SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior OT Threat Hunter

Dragos - Remote - Remote - posted 2026-09-10

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 140,000 - 0 / annual

Dragos is the global leader in xOT (extended Operational Technology) cybersecurity, protecting critical infrastructure systems that deliver water, power, and healthcare services worldwide. As a Senior OT Threat Hunter on the OT Watch team, you will lead hypothesis-driven threat hunting operations across industrial (ICS/OT) networks to identify sophisticated adversaries and uncover attack patterns. You will serve as a key technical escalation point for the broader team, guiding junior OT Hunters and analysts on high-severity alerts, and communicating directly with clients about critical findings, remediation steps, and technical guidance. Key responsibilities include: - Lead hands-on threat hunts across ICS/OT networks, collaborating with Intelligence, R&D, and Engineering teams to find adversaries and uncover attack patterns. - Act as the top escalation point for high-severity alerts, providing guidance to team members and direct client communication on critical security events. - Configure and optimize the Dragos Platform and hunt profiles for customer environments to maximize threat detection while reducing false positives. - Develop new hunting hypotheses and hunt content based on operational experience, providing structured feedback to Detection Engineering and Intelligence teams. - Analyze suspicious network activity, validate alert triggers, and contribute to incident summaries and custom reports for technical and non-technical audiences. - Create scripts, workflows, and tooling to improve hunting efficiency and repeatability; mentor junior team members in OT protocols, adversary tactics, and threat intelligence. The role is part of a remote-first, mission-driven team spanning North America, Europe, the Middle East, and APAC, built on authenticity, transparency, and trust. Requirements: - Demonstrated experience in hypothesis-based threat hunting with ability to reason from intelligence sources to testable hunts and successful investigations. - Experience analyzing network telemetry and identifying behavioral deviations/anomalies (not solely endpoint-focused). - Strong understanding of networking concepts (TCP/IP, firewalls, DNS, packet analysis). - Experience with PCAP analysis, IDS/IPS, SIEM platforms, or other network traffic analysis tools in an OT context. - Deep familiarity with adversary tactics, techniques, and procedures (TTPs) relevant to OT environments, including MITRE ATT&CK for ICS. - Familiarity with threat intelligence workflows, including consumption and feedback loops with intelligence and detection engineering teams. - Proven ability to communicate complex security findings to clients and internal stakeholders, both verbally and in writing. - Experience acting as a technical escalation point or senior contributor in a security operations or threat hunting context. - Experience with ICS/OT environments is strongly preferred.

Similar roles