SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 100,000 - 125,000 / annual
Huntress is seeking a Security Operations Analyst to join its Security Operations Center (SOC) team. Founded in 2015 by former NSA cyber operators, Huntress protects 4M+ endpoints and 7M+ identities worldwide with enterprise-grade cybersecurity solutions designed for businesses of all sizes.
In this role, you will triage, investigate, respond to, and remediate intrusions on a daily basis. You'll work alongside a mission-driven team of security professionals at the forefront of threat detection and response. The position offers significant opportunities to develop your analyst skillset and accelerate career growth within an elite SOC environment.
Key responsibilities include:
- Triaging, investigating, and responding to alerts from the Huntress platform
- Performing tactical review of EDR telemetry, log sources, and forensic artifacts to determine root causes and provide remediations
- Conducting tactical malware analysis as part of alert investigation and triage
- Investigating suspicious Microsoft M365 activity and recommending remediations
- Assisting with escalations from the Product Support team on threat-related and SOC-relevant questions
- Contributing to detection engineering creation and tuning efforts
- Participating in projects to improve outcomes for analysts and partners
- Collaborating with a mentored team environment focused on continuous improvement
Schedule: Initial training is Monday-Friday. Following training, the role operates on a 4x10 schedule (either Wednesday-Saturday or Sunday-Wednesday), with weekend shifts running 7am-5pm PST. The role may be eligible for on-call/call-in pay in addition to base compensation.
Huntress is fully remote and has been since its founding. The company offers comprehensive benefits including generous PTO, 12 weeks paid parental leave, competitive medical/dental/vision coverage, 401(k) with 5% company contribution, stock options for all full-time employees, $500 home office reimbursement, annual professional development allowance, $75/month digital reimbursement, and access to BetterUp coaching platform.
REQUIREMENTS:
- 2+ years of experience in a SOC or Digital Forensics (DFIR) role
- Demonstrated experience with Windows, Linux, and macOS as attack surfaces
- Demonstrated experience with threat actor tools and techniques including: MITRE ATT&CK Framework, PowerShell & Command Prompt, WMIC, Scheduled Tasks, SCM, Windows Domain and host enumeration, lateral movement, persistence mechanisms, defense evasion techniques, and other offensive/Red Team TTPs
- Demonstrated experience with static and dynamic malware analysis concepts
- Working knowledge of Windows Administration or Enterprise Domain Administration (Active Directory, Group Policy, Domain Trusts, etc.)
- Working knowledge of core networking concepts (common ports/protocols, NAT, Public/Private IPs, VLANs, etc.)
- Working knowledge of web technologies and concepts (web servers/applications, OWASP top 10, etc.)
- Effective communication skills with ability to explain complex events to non-technical audiences
- Customer-focused mindset prioritizing customer needs in decision-making
- Strong curiosity and genuine excitement for learning
PREFERRED QUALIFICATIONS:
- Previous experience in MSP/MSSP/MDR role
- Linux and macOS investigative experience
- Experience with scripting languages (PowerShell, Python, Bash, PHP, JavaScript, Ruby)
- Demonstrated experience on platforms such as HackTheBox, TryHackMe, Blue Team Labs Online
- Demonstrated experience with cloud-based investigations (M365, Azure, AWS, GCP)
- Participation in cybersecurity competitions (Capture the Flag, Collegiate Cyber Defense Competition)
- Familiarity with MSP tools such as RMMs