EDR and SIEM platforms including Microsoft Defender, Sentinel, Splunk, and CrowdStrike. Threat Hunters produce client deliverables each week, with opportunities to publish original research as blog posts and to present research at security conferences.

Responsibilities
  • Track emerging threat actor techniques from breaking research, threat intelligence reporting, and firsthand observation, and assess their relevance to client environments.
  • Develop original research from observed malware and threat actor TTPs, including extraction of indicators of compromise (IOCs) and detection opportunities.
  • Build and tune client‑facing threat hunts as queries across customer EDR and SIEM platforms
  • Serve as a technical point of contact for clients, clearly communicating hunt findings, methodology, and recommendations to improve their security posture.
  • Perform static and dynamic malware analysis to understand malicious behavior, execution flow, and common evasion techniques.
  • Analyze telemetry, logs, and alerts to identify suspicious behavior across Windows, Linux, and macOS.
  • Work closely with Threat Hunters and SOC analysts to support investigations and deliver technical findings.
  • Keep current on the latest threat actor techniques and cybersecurity developments relevant to defending client networks.
  • Support and mentor less experienced team members as you grow in the role.
Requirements
  • Hands‑on experience hunting for threat actor activity using EDR and/or SIEM platforms such as Microsoft Sentinel, Splunk, and CrowdStrike.
  • Ability to build and tune hunting and detection queries in platform‑native query languages (for example KQL and SPL).
  • Excellent written and verbal communication, with the ability to explain technical findings clearly to clients and teammates.
  • Working knowledge of threat actor techniques, defense evasion, and the current threat landscape.
  • Experience turning threat intelligence into deployable hunt and detection logic.
  • Familiarity with malware analysis techniques and the ability to interpret and apply results.
  • Network traffic analysis experience.
  • Experience with Windows environments, with working familiarity across Linux and macOS.
  • Strong research and technical analysis skills.
  • Well‑developed problem‑solving and interpersonal skills, strong organizational skills, and acute attention to detail.
  • Associate's degree (or 2 or more years hands‑on experience) in Computer Science, Information Security, Incident Response, Forensics, or a related field.
Preferred
  • Bachelor’s or master’s degree in computer science or Cybersecurity (or 4 or more years hands‑on experience).
  • 2 or more years of experience in threat hunting, detection engineering, incident response, or a SOC role.
  • Experience analyzing or de‑obfuscating scripts (PowerShell, VBA, JavaScript, .NET, and similar).
  • Scripting or programming experience (for example Python, PowerShell, or Bash) to support analysis and internal tooling.
  • Experience publishing original research through blog posts, public reporting, or conference talks.
  • Malware reverse engineering experience, both static and dynamic.
  • Digital forensics and incident response experience.
  • Experience mentoring other analysts.
About Binary Defense

Binary Defense is a leading Managed Detection and Response (MDR) provider, trusted by hundreds of organizations to protect what matters most. Our team of SOC analysts, threat hunters, detection engineers, and threat researchers work around the clock to deliver proactive, risk‑focused security outcomes. We bring the attacker's mindset to defense, helping clients detect threats earlier, respond faster, and continuously improve their security posture.

For more information, visit our website, check out our blog, or follow us on LinkedIn.

  • Competitive medical, dental and vision coverage for employees and dependents
  • 401k match which vests every payroll
  • Flexible and remote friendly work environment
  • Training opportunities to expand your skill set (to name a few!)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Threat Hunter - REMOTE
Cybersecurity Threat Hunter - REMOTE

Binary-Defense • Houston (TX)

Hybrid
USD 90,000 - 130,000
Remote-friendly environment
401(k) match
Training opportunities
Cybersecurity Threat Hunter - REMOTE
Cybersecurity Threat Hunter - REMOTE

Binary Defense • Houston (TX)

Hybrid
USD 95,000 - 150,000
Medical coverage
401k match
Remote-friendly
+1
Threat Hunter — Remote‑Friendly MDR Security Researcher
Threat Hunter — Remote‑Friendly MDR Security Researcher

Totem Market Valuations • Houston (TX)

Hybrid
USD 120,000 - 180,000
Medical, dental and vision coverage
401k match
Remote-friendly environment
+1
Remote Threat Hunter: Advanced Cyber Defense & Research
Remote Threat Hunter: Advanced Cyber Defense & Research

Binary Defense • Houston (TX)

Hybrid
USD 95,000 - 150,000
Medical coverage
401k match
Remote-friendly
+1
Detection Engineer - REMOTE
Detection Engineer - REMOTE

Binary Defense • Houston (TX)

On-site
USD 110,000 - 150,000
Remote-friendly work environment
Training opportunities
401k match
+1
Remote Threat Hunter: Hunt & Research Cyber Threats
Remote Threat Hunter: Hunt & Research Cyber Threats

Binary-Defense • Houston (TX)

Hybrid
USD 90,000 - 130,000
Remote-friendly environment
401(k) match
Training opportunities
Threat Hunt Analyst
Threat Hunt Analyst

Booz Allen Hamilton • Lakewood (CO)

On-site
USD 99,000 - 225,000
Comprehensive health benefits
Paid leave
Professional development
+1
Threat Hunt Analyst
Threat Hunt Analyst

Phase2 Technology • Colorado

On-site
USD 120,000 - 150,000
Tier 2 SOC Analyst - REMOTE
Tier 2 SOC Analyst - REMOTE

Binary Defense • Houston (TX)

Hybrid
USD 70,000 - 95,000
Medical, Dental, Vision
401k match
Remote-friendly work environment
+1
Threat Hunter
Threat Hunter

Ascent360 • Tampa (FL)

On-site
USD 80,000 - 120,000