SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 150,000 - 170,000 / annual
Huntress, founded in 2015 by former NSA cyber operators, is a remote-first cybersecurity company protecting 5M+ endpoints and 15M+ identities worldwide. The company combines in-house technology with a 24/7 human-led Security Operations Center (SOC) to deliver enterprise-grade cybersecurity to businesses of all sizes.
As a Senior Detection Engineering & Threat Hunting (DE&TH) Analyst, you will be part of a specialized team that sits alongside the SOC and Adversary Tactics & Tactical Response function, playing a pivotal role in detecting threat actors before they impact partner environments. You will focus on hard problems: detecting stealthy intrusions, managing false positives and false negatives at scale, and uncovering clues that expose evolving campaigns across millions of endpoints.
On the Detection Engineering side, you will design, build, and maintain a resilient, scalable, high-fidelity detection portfolio that enables the SOC to rapidly identify and respond to adversary activity. This involves collaborating with engineering and adjacent teams across multiple domains including identities and endpoints.
On the Threat Hunting side, you will research new attacker tradecraft, test theories, and review hunting data at scale to proactively hunt for and disrupt stealthy threat actor techniques that evade initial defenses.
Key responsibilities include: contributing to all parts of the detection lifecycle (creating, testing, monitoring, tuning rules); developing rules across ITDR, SIEM, EDR, Windows, Linux, and macOS; managing DE&TH requests from internal teams and partners; conducting hypothesis-driven hunts; translating threat intelligence into detections via Git-based workflows; building hunting dashboards and queries; reviewing ambiguous signs of attacker activity; investigating or escalating likely intrusions; contributing to community projects and Huntress content (blogs, social posts, videos, podcasts, webinars); and using AI-assisted workflows to prototype queries and develop detection rule scaffolding with sound judgment.
REQUIREMENTS:
- 2+ years of experience in detection engineering, threat hunting, SOC, MDR, or incident response
- Intermediate knowledge of Windows internals
- Working knowledge of Linux, macOS, Microsoft 365, Azure, and Google Workspace
- Experience developing, testing, tuning, and documenting detections or analytics from threat intelligence, IOCs, hypotheses, or real-world investigations
- Ability to communicate findings through clear written reports
- Strong familiarity with detection languages (Sigma, Suricata, Snort, YARA) and query languages (KQL, EQL, ES|QL, Splunk SPL)
- Sound understanding of adversary tradecraft including persistence, privilege escalation, defense impairment, lateral movement, discovery, and collection techniques
- Sound understanding of different threat actor roles and goals (initial access brokers, ransomware affiliates, state-sponsored entities)
- Ability to orchestrate reusable AI workflows that improve threat hunting, detection development, or analysis, and verify AI-generated outputs before production
BONUS: Intermediate knowledge of Linux and macOS internals; hands-on experience with OSquery, Velociraptor, EDR/MDR/XDR platforms; experience with forensic tools (EZ Tools, RegRipper, Hayabusa, Chainsaw); intermediate malware analysis skills.