Senior Detection Engineering & Threat Hunting Analyst

Huntress
$150,000 - $170,000Remote

About The Position

Huntress is seeking a Senior Detection Engineering & Threat Hunting Analyst to join their remote-first team. This role is crucial in impeding threat actors through a combination of detection engineering and threat hunting, working alongside the 24x7 Security Operations Center (SOC) and Adversary Tactics & Tactical Response function. The ideal candidate will be drawn to complex challenges such as detecting stealthy intrusions, managing false positives/negatives at scale, and uncovering evolving campaigns. This role involves translating threat intelligence or hypotheses into effective detections to help the SOC identify intrusions faster. While the SOC handles immediate alerts, this team focuses on developing detections and reviewing ambiguous signs of attacker activity on a daily and weekly basis. The position requires designing, building, and maintaining a scalable detection portfolio for identities and endpoints, as well as researching new attacker tradecraft, testing theories, and analyzing data across millions of endpoints to proactively hunt for and disrupt stealthy threat actor techniques.

Requirements

  • 2+ years of experience in detection engineering, threat hunting, SOC, MDR, or incident response.
  • Intermediate knowledge of Windows internals.
  • Working knowledge of Linux, macOS, Microsoft 365, Azure, and Google Workspace.
  • Experience developing, testing, tuning, and documenting detections or analytics from threat intelligence, IOCs, hypotheses, or real-world investigations.
  • Ability to communicate findings through clear written reports.
  • Strong familiarity with detection languages such as Sigma, Suricata, Snort, or YARA, and query languages such as KQL, EQL, ES|QL, or Splunk SPL.
  • A sound understanding of adversary tradecraft, including techniques used for persistence, privilege escalation, defense impairment, lateral movement, discovery, and collection on a system.
  • A sound understanding of the roles different threat actors play and their associated goals, such as initial access brokers, ransomware affiliates, and state-sponsored entities.
  • Ability to orchestrate reusable AI workflows that improve threat hunting, detection development, or analysis, and can verify AI-generated outputs before they reach production environments.

Nice To Haves

  • Intermediate knowledge of Linux and MacOS internals.
  • Hands-on experience using tools to remotely discover evidence of compromise, such as OSquery, Velociraptor, and EDR/MDR/XDR platforms.
  • Previous use of forensic tooling such as Eric Zimmerman's EZ Tools, RegRipper, Hayabusa, or Chainsaw to analyze endpoint artifacts.
  • Intermediate malware analysis skills.

Responsibilities

  • Contribute to all parts of the detection lifecycle by creating new rules, testing them before deployment, monitoring efficacy, and tuning, promoting, or retiring rules based on their performance.
  • Develop rules across a variety of Huntress products and operating systems, including Identity Threat Detection and Response (ITDR), Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), Windows, Linux, and macOS.
  • Manage any DE&TH requests raised internally or escalated from our partners.
  • Undertake hypothesis-driven hunts across Huntress telemetry, prioritizing techniques and tradecraft that may evade high-fidelity detections and initial SOC review.
  • Consume threat intelligence and translate IOCs, TTPs, and internal findings into new or refined detections through Git-based workflows.
  • Build and refine hunting dashboards or queries required to surface potential intrusions.
  • Review ambiguous signs of attacker activity across Huntress products, and surface likely intrusions that require deeper investigation.
  • Investigate or escalate likely intrusions identified to ensure partners receive clear incident reports with accurate advice.
  • Contribute findings to community-driven projects and create Huntress content such as blogs, social posts, videos, podcasts, and webinars.
  • Use AI-assisted workflows to prototype queries, enrich analysis, and develop a scaffolding for detection rules, ensuring you apply sound judgment to validate the AI output. We expect everyone at Huntress to be able to use AI as a real part of how they work, not occasionally, but genuinely embedded in core workflows.

Benefits

  • 100% remote work environment
  • Generous paid time off policy, including vacation, sick time, and paid holidays
  • 12 weeks of paid parental leave
  • Highly competitive and comprehensive medical, dental, and vision benefits plans
  • 401(k) with a 5% contribution regardless of employee contribution
  • Life and Disability insurance plans
  • Stock options for all full-time employees
  • One-time $500 reimbursement for building/upgrading home office
  • Annual allowance for education and professional development assistance
  • $75 USD/month digital reimbursement
  • Access to the BetterUp platform for coaching, personal, and professional growth
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service