About the role
DNSFilter’s mission is to protect our customers and partners with products they love to use! We are revolutionizing network security by providing fast, accurate, and reliable threat protection and content filtering. We're a rapidly growing company dedicated to creating a safer internet for businesses and organizations worldwide. Leveraging AI-driven threat intelligence, DNSFilter empowers our customers to proactively block threats before they impact their networks. We foster a collaborative, innovative, and results-oriented culture where every team member contributes to our mission of making the internet safer.
As we continue our product-fueled growth by adding new features and broadening our solution to meet the needs of the global market, it's clear there's a missing piece. That's where you come in!
We are seeking a Director of Threat Hunting to lead our Threat Intelligence function. This deeply technical "player-coach" will be responsible for tracking adversaries, delivering actionable intelligence to shape our product, and protecting our customers. The ideal candidate is passionate about rolling up their sleeves to conduct deep-dive analysis, strategy, team leadership, and has built and guided intelligence and hunting capabilities as they mature.
This is a full-time role open to candidates in the United States and Canada.
We recognize that people come with a wealth of experience and talent beyond just the technical requirements of a job. If you feel like this job is for you, please apply. We believe diversity of experience and skills, including transferable skills, combined with passion, is a key to innovation and excellence; therefore, we encourage people from all backgrounds to apply to our positions!
In this role, you will:
- Lead from the front by actively engaging in hands-on threat hunting across DNSFilter's vast DNS telemetry and cloud environments to detect, investigate, and disrupt adversary activity, serving as a senior individual contributor while building and mentoring a high-performing threat intelligence team.
- Architect and establish initial intelligence workflows by designing and implementing the foundational processes and practices for the threat intelligence function, demonstrating the ability to build from the ground up before scaling the team and its capabilities.
- Translate real-world investigations and Indicators of Compromise (IOCs) into an actionable product strategy and roadmap for new features.
- Collaborate with DNSFilter’s internal IT and Security teams to pilot and establish company-wide investigation workflows and best practices.
- Partner closely with Product Management to define the vision and shape the evolution of DNSFilter’s threat intelligence and digital forensics capabilities.
- Share your expertise by establishing the standards for clear reports and playbooks, while providing direct mentorship and career development as the team grows.
To qualify for this role, you have:
- 10+ years of professional experience in threat intelligence and analysis, with a history of proactively seeking out novel threats and vulnerabilities, and publicly accessible published material available for review.
- Proven ability to operate as a hands-on individual contributor with demonstrated experience in directly analyzing DNS data and webpage captures, mapping network infrastructure, identifying threats, and developing intelligence, with a clear track record of building and scaling threat intelligence functions from an initial stage.
- Strong leadership in establishing new initiatives with experience in leading the charge from zero, including defining initial workflows and processes for a threat intelligence program, and then successfully scaling the function as it matures.
- At least 3 years of experience managing or leading a technical team.
- Strong scripting ability (Python) and experience with data analysis libraries such as pandas
- Experience with reverse engineering tools (IDA Pro, Ghidra, or similar)
- Proven experience turning investigative insights into product improvements, shaping repeatable, scalable workflows, and contributing to the overall security posture through advanced threat intelligence and detection strategies.
- Excellent communication skills — comfortable collaborating with and presenting to cross-functional technical and executive teams.
- Experience in analytics on big data (Petabytes) using AWS Athena queries.
- Ability to work hours mostly overlapping with ET hours.
- Must be eligible to work in the region of hire without sponsorship from an employer now and in the future.
Bonus points for:
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s