Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cyber Threat Hunter

$80k - $110k

NinjaOne

Description

About the Role


We are looking for a Threat Hunter to join our Cyber Threat Intelligence function and run proactive, hypothesis-driven hunts across our environment. This is a dedicated hunting role at the front of a detection pipeline: you will turn intelligence and adversary tradecraft into concrete hunts and turn what you find into detection packages that our tooling team operationalizes and our SOC consumes as tuned, documented alerts.

You will sit at the intersection of threat intelligence, detection engineering, and offensive validation. Working from CTI and from our red teamer's findings, you will hunt for activity that never trips an existing alert, novel techniques, living-off-the-land tradecraft, misconfiguration abuse, and long-dwell intrusions, and close those gaps by feeding durable detections and configuration fixes back into the organization. It is a role for a curious, methodical hunter who is energized by long-horizon investigation rather than the pace of the alert queue.

Location: We are flexible on remote working from home, if you are located in the USA and reside in one of the following states: CA, CO, CT, FL, GA, *IL, KS, MA, MD, ME, NJ, NC, NY, OH, OR, TN, TX, VA, and WA . We have physical offices in Austin, TX and Tampa, FL , if you prefer a hybrid option.

*Onsite interviews may be required for this role.

What You'll Be Doing

  • Plan and run hypothesis-driven hunts (intel-led, TTP-led, and behavior-led) across endpoint, identity, cloud, and network telemetry
  • Consume CTI and red-team/purple-team findings to prioritize hunts against the adversary behaviors most relevant to us
  • Map hunts and findings to MITRE ATT&CK to track coverage and expose blind spots
  • Translate hunt findings into detection packages and recommendations, including detection logic, required context and enrichment, and draft SOP guidance, for the tooling team to operationalize
  • Partner with the red teamer on purple validation of configuration faults and security-posture gaps
  • Surface configuration faults and posture gaps discovered during hunts, and drive recommendations to close them
  • Document hypotheses, methods, and outcomes so hunting knowledge lives in reusable artifacts rather than in one person's head
  • Contribute threat context and hunt-derived intelligence during declared Sev 1 incidents, in an advisory (non-primary) capacity
  • Other duties as needed
Required Qualifications
  • 5+ years in a security operations, detection engineering, CTI, or incident response role, with meaningful hands-on threat-hunting responsibility
  • Demonstrated experience running hypothesis-driven hunts, forming a hypothesis, testing it against telemetry, and driving it to a conclusion, not solely alert triage
  • Strong working knowledge of adversary tactics, techniques, and procedures, and practical fluency with the MITRE ATT&CK framework
  • Proficiency querying and pivoting across security telemetry at scale in a SIEM and/or EDR/XDR (e.g., KQL, SPL, or equivalent query languages)
  • Solid understanding of endpoint, identity, cloud, and network telemetry, and a sense of what normal and abnormal look like in each
  • Ability to turn a hunt finding into a detection recommendation, including logic, supporting context, and fidelity/signal-to-noise considerations
  • Understanding of the detection lifecycle and why signal-to-noise quality matters to a SOC
  • Clear written communication for documentation, detection packages, and SOP recommendations
  • Able to plan and sustain long-horizon hunt campaigns with limited day-to-day direction
Preferred Qualifications
  • Experience consuming red-team or purple-team output to drive and prioritize hunts
  • Scripting for automation and enrichment (Python preferred)
  • Familiarity with detection-as-code workflows and version-controlled detection content
  • Depth in cloud-native and SaaS telemetry (CloudTrail, Entra ID/Azure AD, SaaS audit logs)
  • Experience with a threat intelligence platform (TIP) and structured intel workflows
  • Exposure to an IR-capable or standing-response team environment
  • Relevant certifications, one or more (preferred, not required):
    • GCTI, GCFA, GCDA, GCIA, or similar GIAC certifications
    • OSCP or comparable (for offensive-tradecraft awareness)
    • Cloud security certifications (AWS, Azure, or GCP), or equivalent
Key Skills
  • Adversary mindset, thinks in behaviors and TTPs, not indicators alone
  • Patience and persistence for long-horizon threads that may not pay off immediately
  • Strong analytical and data-pivoting skills across large, varied datasets
  • Translates findings into durable, reusable detections and clear documentation
  • Communicates effectively across CTI, tooling, and SOC audiences
  • Curiosity and a genuine drive to find what existing alerting misses
About Us


NinjaOne unifies IT to simplify work for nearly 40,000 customers in 140+ countries. The NinjaOne Unified IT Operations Platform delivers endpoint management, autonomous patching, backup, and remote access in a single console to improve efficiency, increase resilience, and reduce spend. By automating IT and managing all endpoints, organizations give employees a great technology experience at work. NinjaOne is obsessed with customer success and has retained a 98% customer satisfaction score for more than 5 years.

