Endpoint Threat Hunting Consultant

Jobgether

United States

Remote

USD 115,000 - 160,000

Full time

7 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Fully remote in US
Base salary plus equity
Health insurance
401(k)

Job summary

Jobgether seeks an Endpoint Threat Hunting Consultant based in the United States for a fully remote role focused on proactively identifying sophisticated cyber threats across enterprise environments.

You will investigate historical and active adversary activity by analyzing endpoint data, logs, system artifacts, and threat intelligence, translating findings into actionable remediation for technical teams, executives, and legal stakeholders.

Qualifications

  • Experience in threat hunting, cybersecurity investigations, digital forensics, threat analysis, or related discipline.
  • Strong knowledge of Windows and Linux OS, file systems, registry, memory management, and processes.
  • Knowledge of threat analysis methodologies, IOC searching, correlation, pivots, and timelines.
  • Understanding of targeted attack techniques and adversary tradecraft in eCrime and nation-state activities.
  • Ability to use threat intelligence to develop targeted searches for indicators of compromise.

Responsibilities

  • Conduct proactive threat hunting across enterprise environments, analyzing logs and endpoint telemetry for indicators of adversary activity.
  • Investigate Windows and Linux forensic artifacts including execution, persistence, file systems, logs, processes.
  • Perform hypothesis-driven threat analysis using IOC searches, correlation, pivots, and timelines.
  • Apply threat intelligence to identify relevant IOC and adversary tradecraft.
  • Produce clear reports and remediation recommendations for technical and legal stakeholders.
  • Develop and refine threat hunting methodologies, search queries, and supporting scripts.

Skills

Threat Hunting
Digital Forensics
Threat Analysis
Windows/Linux
Python Scripting
Threat Intelligence
Incident Response
AI in Security
Cloud Platforms
Communication

Education

Bachelor's or Master's in CS/Engineering/Security
Relevant experience in lieu of a degree

Tools

Active Directory
Python
SIEM
Threat Intel Platforms

Job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Endpoint Threat Hunting Consultant based in United States.

This fully remote role focuses on proactively identifying sophisticated cyber threats across enterprise environments.

You will investigate historical and active adversary activity by analyzing endpoint data, logs, system artifacts, and threat intelligence.

The role combines digital forensics, threat hunting, intelligence analysis, scripting, and security research to uncover meaningful indicators of compromise.

You will translate complex technical findings into actionable remediation recommendations for technical teams, executives, and legal stakeholders.

The position also contributes to the evolution of threat hunting methodologies, research practices, and automation capabilities.

You’ll work in a highly technical cybersecurity environment focused on protecting organizations from advanced criminal and nation-state threats.

The role offers substantial autonomy, remote flexibility, and opportunities to apply AI technologies to improve security workflows and decision-making.

