← Back to results

Senior Detection Engineering & Threat Hunting Analyst

Join Huntress as a Senior Detection Engineering & Threat Hunting Analyst to combat cyber threats in a fully remote environment.

Location
United States
Compensation
$150k–$170k/yr
Level
senior
Type
full time · Remote

Posted by employer 1 day ago

First seen on Joblaze 23 hours ago

Last verified on the company career page 23 hours ago

Apply at Huntress → Save job Scanned from huntress.com

What you'll build

  • Create new detection rules
  • Develop rules across Huntress products
  • Undertake hypothesis-driven hunts
  • Build and refine hunting dashboards
  • Investigate likely intrusions

Must have

  • 2+ years of experience in detection engineering, threat hunting, SOC, MDR, or incident response
  • Intermediate knowledge of Windows internals
  • Working knowledge of Linux, macOS, Microsoft 365, Azure, and Google Workspace
  • Experience developing, testing, tuning, and documenting detections
  • Strong familiarity with detection languages and query languages

Nice to have

  • Intermediate knowledge of Linux and MacOS internals
  • Hands-on experience using tools to discover evidence of compromise
  • Previous use of forensic tooling to analyze endpoint artifacts
  • Intermediate malware analysis skills

AI in the day-to-day

Use AI-assisted workflows to prototype queries, enrich analysis, and develop detection rules.

Requirements

Experience
2+ years

Not disclosed in this posting: visa sponsorship.

Benefits

401k Match Education Budget Equity/Stock Options Remote Work Health Insurance Parental Leave

Joblaze summary

In the role of Senior Detection Engineering & Threat Hunting Analyst at Huntress, the individual will focus on developing and refining detection rules while actively hunting for threats across a vast network of endpoints. Key skills include expertise in detection languages and a solid understanding of adversary tactics, with a strong emphasis on translating threat intelligence into actionable insights. This position is suited for professionals with a background in cybersecurity, particularly those with experience in detection engineering or threat hunting. The team operates within a remote-first environment, collaborating closely with a 24/7 Security Operations Center.

Joblaze insights

  • Listed today — first seen on Joblaze September 23, 2026. Last confirmed on Huntress's careers page September 23, 2026.
  • Salary band is below the typical range for Security roles (median ~$170,000).
  • Starts above 13% of 23 comparable senior security roles in United States that list Azure we track (median $170,000 across 15 companies). See Azure salary trends
  • Azure appears in 10.1% of 306 comparable senior security roles in United States; Splunk SPL appears in 0.3% of 306 comparable senior security roles in United States.

Quick facts

Is the Senior Detection Engineering & Threat Hunting Analyst role remote?
Yes — Huntress lists this as a fully remote position.
What's the salary range?
Huntress lists $150,000–$170,000 for this role.
How much experience is required?
At least 2 years of relevant experience for this Senior Detection Engineering & Threat Hunting Analyst role.
What's the tech stack?
Joblaze extracted these technologies from the posting: Azure, EDR, EQL, ES|QL, Google Workspace, KQL.
What seniority level is this role?
Huntress targets senior candidates for this position.
Is this full-time or contract?
Full-time for this Senior Detection Engineering & Threat Hunting Analyst role at Huntress.

From the original posting

Reports to: Sr. Manager, Detection Engineering & Threat Hunting

Location: Remote US

Compensation Range: $150,000 to $170,000 base plus bonus and equity

Huntress now secures more than 5M+ endpoints and 15M+ identities worldwide. Those numbers keep growing because more businesses rely on us to help carry the load and operate with more confidence. Every day, you can see that commitment in how we stand with our customers and how we show up for each other.

What You’ll Do:

Members of the Huntress DE&TH team wake up every morning with the honor of impeding threat actors through a combination of detection engineering and threat hunting. This team sits alongside our 24x7 Security Operations Center and our Adversary Tactics & Tactical Response function, and plays a pivotal role in detecting threat actors before they can impact our partner environments.

