Cyber Threat Hunter
$80k - $110kNinjaOne
Description About the Role
We are looking for a Threat Hunter to join our Cyber Threat Intelligence function and run proactive, hypothesis-driven hunts across our environment. This is a dedicated hunting role at the front of a detection pipeline: you will turn intelligence and adversary tradecraft into concrete hunts and turn what you find into detection packages that our tooling team operationalizes and our SOC consumes as tuned, documented alerts. You will sit at the intersection of threat intelligence, detection engineering, and offensive validation. Working from CTI and from our red teamer's findings, you will hunt for activity that never trips an existing alert, novel techniques, living-off-the-land tradecraft, misconfiguration abuse, and long-dwell intrusions, and close those gaps by feeding durable detections and configuration fixes back into the organization. It is a role for a curious, methodical hunter who is energized by long-horizon investigation rather than the pace of the alert queue. Location: We are flexible on remote working from home, if you are located in the USA and reside in one of the following states: CA, CO, CT, FL, GA, *IL, KS, MA, MD, ME, NJ, NC, NY, OH, OR, TN, TX, VA, and WA . We have physical offices in Austin, TX and Tampa, FL , if you prefer a hybrid option. *Onsite interviews may be required for this role. What You'll Be Doing
NinjaOne unifies IT to simplify work for nearly 40,000 customers in 140+ countries. The NinjaOne Unified IT Operations Platform delivers endpoint management, autonomous patching, backup, and remote access in a single console to improve efficiency, increase resilience, and reduce spend. By automating IT and managing all endpoints, organizations give employees a great technology experience at work. NinjaOne is obsessed with customer success and has retained a 98% customer satisfaction score for more than 5 years. What You'll Love
Additional Information
This position is NOT eligible for Visa sponsorship. Due to federal government security requirements associated with our FedRAMP-authorized environment, candidates must be U.S. citizens or lawful permanent residents. Due to operational policies, NinjaOne is unable to hire for this role within the city limits of Chicago. We will consider all qualified candidates who reside outside of the city proper or are willing to self-relocate. Starting pay for the successful applicant depends on a variety of job-related factors, including but not limited to location, market demands, experience, job-related knowledge, and skills. The benefits available for this position include medical, dental, vision, 401(k) plan, life insurance coverage, and PTO. For roles based in California, Colorado, Maryland, New Jersey, or Washington, the base salary hiring range for this position is $80,000 to $110,000 per year. For roles based in New York, the base salary hiring range for this position is $80,000 to $110,000 per year. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, genetic information, marital status, veteran status, or any other status protected by applicable law. We are committed to providing an inclusive and diverse work environment.
We are looking for a Threat Hunter to join our Cyber Threat Intelligence function and run proactive, hypothesis-driven hunts across our environment. This is a dedicated hunting role at the front of a detection pipeline: you will turn intelligence and adversary tradecraft into concrete hunts and turn what you find into detection packages that our tooling team operationalizes and our SOC consumes as tuned, documented alerts. You will sit at the intersection of threat intelligence, detection engineering, and offensive validation. Working from CTI and from our red teamer's findings, you will hunt for activity that never trips an existing alert, novel techniques, living-off-the-land tradecraft, misconfiguration abuse, and long-dwell intrusions, and close those gaps by feeding durable detections and configuration fixes back into the organization. It is a role for a curious, methodical hunter who is energized by long-horizon investigation rather than the pace of the alert queue. Location: We are flexible on remote working from home, if you are located in the USA and reside in one of the following states: CA, CO, CT, FL, GA, *IL, KS, MA, MD, ME, NJ, NC, NY, OH, OR, TN, TX, VA, and WA . We have physical offices in Austin, TX and Tampa, FL , if you prefer a hybrid option. *Onsite interviews may be required for this role. What You'll Be Doing
- Plan and run hypothesis-driven hunts (intel-led, TTP-led, and behavior-led) across endpoint, identity, cloud, and network telemetry
- Consume CTI and red-team/purple-team findings to prioritize hunts against the adversary behaviors most relevant to us
- Map hunts and findings to MITRE ATT&CK to track coverage and expose blind spots
- Translate hunt findings into detection packages and recommendations, including detection logic, required context and enrichment, and draft SOP guidance, for the tooling team to operationalize
- Partner with the red teamer on purple validation of configuration faults and security-posture gaps
- Surface configuration faults and posture gaps discovered during hunts, and drive recommendations to close them
- Document hypotheses, methods, and outcomes so hunting knowledge lives in reusable artifacts rather than in one person's head
- Contribute threat context and hunt-derived intelligence during declared Sev 1 incidents, in an advisory (non-primary) capacity