What You'll Love
  • A collaborative, kind, and curious community
  • Full-time work that is hybrid remote, honoring your flexibility needs
  • A comprehensive benefits package, including medical, dental, and vision insurance
  • A 401(k) plan to help you prepare for your financial future
  • Unlimited PTO that prioritizes your work-life balance
  • Opportunity for growth and advancement

Additional Information


This position is NOT eligible for Visa sponsorship. Due to federal government security requirements associated with our FedRAMP-authorized environment, candidates must be U.S. citizens or lawful permanent residents.

Due to operational policies, NinjaOne is unable to hire for this role within the city limits of Chicago. We will consider all qualified candidates who reside outside of the city proper or are willing to self-relocate.

Starting pay for the successful applicant depends on a variety of job-related factors, including but not limited to location, market demands, experience, job-related knowledge, and skills. The benefits available for this position include medical, dental, vision, 401(k) plan, life insurance coverage, and PTO. For roles based in California, Colorado, Maryland, New Jersey, or Washington, the base salary hiring range for this position is $80,000 to $110,000 per year.

For roles based in New York, the base salary hiring range for this position is $80,000 to $110,000 per year.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, genetic information, marital status, veteran status, or any other status protected by applicable law. We are committed to providing an inclusive and diverse work environment.
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Cyber Threat Hunter in United States vacancy
  • DescriptionSAIC is seeking Cyber Threat & Vulnerability Hunter to join its Blue Team Vulnerability Assessment Program in Chantilly, Virginia. This position requires an active TS/SCI Clearance with Polygraph.Positional Overview: Perform technical reviews and analysis of... 
    Cyber
    Work experience placement

    Science Applications International Corporation

    Chantilly, Loudoun County, VA
    22 hours ago
  • $62k - $141k

    Cyber Threat Hunter, MidThe Opportunity:The Threat Hunter supports a Cybersecurity Operations Division by proactively identifying malicious activity, uncovering hidden threats, and strengthening the organization’s defensive posture. This role conducts hypothesis‑driven... 
    Cyber
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Bethesda, MD
    1 day ago
  •  ...worldwide.Job Description*** This position is contingent upon contract award ***OverviewSOSi is seeking a Senior Threat Hunter to support proactive cyber defense activities in alignment with our customer. This role is responsible for conducting threat hunting operations... 
    Cyber
    Contract work
    Work at office
    Worldwide
    Monday to Friday
    Weekend work
    Afternoon shift

    SOSi

    Washington DC
    22 hours ago
  •  ...can build, innovate, and secure your career. Sentar is seeking a Cybersecurity Threat Hunter in Columbus, OH! Role Description: The DLA JETS 2.0 Cyber Security Services Provider Support Services (CSSP) effort focuses on providing... 
    Cyber
    Temporary work
    For contractors
    Flexible hours

    Sentar

    Columbus, OH
    22 hours ago
  •  ...Defense and Federal customers. We are hiring a Cybersecurity Threat Hunter to support an enterprise-level program within a federal environment...  ...Responsibilities Proactively identifies and investigates cyber threats that may be operating undetected within the network,... 
    Cyber
    For contractors
    Work at office
    Local area
    Remote work

    ESM

    Columbus, OH
    4 days ago
  • $120k - $135k

    ## Cybersecurity Threat HunterApplylocations: (North America) Adelphi, MDtime type: Full...  ...timeStateside Exempt 3.4**Cybersecurity Threat Hunter****Security Operations****Full-time,...  ...consultation on threat hunting methodologies and cyber adversary techniques.* Maintain awareness... 
    Cyber
    Full time
    Part time
    Immediate start
    Flexible hours

    University of Maryland Global Campus

    Hyattsville, MD
    3 days ago
  • Job Title: Senior Exposure Threat HunterLocation: Austin, USARole SummaryWe are seeking an...  ...and highly analytical Exposure Threat Hunter to join our Information Security team. This...  ...investigative workflows.Solid understanding of the cyber-attack lifecycle and common attacker... 
    Cyber
    Full time
    Work at office
    Local area

