SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 140,000 - 0 / annual
Dragos is the global leader in xOT (extended Operational Technology) cybersecurity, protecting critical infrastructure systems that deliver water, power, and healthcare services worldwide. As a Senior OT Threat Hunter on the OT Watch team, you will lead hypothesis-driven threat hunting operations across industrial (ICS/OT) networks to identify sophisticated adversaries and uncover attack patterns. You will serve as a key technical escalation point for the broader team, guiding junior OT Hunters and analysts on high-severity alerts, and communicating directly with clients about critical findings, remediation steps, and technical guidance.
Key responsibilities include:
- Lead hands-on threat hunts across ICS/OT networks, collaborating with Intelligence, R&D, and Engineering teams to find adversaries and uncover attack patterns.
- Act as the top escalation point for high-severity alerts, providing guidance to team members and direct client communication on critical security events.
- Configure and optimize the Dragos Platform and hunt profiles for customer environments to maximize threat detection while reducing false positives.
- Develop new hunting hypotheses and hunt content based on operational experience, providing structured feedback to Detection Engineering and Intelligence teams.
- Analyze suspicious network activity, validate alert triggers, and contribute to incident summaries and custom reports for technical and non-technical audiences.
- Create scripts, workflows, and tooling to improve hunting efficiency and repeatability; mentor junior team members in OT protocols, adversary tactics, and threat intelligence.
The role is part of a remote-first, mission-driven team spanning North America, Europe, the Middle East, and APAC, built on authenticity, transparency, and trust.
Requirements:
- Demonstrated experience in hypothesis-based threat hunting with ability to reason from intelligence sources to testable hunts and successful investigations.
- Experience analyzing network telemetry and identifying behavioral deviations/anomalies (not solely endpoint-focused).
- Strong understanding of networking concepts (TCP/IP, firewalls, DNS, packet analysis).
- Experience with PCAP analysis, IDS/IPS, SIEM platforms, or other network traffic analysis tools in an OT context.
- Deep familiarity with adversary tactics, techniques, and procedures (TTPs) relevant to OT environments, including MITRE ATT&CK for ICS.
- Familiarity with threat intelligence workflows, including consumption and feedback loops with intelligence and detection engineering teams.
- Proven ability to communicate complex security findings to clients and internal stakeholders, both verbally and in writing.
- Experience acting as a technical escalation point or senior contributor in a security operations or threat hunting context.
- Experience with ICS/OT environments is strongly preferred.