SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 125,000 - 135,000 / annual
Huntress, founded in 2015 by former NSA cyber operators, is a remote-first cybersecurity company that makes enterprise-grade security accessible to businesses of all sizes. The company operates a 24/7 human-led Security Operations Center (SOC) backing its platform, currently protecting 5M+ endpoints and 15M+ identities worldwide.
As a Senior Tactical Response Analyst reporting to the Senior Manager of Tactical Response, you will lead complex incident investigations involving active adversaries, hands-on-keyboard activity, and serious intrusions. Your core responsibility is understanding what happened during security incidents, how attackers gained access, what they did, what remains at risk, and what partners should do next.
Key responsibilities include:
- Leading or supporting cases involving confirmed active adversaries and complex intrusions
- Investigating across endpoint, identity, cloud, SIEM, VPN, firewall, and other telemetry sources (Windows, Linux, macOS)
- Building clear, evidence-based timelines and narratives explaining incident progression and required remediation
- Providing practical guidance on eviction, recovery, and recurrence prevention
- Communicating complex findings clearly to technical teams, executives, and stakeholders during high-pressure partner calls
- Identifying gaps in Huntress capabilities and indicating needs for additional coverage
- Facilitating technical handoffs and supporting post-incident briefings
- Researching emerging attacker tradecraft and testing hypotheses against Huntress telemetry
- Developing scripts, automations, dashboards, playbooks, and data-normalization workflows
- Contributing validated intelligence to enablement materials, blogs, webinars, and case studies
- Mentoring responders and collaborating across Product, Detection Engineering, and other functions
Success means partners receive clear answers and actionable guidance during incidents, cases close with defensible root-cause analysis, investigation findings drive product improvements and detection enhancements, and your work improves the quality and scalability of future engagements.
REQUIREMENTS:
- Typically 3–5+ years of experience in SOC, MDR, threat hunting, digital forensics, or incident response
- Experience leading or participating in external-customer incident response engagements
- Demonstrated ability to investigate complex or multi-host intrusions with limited oversight
- Strong understanding of initial access, persistence, lateral movement, credential access, remote access, and ransomware activity
- Ability to reconstruct attacker activity across systems, data sources, and time periods
- Experience with Microsoft 365, Azure, identity, VPN, firewall, SIEM, or cloud telemetry
- Experience with endpoint and forensic tools (osquery, Velociraptor, EDR platforms, Eric Zimmerman tools, RegRipper, Hayabusa, Chainsaw, or equivalents)
- Strong knowledge of forensic artifacts (event logs, registry data, prefetch, jump lists, shellbags, scheduled tasks, services, browser artifacts, authentication activity)
- Working knowledge of Windows internals; Linux and macOS experience beneficial
- Working knowledge of static and dynamic malware analysis, indicator extraction, and basic unpacking or deobfuscation
- Familiarity with OSINT and attacker infrastructure research
- Strong working knowledge of KQL, EQL, ES|QL, Splunk SPL, or equivalent query languages
- Experience with Sigma, YARA, Suricata, Snort, or comparable detection formats
- Scripting or automation experience with Python, PowerShell, Bash, JavaScript, PHP, Ruby, or similar
- Ability to identify product, telemetry, detection, and workflow gaps and express them as actionable requirements
- Demonstrated ability to write concise technical notes, investigation reports, and executive summaries
- Strong verbal communication, judgment, empathy, and composure during high-pressure partner engagements
- Experience collaborating with Product, Engineering, Detection Engineering, Sales Engineering, TAM, or other cross-functional teams
Helpful but not required: experience designing reusable investigation playbooks, developing production-quality automation, creating technical enablement content, or relevant certifications in forensics, incident response, threat hunting, or offensive security.