    NXP Semiconductors

    Austin, TX
    22 hours ago
  • $106.58k - $177.63k

     ...organization, apply now.We are currently seeking a Security Analysis Threat Hunter - Addison, TX Hybrid to join our team in Addison, Texas (US-TX...  ...intelligence feedsBasic Requirements10+ years’ experience in Cyber SecurityAdditional Skills & ExperienceStrong understanding of... 
    Cyber
    Full time
    Temporary work
    Work at office
    Local area
    Remote work
    Flexible hours

    NTT DATA

    Addison, TX
    4 days ago
  • $80k - $128k

    ResponsibilitiesPeraton requires a Cyber Threat Hunter to support the Special Operation Command Information Technology Enterprise Contract (SITEC) - 3 EOM.  This position is located at MacDill AFB in Florida.The purpose of the Special Operations Forces Information Technology... 
    Cyber
    Contract work
    Shift work

    Peraton Corporation

    Tallahassee, FL
    3 days ago
  • $104k - $166k

    ResponsibilitiesPeraton's Cyber Mission sector is looking for a Sr Threat Hunter to support a SOC.Location: Chandler, AZ or Washington DC.Role and Responsibility:Conduct proactive, intelligence-driven threat hunting to identify malicious activity that evades traditional... 
    Cyber
    Contract work
    Shift work

    Peraton Corporation

    Washington, VA
    22 hours ago
  • $110k

     ...Cybersecurity Threat Hunter AGE Solutions is a premier technology and professional services company, providing in-depth consulting, advanced...  ...defending complex enterprise environments against advanced cyber threats. In this role, you will go beyond traditional... 
    Cyber
    Full time
    Contract work
    Work at office
    Immediate start

    AGE Solutions LLC

    Columbus, OH
    3 days ago
  • $137k - $263k

     ...Verizon Cybersecurity integrates advanced threat intelligence, governance, cutting-edge...  ...systems and services.As a Distinguished Threat Hunter and operational lead, you will play a...  ...against advanced, persistent, and emerging cyber threats. In this high-impact role, you... 
    Cyber
    Full time
    Temporary work
    Part time
    Work experience placement
    Remote work
    Work from home
    Shift work

    Verizon

    Tallahassee, FL
    3 days ago
  • $101k - $194k

     ...#VTeamLife.What you’ll be doing...The Network Threat Hunting role is crucial for maintaining...  ...time-sensitive analysis during cyber investigations, including active network...  ...looking for...We're looking for a threat hunter with strong critical thinking and analytical... 
    Cyber
    Full time
    Temporary work
    Part time
    Work experience placement
    Work at office
    Work from home
    Shift work
    3 days per week

    Verizon

    Basking Ridge, NJ
    1 day ago
  • $110.8k - $179.23k

     ...accountability, and shared success where your work truly matters.Job SummaryThreat Hunter (MTH) - Job Description Your impactHelp multinational organizations stay one step ahead of adversaries and cyber threats.Collaborate and guide our customers on the best ways to enhance their... 
    Cyber
    Full time
    Remote work
    Visa sponsorship
    Work visa

    Palo Alto Networks

    Austin, TX
    22 hours ago
  • $94.1k - $150k

     ...Position Overview The Cyber Threat Hunter proactively protects enterprise environments from advanced cyber threats by analyzing network, endpoint, and log data to identify malicious activity that may evade conventional security controls. This role establishes normal... 
    Cyber
    Contract work
    Work at office

    ASM Research, An Accenture Federal Services Company

    Phoenix, AZ
    22 hours ago
  • Electrosoft Services, LLC is seeking a Cybersecurity Threat Hunter to proactively search for threats within the network and lead investigations into unusual activity. The role collaborates with Threat Detection and Incident Response teams to analyze logs and network data... 
    Cyber

    Electrosoft

    Columbus, OH
    4 days ago
  •  ...services firm focused on high-profile, high-threat public and private sector customers who...  ...Perks: As recognized members of the Cyber Elite, we work together in partnership to...  ...Senior Incident Responder / Threat Hunter for a potential opportunity with demonstrated... 
    Cyber
    Contract work
    Work experience placement

    ShorePoint

    Albuquerque, NM
    6 days ago
  • $121.56k

     ...community of more than 12,000 banks and financial institutions. The Cyber Fusion Centre (CFC) is looking for a Lead SOC (Security...  ...SOC Analyst, you will provide input to security strategy , the threat hunting program, and control of systems, networks, physical infrastructure... 
    Cyber
    Full time
    Work experience placement
    Casual work
    Overseas
    Shift work