As a Senior Detection Engineering and Threat Hunting (DE&TH) Analyst, you should be drawn to the hard problems: detecting stealthy intrusions, managing false positives and false negatives at scale, and uncovering clues that may expose an evolving campaign across Huntress partners. In this role, you will turn threat intelligence, or a hypothesis, into detections that help the SOC find real intrusions faster. While the SOC is responding to alerts within minutes, this team is developing detections and reviewing more ambiguous signs of attacker activity on a daily & weekly basis.

On the Detection Engineering side of the role, you will play a part in designing, building, and maintaining a resilient, scalable, and high-fidelity detection portfolio that enables the SOC to rapidly identify and respond to adversary activity. This will involve working with engineering and other adjacent teams to achieve a shared goal across multiple domains, which includes identities and endpoints.

On the Threat Hunting side of the role, you will get to research new attacker tradecraft, test new theories, and review hunting data at scale for millions of endpoints to proactively hunt for and disrupt stealthy threat actor techniques that evade initial defenses.

If you love Detection Engineering and Threat Hunting at scale, whilst in the environment and energy of a SOC, this is the role for you!

Responsibilities:

  • Contribute to all parts of the detection lifecycle by creating new rules, testing them before deployment, monitoring efficacy, and tuning, promoting, or retiring rules based on their performance.
  • Develop rules across a variety of Huntress products and operating systems, including Identity Threat Detection and Response (ITDR), Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), Windows, Linux, and macOS.
  • Manage any DE&TH requests raised internally or escalated from our partners.
  • Undertake hypothesis-driven hunts across Huntress telemetry, prioritizing techniques and tradecraft that may evade high-fidelity detections and initial SOC review.
  • Consume threat intelligence and translate IOCs, TTPs, and internal findings into new or refined detections through Git-based workflows.
  • Build and refine hunting dashboards or queries required to surface potential intrusions.
  • Review ambiguous signs of attacker activity across Huntress products, and surface likely intrusions that require deeper investigation.
  • Investigate or escalate likely intrusions identified to ensure partners receive clear incident reports with accurate advice.
  • Contribute findings to community-driven projects and create Huntress content such as blogs, social posts, videos, podcasts, and webinars.
  • Use AI-assisted workflows to prototype queries, enrich analysis, and develop a scaffolding for detection rules, ensuring you apply sound judgment to validate the AI output. We expect everyone at Huntress to be able to use AI as a real part of how they work, not occasionally, but genuinely embedded in core workflows.

What You Bring To The Team:

  • 2+ years of experience in detection engineering, threat hunting, SOC, MDR, or incident response.
  • Intermediate knowledge of Windows internals.
  • Working knowledge of Linux, macOS, Microsoft 365, Azure, and Google Workspace.
  • Experience developing, testing, tuning, and documenting detections or analytics from threat intelligence, IOCs, hypotheses, or real-world investigations.
  • Ability to communicate findings through clear written reports.
  • Strong familiarity with detection languages such as Sigma, Suricata, Snort, or YARA, and query languages such as KQL, EQL, ES|QL, or Splunk SPL.
  • A sound understanding of adversary tradecraft, including techniques used for persistence, privilege escalation, defense impairment, lateral movement, discovery, and collection on a system.
  • A sound understanding of the roles different threat actors play and their associated goals, such as initial access brokers, ransomware affiliates, and state-sponsored entities.
  • Ability to orchestrate reusable AI workflows that improve threat hunting, detection development, or analysis, and can verify AI-generated outputs before they reach production environments.

Bonus Points for:

  • Intermediate knowledge of Linux and MacOS internals.
  • Hands-on experience using tools to remotely discover evidence of compromise, such as OSquery, Velociraptor, and EDR/MDR/XDR platforms.
  • Previous use of forensic tooling such as Eric Zimmerman's EZ Tools, RegRipper, Hayabusa, or Chainsaw to analyze endpoint artifacts.
  • Intermediate malware analysis skills.

#BI-Remote

Standard company text repeated across Huntress's postings is omitted here.

Similar positions

Huntress
Huntress
Vice President, Threat Detection & Response
Huntress · United States of America
Huntress
Senior Tactical Response Analyst
Huntress · United States
Huntress
Manager, Security Operations Center
Huntress · United States of America
Huntress
Director, Engineering - Platform
Huntress · United States of America