Cyber Threat Hunter

Job not on LinkedIn

🔥 3 minutes ago

🏄 California, Colorado, +16 more states – Remote

infoinfo

💵 $80k - $110k / year

⏰ Full Time

🟡 Mid-level

🟠 Senior

🕵️ Threat Intelligence Specialist

🦅 H1B Visa Sponsor

infoinfo

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of NinjaOne

NinjaOne

1001 - 5000 employees

☁️ SaaS

🔒 Cybersecurity

🤝 B2B

SaaS • Cybersecurity • B2B

NinjaOne is an automated, cloud-native endpoint management platform that provides remote monitoring and management (RMM), patch management, mobile device management (MDM), backup, remote access, and unified reporting for MSPs and IT departments. The SaaS product uses a single lightweight agent and centralized console to manage Windows, macOS, Linux, servers, VMs, and mobile devices, and includes security-focused features (autonomous patching, encrypted backups, FedRAMP and SOC compliance) and integrations and APIs to streamline IT operations and automate workflows.

📋 Description

• Plan and run hypothesis-driven hunts across endpoint, identity, cloud, and network telemetry • Consume CTI and red-team/purple-team findings to prioritize hunts • Map hunts and findings to MITRE ATT&CK to track coverage and expose blind spots • Translate hunt findings into detection packages and recommendations for the tooling team • Partner with the red teamer on purple validation of configuration faults and security-posture gaps • Surface configuration faults and posture gaps and drive recommendations to close them • Document hypotheses, methods, and outcomes in reusable artifacts • Contribute threat context and hunt-derived intelligence during declared Sev 1 incidents in an advisory capacity

🎯 Requirements

• 5+ years in a security operations, detection engineering, CTI, or incident response role, with meaningful hands-on threat-hunting responsibility • Experience running hypothesis-driven hunts and driving investigations to a conclusion • Strong working knowledge of adversary tactics, techniques, and procedures • Practical fluency with the MITRE ATT&CK framework • Proficiency querying and pivoting across security telemetry at scale in a SIEM and/or EDR/XDR, such as KQL or SPL • Understanding of endpoint, identity, cloud, and network telemetry • Ability to turn hunt findings into detection recommendations with logic, context, and fidelity considerations • Understanding of the detection lifecycle and SOC signal-to-noise quality • Clear written communication for documentation, detection packages, and SOP recommendations • Ability to plan and sustain long-horizon hunt campaigns with limited day-to-day direction • Scripting for automation and enrichment, Python preferred • Familiarity with detection-as-code workflows and version-controlled detection content • Experience with cloud-native and SaaS telemetry, including CloudTrail, Entra ID/Azure AD, and SaaS audit logs • Experience with a threat intelligence platform and structured intelligence workflows • Exposure to an incident-response-capable or standing-response team environment • Relevant certifications preferred but not required, such as GCTI, GCFA, GCDA, GCIA, OSCP, or cloud security certifications • Must be a U.S. citizen or lawful permanent resident • Must reside in an eligible U.S. state; the role is unavailable within the city limits of Chicago • This position is not eligible for visa sponsorship

🏖️ Benefits

• A comprehensive benefits package, including medical, dental, and vision insurance • 401(k) plan • Unlimited PTO • Life insurance coverage • Opportunity for growth and advancement • Collaborative, kind, and curious community • Flexible hybrid-remote work arrangement

Apply Now

Similar Jobs

🕒 6 days ago

Northrop Grumman

10,000+ employees

🏭 Manufacturing

📦 Logistics

🎖️ Defense

Senior cyber threat analyst protecting Northrop Grumman’s defense networks, intellectual property, and sensitive data. Conducting intrusion analysis, threat intelligence, scripting, and cyber event mitigation.

🕒 September 19

Fortress Information Security

201 - 500

🔒 Cybersecurity

🏛️ Government

🤖 Artificial Intelligence

Senior Threat Intelligence Specialist analyzing open-source cybersecurity incidents and vendor risks at Fortress Information Security. Producing assessments, improving intelligence processes, and supporting critical infrastructure protection.

🇺🇸 United States – Remote

💵 $89.5k - $127.2k / year

💰 $125M Series C - Fortress Information Security on 2022-04

⏰ Full Time

🟠 Senior

🕵️ Threat Intelligence Specialist

🕒 September 18

Kodex

11 - 50

📋 Compliance

🔒 Cybersecurity

💳 Fintech

Threat intelligence specialist protecting Kodex’s secure data exchange platform for law enforcement requests. Investigating identity fraud and threat actors across the LATAM region.

🇺🇸 United States – Remote

💵 $70k - $110k / year

💰 Venture Round on 2022-10

⏰ Full Time

🟡 Mid-level

🟠 Senior

🕵️ Threat Intelligence Specialist

🗣️🇧🇷🇵🇹 Portuguese Required

🗣️🇪🇸 Spanish Required

🕒 September 17

Choice Hotels International

1001 - 5000

✈️ Travel

💼 Consulting

📦 Logistics

Revenue intelligence analyst optimizing performance reporting, automation, and revenue initiatives for Choice Hotels’ 5,500-hotel lodging franchise portfolio. Translating multi-source data into executive-ready actions.

🕒 September 15

CGS Federal (Contact Government Services)

51 - 200

⚖️ Legal

📦 Logistics

💼 Consulting

Intelligence Analyst/Review Attorney supporting a federal agency’s litigation matters. Reviewing and redacting documents, video, audio, and electronic data using RelativityOne and Evidence.com.