Lead Threat Hunter & Adversary Emulation Engineer

Elastic

Mountain View (CA)

Hybrid

USD 160,000 - 253,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health coverage
Flexible locations & schedules
Vacation days
Stock program
401k matching
Volunteer hours
Parental leave

Job summary

Elastic is seeking a Principal Threat Hunting and Emulation Engineer to lead structured, hypothesis-driven hunts across its cloud, SaaS, endpoint, and CI/CD environments. You will design adversary emulation exercises, validate detection pipelines, and build scalable threat-hunting programs with a focus on durable detections and hardened defenses.

You will leverage AI-assisted analysis and collaborate with Detection Engineering, Incident Response, and Threat Intelligence to translate hunting

Qualifications

  • Minimum 8 years in information security with threat hunting, detection engineering, incident response, or red/purple team roles.
  • Experience conducting structured, hypothesis-driven threat hunts in complex enterprise or cloud-native environments.
  • Familiarity with threat hunting frameworks such as PEAK, TaHiTI, Sqrrl; ability to apply at scale.
  • Experience designing adversary emulation exercises or purple team engagements.
  • Knowledge of MITRE ATT&CK and mapping threat intelligence to hunts.
  • Experience using AI-assisted tooling or large language models to support threat hunting workflows.
  • Scripting or coding ability to automate tasks.
  • Strong written communication; able to document findings for technical and executive audiences.
  • Eligible to work in DoD Impact Level 4+ cloud environments.

Responsibilities

  • Lead structured threat hunting operations across Elastic's environments using PEAK, TaHiTI, or equivalents.
  • Develop and maintain a scalable threat hunting program with hypotheses from threat intel and risk profiles.
  • Design adversary emulation exercises and purple team engagements to validate detections.
  • Build a library of reusable attack simulations with tools like Atomic Red Team, Caldera, Scythe.
  • Leverage AI/ML to accelerate hypothesis generation and anomaly detection.
  • Translate hunt findings into production-ready detections with Detection Engineering.
  • Document hunt methodologies, playbooks, and emulation plans for repeatability.
  • Collaborate with Threat Intelligence to inform hunt hypotheses based on emerging campaigns.

Skills

Threat hunting
Detection engineering
Incident response
Red/Purple teaming
Scripting
Communication skills

Tools

Atomic Red Team
Caldera
Scythe
Elastic Stack

Job description

Elastic is seeking a Principal Threat Hunting and Emulation Engineer to lead structured, hypothesis-driven hunts across its cloud, SaaS, endpoint, and CI/CD environments. You will design adversary emulation exercises, validate detection pipelines, and build scalable threat-hunting programs with a focus on durable detections and hardened defenses.

You will leverage AI-assisted analysis and collaborate with Detection Engineering, Incident Response, and Threat Intelligence to translate hunting

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Threat Hunting & Adversary Emulation Engineer
Lead Threat Hunting & Adversary Emulation Engineer

Elastic • United States

Remote
USD 160,000 - 253,000
Health coverage for you and family
Stock program and 401k matching
Generous vacation days
+1
Senior Threat Hunter & Adversary Emulation Lead
Senior Threat Hunter & Adversary Emulation Lead

Elasticsearch B.V. • United States

Hybrid
USD 160,000 - 253,000
Health coverage for you and family
Flexible locations and schedules
Generous vacation days
+1
Lead Threat Hunting & Adversary Emulation Engineer
Lead Threat Hunting & Adversary Emulation Engineer

Referral Board • United States

On-site
USD 160,000 - 253,000
Stock program
401k matching
Senior Threat Hunter & Adversary Emulation Architect
Senior Threat Hunter & Adversary Emulation Architect

Neura Market • Northern (KY)

Hybrid
USD 160,000 - 253,000
Stock program
401k with company match
Flexible locations & schedules
+3
Senior Threat Hunt Engineer - Hybrid, AI-Driven Detections
Senior Threat Hunt Engineer - Hybrid, AI-Driven Detections

Northwestern Mutual • Milwaukee (WI)

Hybrid
USD 118,000 - 179,000
Flexible work schedules
Concierge service
Comprehensive benefits
+1
Lead Purple Team Engineer: Cloud Security & Emulation
Lead Purple Team Engineer: Cloud Security & Emulation

TENEX.AI • Missouri

On-site
USD 140,000 - 190,000
Competitive salary
Benefits package
Growth opportunities
Senior Adversary Emulation Engineer
Senior Adversary Emulation Engineer

Relha LLC • Philadelphia

On-site
USD 140,000 - 200,000
Senior Cyber Threat Hunter & ATT&CK Lead
Senior Cyber Threat Hunter & ATT&CK Lead

ECS • Richmond (VA)

On-site
USD 165,000 - 185,000
Lead Threat Hunting & Defense Strategist
Lead Threat Hunting & Defense Strategist

Prudential Annuities Distributors (PAD) • Newark (NJ)

On-site
USD 123,700 - 204,100
Yearly bonus potential
Medical, dental, and vision insurance
401(k) plan with company match
+2
Principal Threat Hunting and Emulation Engineer - InfoSec
Principal Threat Hunting and Emulation Engineer - InfoSec

Elastic • Mountain View (CA)

Hybrid
USD 160,000 - 253,000
Health coverage
Flexible locations & schedules
Vacation days
+4