SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 100,000 - 125,000 / annual
Huntress, founded in 2015 by former NSA cyber operators, is a remote-first cybersecurity company protecting over 5 million endpoints and 14 million identities worldwide. The company provides enterprise-grade security solutions to businesses of all sizes through a combination of in-house technology and a 24/7 human-led Security Operations Center (SOC).
As a Security Operations Analyst, you will be a core member of Huntress's elite SOC team, responsible for triaging, investigating, responding to, and remediating intrusions daily. Your primary responsibilities include analyzing alerts from the Huntress platform, reviewing EDR telemetry and forensic artifacts to determine attack root causes, performing tactical malware analysis, investigating suspicious Microsoft 365 activity, and providing remediation guidance. You will also assist with escalations from the Product Support team, contribute to detection engineering efforts, and participate in projects aimed at improving outcomes for analysts and partners.
The role requires 2+ years of hands-on experience in a SOC or Digital Forensics (DFIR) environment. You should have demonstrated expertise with Windows, Linux, and macOS as attack surfaces, familiarity with threat actor tools and techniques (MITRE ATT&CK Framework, PowerShell, command-line utilities, lateral movement, persistence, and defense evasion), and knowledge of static and dynamic malware analysis. Working knowledge of Windows/Enterprise Domain Administration (Active Directory, Group Policy), core networking concepts, and web technologies is essential. Strong communication skills are critical for explaining complex security events to less technical audiences and enabling cross-functional collaboration.
Preferred qualifications include prior MSP/MSSP/MDR experience, Linux and macOS investigative expertise, scripting proficiency (PowerShell, Python, Bash, PHP, JavaScript, Ruby), and hands-on experience with platforms like HackTheBox or TryHackMe.
The initial training period is Monday-Friday full-time. Following training, the schedule may shift to include weekends or 4x10 shifts based on business needs. The role may include on-call/call-in pay in addition to base compensation.