Senior Hunt & Response Analyst - West Coast
HuntressAbout the role
Reports to: Senior Manager, Hunt & Response
Location: Remote US
Compensation Range: $145,000 to $165,000 base plus bonus and equity
What We Do:
Huntress is a fully remote, global team of passionate experts and ethical badasses on a mission to break down the barriers to cybersecurity. Whether creating purpose-built security solutions, hunting down hackers, or impacting our community, our people go above and beyond to change the security game and make a real difference.
Founded in 2015 by former NSA cyber operators, Huntress protects all businesses—not just the 1%—with enterprise-grade, fully owned, and managed cybersecurity products at the price of an affordable SaaS application. The Huntress difference is our One Team advantage: our technology is designed with our industry-defining Security Operations Center (SOC) in mind and is never separated from our service.
We protect 4M+ endpoints and 7M+ identities worldwide, elevating underresourced IT teams with protection that works as hard as they do. As long as hackers keep hacking, Huntress keeps hunting.
What You’ll Do:
The Huntress Global Hunting & Response team has the unique honor of waking up every morning knowing we will be kicking out threat actors. This team sits alongside our 24x7 Security Operations Center team. It is a skilled team of individuals who review lower-confidence signals and manage tactical incident response scenarios to assist customers in exiting critical intrusions.
Members of this team will be able to allocate their time between hunting and response efforts. While in Hunting mode, you will get to research new attacker tradecraft, test new theories, and review hunting data at scale for millions of endpoints. While the SOC responds to alerts within minutes, this team develops detections and reviews more ambiguous signs of attacker activity on a daily & weekly basis.
In the Response side of the role, you will have the opportunity to flex your incident response and forensics skills. When customers are experiencing the worst incidents of their lives, this team will step in to answer questions core to understanding the cause of an attack, the high-level activities of the attacker once in the environment, and provide remediation actions and recommendations that will help reduce or eliminate this threat from occurring again in their environment.
If you love Threat Hunting, Incident Response, and Detection Engineering while in the environment and energy of a SOC, this is the role for you!
Responsibilities:
- Perform a cadenced review of hunting data to identify compromises not found during standard SOC workflows
- Research, develop, and test new hunting hypotheses in the form of new detections or analytics
- Lead or support tactical incident response engagements for customers who already utilize Huntress MDR. Perform live analysis on systems to determine the root cause of an intrusion, and craft reports that summarize the intrusion, with the next steps to be taken
- Perform intermediate malware analysis as part of hunting and response efforts
- Perform OSINT as part of hunting and response efforts
- Contribute to content creation efforts such as blogs, videos, podcasts, and webinars
- Contribute to community-driven projects and frameworks, such as MITRE ATT&CK, HijackLibs, and the LOLBAS Project
- Speak with customers to explain or summarize findings from investigations
What You Bring To The Team:
- 3-5 years working in one or more of the following: SOC, MDR, Threat Hunting, or Incident Response roles
- Experience leading or participating in Incident Response engagements for external customers
- Experience with tools such as osquery, Velociraptor, or leveraging EDRs to perform forensic artifact analysis on systems
- Confident command of forensic tools - such as Ericzimmerman’s EZ tools, RegRipper, Hayabusa, or Chainsaw - and forensic artifacts - such as prefetch, jumplists, shellbags, and more
- Deep understanding of offensive security tradecraft, particularly persistence, lateral movement, credential theft, and remote access.
- Confidently able to track threat actors across an organization and timeline the activity
- Strong familiarity with one or more detection languages such as Sigma, Suricata, Snort, or Yara
- Familiarity with OSINT sources and how they can help answer questions relating to threat actor activity and infrastructure.
- Strong familiarity with various query languages such as KQL, EQL, ES|QL, Splunk SPL
- Intermediate malware analysis skills
- Intermediate knowledge of Windows internals
- Intermediate knowledg
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s