Threat Hunter
DeepwatchAbout the role
Come join Deepwatch’s team of world-class cybersecurity professionals and the brightest minds in the industry. If you're ready to challenge yourself with work that matters, then this is the place for you. We're redefining cybersecurity as one of the fastest growing companies in the U.S. – and we have a blast doing it!
Who We Are
Deepwatch is the leader in managed security services, protecting organizations from ever-increasing cyber threats 24/7/365. Powered by Deepwatch’s cloud-based security operations platform, Deepwatch provides the industry’s fastest, most comprehensive detection and automated response to cyber threats together with tailored guidance from dedicated experts to mitigate risk and measurably improve security posture. Hundreds of organizations, from Fortune 100 to mid-sized enterprises, trust Deepwatch to protect their business.
Our core values drive everything we do at Deepwatch, including our approach to tackling tough cyber challenges. We seek out tenacious individuals who are passionate about solving complex problems and protecting our customers. At Deepwatch, every decision, process, and hire is made with a focus on improving our cybersecurity solutions and delivering an exceptional experience for our customers. By embracing our values, we create a culture of excellence that is dedicated to empowering our team members to explore their potential, expand their skill sets, and achieve their career aspirations, which is supported by our unique annual professional development benefit.
Deepwatch recognition includes:
- 2025, 2024, 2023, 2022 and 2021 Great Place to Work® Certified
- 2024 Military Times Best for Vets Employers
- 2024 US Department of Labor Hire Vets Gold Award
- 2024 Forbes' America's Best Startup Employers
- 2024 Cyber Defense Magazine, Global Infosec Awards
- 2023 and 2022 Fortress Cybersecurity Award
- 2023 $180M Series C investment from Springcoast Capital Partners, Splunk Ventures, and Vista Credit Partners of Vista Equity Partners
- 2022 Cybersecurity Excellence Award for MDR
Threat Hunter
Deepwatch is seeking a motivated and analytically driven Junior Threat Hunter to join our Security Operations team. You will work alongside experienced hunters, threat intelligence, threat research and incident responders to identify advanced threats that evade traditional controls. This role offers hands-on exposure to enterprise telemetry, detection engineering, and real-world adversary tradecraft.
Key Responsibilities:
- Assist in proactive, hypothesis-driven threat hunts across endpoint, network, cloud, and identity environments.
- Analyze telemetry from EDR, SIEM, NDR, email, and identity platforms.
- Investigate suspicious activity and anomalies to determine malicious vs. benign behavior.
- Support development and tuning of detection rules and analytics.
- Leverage the MITRE ATT&CK framework to understand and map adversary techniques.
- Document hunt findings, methodologies, and lessons learned.
- Collaborate with SOC and Incident Response teams to escalate validated threats.
- Contribute to continuous improvement of detection coverage and hunting playbooks.
- Stay current on emerging threats, malware trends, and attacker techniques.
Required Qualifications:
- 4+ years in cybersecurity with at least 2 years in threat hunting, advanced detection engineering, or incident response.
- Strong experience with EDR platforms (CrowdStrike, Microsoft Defender, SentinelOne, etc.).
- Proficiency in SIEM platforms (Splunk, Sentinel, Elastic, QRadar, etc.).
- Experience writing advanced queries (KQL, SPL, SQL, Lucene, etc.).
- Deep understanding of Windows, Linux, and Active Directory internals.
- Strong knowledge of Cloud services (AWS, Azure, Google Cloud, etc.)
- Familiarity with MITRE ATT&CK framework.
- Experience analyzing process trees, command-line artifacts, persistence mechanisms, and lateral movement.
- Strong knowledge of networking fundamentals and common attack techniques.
- Ability to independently conduct investigations from hypothesis to conclusion.
- Strong written and verbal communication skills.
Preferred Qualifications
- Knowledge of identity-based attacks (OAuth abuse, token theft, Kerberos abuse).
- Experience with scripting (Python, PowerShell, Bash).
- Background in detection engineering or purple teaming.
- Industry certifications such as GCFA, GCIA, GCIH, GCED, CISSP, or similar.
- Experie
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s