Senior Detection Engineer & Threat Hunter (Remote)

Linuxconfig

Northern (KY)

Hybrid

USD 150,000 - 170,000

Full time

8 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

100% remote work
Paid time off
Parental leave
Medical benefits
401(k)
Stock options
Home office stipend
Education assistance
AI tools access

Job summary

Huntress, a remote‑first cybersecurity company, is seeking a Senior Detection Engineering and Threat Hunting Analyst to join our DE&TH team. You will turn threat intelligence into detections that help the SOC identify intrusions quickly while collaborating with engineering and adjacent teams.

Work involves designing scalable detection portfolios, hunting at scale across millions of endpoints, and using AI tools to prototype queries.

Qualifications

  • 2+ years of experience in detection engineering, threat hunting, SOC, MDR, or incident response.
  • Intermediate knowledge of Windows internals.
  • Working knowledge of Linux, macOS, Microsoft 365, Azure, and Google Workspace.
  • Experience developing, testing, tuning, and documenting detections or analytics from threat intelligence, IOCs, hypotheses, or real‑world investigations.
  • Ability to communicate findings through clear written reports.
  • Strong familiarity with detection languages such as Sigma, Suricata, Snort, or YARA, and query languages such as KQL, EQL, ES|QL, or Splunk SPL.
  • A sound understanding of adversary tradecraft, including techniques used for persistence, privilege escalation, defense impairment, lateral movement, discovery, and collection on a system.
  • A sound understanding of the roles different threat actors play and their associated goals, such as initial access brokers, ransomware affiliates, and state‑sponsored entities.
  • Ability to orchestrate reusable AI workflows that improve threat hunting, detection development, or analysis, and can verify AI‑generated outputs before they reach production environments.

Responsibilities

  • Contribute to all parts of the detection lifecycle by creating new rules, testing them before deployment, monitoring efficacy, and tuning, promoting, or retiring rules based on their performance.
  • Develop rules across a variety of Huntress products and operating systems, including Identity Threat Detection and Response (ITDR), SIEM, Endpoint Detection and Response (EDR), Windows, Linux, and macOS.
  • Manage any DE&TH requests raised internally or escalated from our partners.
  • Undertake hypothesis‑driven hunts across Huntress telemetry, prioritizing techniques and tradecraft that may evade high‑fidelity detections and initial SOC review.
  • Consume threat intelligence and translate IOCs, TTPs, and internal findings into new or refined detections through Git‑based workflows.
  • Build and refine hunting dashboards or queries required to surface potential intrusions.
  • Review ambiguous signs of attacker activity across Huntress products, and surface likely intrusions that require deeper investigation.
  • Investigate or elevate likely intrusions identified to ensure partners receive clear incident reports with accurate advice.
  • Contribute findings to community‑driven projects and create Huntress content such as blogs, social posts, videos, podcasts, and webinars.
  • Use AI‑assisted workflows to prototype queries, enrich analysis, and develop a scaffolding for detection rules, ensuring you apply sound judgment to validate the AI output. We expect everyone at Huntress to be able to use AI as a real part of how they work, not occasionally, but genuinely embedded in core workflows.

Skills

Detection engineering
Threat hunting
SOC
IOCs
Sigma
Suricata
YARA
KQL
AI workflows
Windows internals

Tools

OSquery
Velociraptor
EDR/MDR/XDR platforms
Git

Job description

Huntress, a remote‑first cybersecurity company, is seeking a Senior Detection Engineering and Threat Hunting Analyst to join our DE&TH team. You will turn threat intelligence into detections that help the SOC identify intrusions quickly while collaborating with engineering and adjacent teams.

Work involves designing scalable detection portfolios, hunting at scale across millions of endpoints, and using AI tools to prototype queries.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Remote Senior Detection & Threat Hunting Engineer
Remote Senior Detection & Threat Hunting Engineer

Huntress • United States

Remote
USD 150,000 - 170,000
Remote work
Paid time off
Parental leave
+7
Senior Detection Engineering & Threat Hunting Analyst
Senior Detection Engineering & Threat Hunting Analyst

Huntress • United States

Remote
USD 150,000 - 170,000
Remote work
Paid time off
Parental leave
+7
Senior Detection Engineering & Threat Hunting Analyst
Senior Detection Engineering & Threat Hunting Analyst

Linuxconfig • Northern (KY)

Hybrid
USD 150,000 - 170,000
100% remote work
Paid time off
Parental leave
+6
Remote Senior Threat Response Lead
Remote Senior Threat Response Lead

Huntress • Northern (KY)

Hybrid
USD 125,000 - 135,000
Remote work
Paid time off
Parental leave
+2
Senior Incident Response & Threat Hunt Lead (Remote)
Senior Incident Response & Threat Hunt Lead (Remote)

Huntress • United States

Remote
USD 125,000 - 135,000
Remote work environment
Paid time off
Parental leave
+4
Staff Software Engineer, Detection Platform - Remote US
Staff Software Engineer, Detection Platform - Remote US

Engg • United States

On-site
USD 200,000 - 220,000
Remote Security Operations Analyst - Threat Hunting & IR
Remote Security Operations Analyst - Threat Hunting & IR

Huntress • Northern (KY)

Hybrid
USD 100,000 - 125,000
Remote work
Paid time off
12 weeks parental leave
+6
Senior Detection Engineer — Remote/Hybrid
Senior Detection Engineer — Remote/Hybrid

LinkedIn • United States

Hybrid
USD 129,000 - 212,000
Threat Hunter & Detection Engineer - Cyber Defense
Threat Hunter & Detection Engineer - Cyber Defense

Partner Forces LLC • Arlington (VA)

On-site
USD 110,000 - 140,000
Remote Threat Hunter: Detect & Dismantle Cyber Threats
Remote Threat Hunter: Detect & Dismantle Cyber Threats

UnitedHealth-Grou • Raleigh (NC)

On-site
USD 92,000 - 164,000