Accountabilities
  • Conduct proactive threat hunting across enterprise environments, analyzing logs, endpoint telemetry, and system artifacts for evidence of historical or active adversary activity.
  • Investigate Windows and Linux forensic artifacts, including program execution, persistence mechanisms, file systems, event logs, processes, and other indicators of suspicious activity.
  • Perform hypothesis-driven threat analysis using IOC searches, correlation, long-tail analysis, investigative pivots, and timeline development.
  • Apply threat intelligence related to targeted attacks, eCrime, and nation-state activity to identify relevant indicators and adversary tradecraft.
  • Produce clear, high-quality written reports, presentations, findings, and remediation recommendations for technical stakeholders, management, and legal counsel.
  • Develop and refine threat hunting methodologies, research approaches, search queries, and supporting scripts.
  • Create practical automation and scripting solutions using Python or other scripting languages to improve investigative efficiency.
  • Analyze endpoint, identity, operating system, and network activity to identify patterns associated with compromise or malicious behavior.
  • Contribute to customized tactical and strategic remediation recommendations for organizations affected by targeted attacks.
  • Apply AI technologies to enhance investigative decision-making, streamline workflows, improve efficiency, and support security outcomes.
  • Collaborate with clients and internal stakeholders to communicate findings, explain technical risks, and support appropriate remediation strategies.
  • Where applicable, contribute expertise to large-scale incident response investigations involving sophisticated cybercriminal or nation-state actors.
Requirements
  • Demonstrated experience in threat hunting, cybersecurity investigations, digital forensics, threat analysis, or a closely related discipline.
  • Strong understanding of Windows and Linux operating systems, including file systems, registry, memory management, kernel and user-mode functions, identity, and process handling.
  • Solid knowledge of threat analysis methodologies, including hypothesis-driven investigations, IOC searching, correlation, pivoting, anomaly detection, and threat activity timelines.
  • Understanding of targeted attack techniques and adversary tradecraft associated with eCrime and nation-state actors.
  • Ability to use threat intelligence to develop targeted searches and identify relevant indicators of compromise.
  • Programming or scripting experience, particularly the ability to create search queries and develop practical scripts using Python or another scripting language.
  • Practical understanding of network protocols and how data is transmitted and processed across the layers of the OSI model.
  • Familiarity with identity and authentication concepts, including Active Directory and protocols such as Kerberos.
  • Strong written and verbal communication skills, with the ability to present complex investigative findings to technical, executive, and legal audiences.
  • Demonstrated experience using AI technologies to improve decision-making, workflows, processes, or operational efficiency.
  • Experience with incident response and large-scale investigations involving sophisticated adversaries is beneficial.
  • Familiarity with one or more major cloud platforms, such as AWS, Azure, or Google Cloud Platform, is advantageous.
  • Experience developing tactical and strategic remediation plans for compromised environments is preferred.
  • Bachelor's or master's degree in Computer Science, Computer Engineering, Mathematics, Information Security, Cybersecurity, Intelligence Studies, or a related discipline is preferred. Relevant professional experience and/or training may be considered in lieu of a degree.
  • Strong analytical thinking, curiosity, self-direction, and ability to operate effectively in complex and evolving cybersecurity environments.
Benefits
  • Fully remote position within the United States.
  • Base salary range of $115,000--$160,000 per year, depending on experience, skills, certifications, job level, and location.
  • Eligibility for bonuses and equity grants.
  • Comprehensive health insurance and benefits.
  • 401(k) retirement plan.
  • Paid time off and competitive vacation policies.
  • Paid parental and adoption leave.
  • Physical and mental wellness programs.
  • Professional development opportunities across career levels and roles.
  • Employee networks, geographic communities, and volunteer opportunities.
  • Opportunity to work on advanced threat hunting and cybersecurity challenges.
  • Collaborative environment focused on innovation, responsible use of AI, and continuous learning.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Detection Engineer/Threat Hunter
Detection Engineer/Threat Hunter

Partner Forces LLC • Arlington (VA)

On-site
USD 110,000 - 140,000
Sr. Threat Hunter
Sr. Threat Hunter

SentinelOne • United States

On-site
USD 108,000 - 130,000
Restricted Stock Units (RSUs)
Employee Stock Purchase Plan (ESPP)
Home office allowance
+1
Detection Engineer/Threat Hunter
Detection Engineer/Threat Hunter

Partner Forces • Arlington (VA)

On-site
USD 120,000 - 160,000
Threat Hunting Engineer
Threat Hunting Engineer

RK Management Consultants, Inc. • Milwaukee (WI)

On-site
USD 70,000 - 90,000
Senior Incident Responder / Threat Hunter
Senior Incident Responder / Threat Hunter

ShorePoint, LLC • Albuquerque (NM)

On-site
USD 140,000 - 170,000
144 hours PTO
11 holidays
Health insurance
+2
Senior Threat Hunter
Senior Threat Hunter

SentinelOne • United States

On-site
USD 140,000 - 210,000
Medical cover
Assistance program
Gym reimbursement
+7
Threat Detection Analyst (Expert)
Threat Detection Analyst (Expert)

Huntington Bancshares, Inc. • Columbus (OH)

On-site
USD 70,000 - 140,000
Senior Threat Hunter
Senior Threat Hunter

Peraton • Chandler (AZ)

On-site
USD 104,000 - 166,000
Senior Cybersecurity Threat Hunter III
Senior Cybersecurity Threat Hunter III

Invictus International Consulting, LLC • Colorado Springs (CO)

On-site
USD 158,000 - 193,000
Senior Tactical Response Analyst
Senior Tactical Response Analyst

Huntress • Northern (KY)

Hybrid
USD 125,000 - 135,000
Remote work
Paid time off
Parental leave
+2