    SWIFT

    Culpeper, VA
    1 day ago
  •  ...Description Job Description Title: Senior Cybersecurity Threat Hunter III Location: Colorado Springs, CO Clearance: TS/SCI with...  ...hands-on experience conducting threat hunting, advanced cyber analysis, or adversary-focused investigations Strong knowledge... 
    Cyber

    Invictus International Consulting, LLC

    Colorado Springs, CO
    a month ago
  • Sabree Software Services, Inc. is seeking a Cyber Threat Hunter to proactively detect, investigate, and mitigate threats within a large enterprise environment. You will base hunts on the HMM-4 approach and use the MITRE ATT&CK framework to identify attacker techniques and... 
    Cyber

    Sabree Software Services, Inc.

    Mc Lean, VA
    4 days ago
  • As a Cyber Threat Hunter, you will be responsible for proactively detecting, investigating, and mitigating cyber threats within our large enterprise environment. Your primary focus will be on hypothesis-based threat hunting utilizing the HMM-4 approach and leveraging the... 
    Cyber

    Sabree Software Services, Inc.

    Mc Lean, VA
    4 days ago
  • $113.2k - $172.6k

     ...opportunities and development for our teams. GENERAL PURPOSE The Security Engineer II position is responsible for proactive threat hunting and cyber threat intelligence analysis to identify emerging threats, mitigate risks, and strengthen the organization's overall... 
    Cyber
    Full time
    Work at office
    Local area
    Remote work
    Night shift

    Ross Stores

    Dublin, CA
    23 days ago
  •  ...Premera is seeking a Threat Response Engineer III on a hybrid basis at our Mountlake Terrace campus. You will act as the spear in investigations, protecting personal and financial data while working within a threat intel and response team. The role requires strong... 
    Cyber

    Jobleads-US

    Mountlake Terrace, WA
    2 days ago
  • Piper Companies seeks a Threat Hunting Investigator for a long term remote consulting opportunity. You will identify insider risk activity...  ...across enterprise environments. The role requires 8+ years in cyber investigations or related fields, expertise in Splunk (SPL,... 
    Cyber
    Remote job

    Piper Companies

    New York, NY
    4 days ago
  • $125k - $150k

     ...prioritizing speed, ownership, and execution over bureaucracy. Senior Threat Hunter Analyst Location: Washington, DC, Ft. Collins, CO, or Kansas...  ...better over time. You work in close coordination with the Cyber Threat Intelligence team, maintaining threat indicator feeds... 
    Cyber
    Full time
    Work experience placement
    Local area
    Remote work
    Flexible hours
    Shift work

    Revolutional, LLC

    Fort Collins, CO
    27 days ago
  •  ...Vision insurance SarelaTech is seeking an experienced Cybersecurity Threat Hunter to support a Department of War (DoW) cybersecurity mission. This position will proactively search for cyber threats that may exist undetected within the network and initiate... 
    Cyber

    Career Listings

    Columbus, OH
    10 days ago
  •  ...Job Description Job Description CYBERSECURITY THREAT HUNTER Location: Columbus, OH Security Clearance: Must possess a Top Secret...  ...approach. Key Responsibilities Proactively searches for cyber threats that exist undetected within the network. Initiates investigations... 
    Cyber

    Horizon Industries

    Columbus, OH
    3 days ago
  •  ...who manages all applications and next steps. Our partner is looking for a Cybersecurity Threat Hunter based in United States. This role focuses on proactively identifying cyber threats that may remain undetected within complex network environments. You will investigate... 
    Cyber
    Remote job
    Full time
    Contract work
    Temporary work

    jobgether

    United States
    20 hours ago
  •  ...Job Description Job Description cFocus Software seeks a Mid Level Cyber Threat Hunter to join our program supporting US Courts in Washington, DC. This position is 4 days a week onsite in DC and one day remote. Required Qualifications include: ~5+ years of experience... 
    Cyber
    Work at office
    Remote work

    cFocus Software Incorporated

    Washington DC
    4 days ago
  •  ...Summary Strategic Operational Solutions (STOPSO) is seeking a Threat Hunter to support the U.S. Army Reserve Command (USARC) Defensive...  ...hypothesis-driven hunts that combine defensive telemetry and cyber threat intelligence. The Threat Hunter develops findings and detection... 
    Cyber
    Work at office
    Local area
    Shift work

    Strategic Operational Solutions

    Fort Bragg, NC
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cyber Threat Hunter. Be the first to apply!