- Other duties as needed
- 5+ years in a security operations, detection engineering, CTI, or incident response role, with meaningful hands-on threat-hunting responsibility
- Demonstrated experience running hypothesis-driven hunts, forming a hypothesis, testing it against telemetry, and driving it to a conclusion, not solely alert triage
- Strong working knowledge of adversary tactics, techniques, and procedures, and practical fluency with the MITRE ATT&CK framework
- Proficiency querying and pivoting across security telemetry at scale in a SIEM and/or EDR/XDR (e.g., KQL, SPL, or equivalent query languages)
- Solid understanding of endpoint, identity, cloud, and network telemetry, and a sense of what normal and abnormal look like in each
- Ability to turn a hunt finding into a detection recommendation, including logic, supporting context, and fidelity/signal-to-noise considerations
- Understanding of the detection lifecycle and why signal-to-noise quality matters to a SOC
- Clear written communication for documentation, detection packages, and SOP recommendations
- Able to plan and sustain long-horizon hunt campaigns with limited day-to-day direction
- Experience consuming red-team or purple-team output to drive and prioritize hunts
- Scripting for automation and enrichment (Python preferred)
- Familiarity with detection-as-code workflows and version-controlled detection content
- Depth in cloud-native and SaaS telemetry (CloudTrail, Entra ID/Azure AD, SaaS audit logs)
- Experience with a threat intelligence platform (TIP) and structured intel workflows
- Exposure to an IR-capable or standing-response team environment
- Relevant certifications, one or more (preferred, not required):
- GCTI, GCFA, GCDA, GCIA, or similar GIAC certifications
- OSCP or comparable (for offensive-tradecraft awareness)
- Cloud security certifications (AWS, Azure, or GCP), or equivalent
- Adversary mindset, thinks in behaviors and TTPs, not indicators alone
- Patience and persistence for long-horizon threads that may not pay off immediately
- Strong analytical and data-pivoting skills across large, varied datasets
- Translates findings into durable, reusable detections and clear documentation
- Communicates effectively across CTI, tooling, and SOC audiences
- Curiosity and a genuine drive to find what existing alerting misses
NinjaOne unifies IT to simplify work for nearly 40,000 customers in 140+ countries. The NinjaOne Unified IT Operations Platform delivers endpoint management, autonomous patching, backup, and remote access in a single console to improve efficiency, increase resilience, and reduce spend. By automating IT and managing all endpoints, organizations give employees a great technology experience at work. NinjaOne is obsessed with customer success and has retained a 98% customer satisfaction score for more than 5 years. What You'll Love
- A collaborative, kind, and curious community
- Full-time work that is hybrid remote, honoring your flexibility needs
- A comprehensive benefits package, including medical, dental, and vision insurance
- A 401(k) plan to help you prepare for your financial future
- Unlimited PTO that prioritizes your work-life balance
- Opportunity for growth and advancement
Additional Information
This position is NOT eligible for Visa sponsorship. Due to federal government security requirements associated with our FedRAMP-authorized environment, candidates must be U.S. citizens or lawful permanent residents. Due to operational policies, NinjaOne is unable to hire for this role within the city limits of Chicago. We will consider all qualified candidates who reside outside of the city proper or are willing to self-relocate. Starting pay for the successful applicant depends on a variety of job-related factors, including but not limited to location, market demands, experience, job-related knowledge, and skills. The benefits available for this position include medical, dental, vision, 401(k) plan, life insurance coverage, and PTO. For roles based in California, Colorado, Maryland, New Jersey, or Washington, the base salary hiring range for this position is $80,000 to $110,000 per year. For roles based in New York, the base salary hiring range for this position is $80,000 to $110,000 per year. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, genetic information, marital status, veteran status, or any other status protected by applicable law. We are committed to providing an inclusive and diverse work environment.
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Cyber Threat Hunter in United States vacancy
- DescriptionSAIC is seeking Cyber Threat & Vulnerability Hunter to join its Blue Team Vulnerability Assessment Program in Chantilly, Virginia. This position requires an active TS/SCI Clearance with Polygraph.Positional Overview: Perform technical reviews and analysis of...CyberWork experience placement
$62k - $141k
Cyber Threat Hunter, MidThe Opportunity:The Threat Hunter supports a Cybersecurity Operations Division by proactively identifying malicious activity, uncovering hidden threats, and strengthening the organization’s defensive posture. This role conducts hypothesis‑driven...CyberFull timeContract workPart timeWork at officeLocal areaRemote work- ...worldwide.Job Description*** This position is contingent upon contract award ***OverviewSOSi is seeking a Senior Threat Hunter to support proactive cyber defense activities in alignment with our customer. This role is responsible for conducting threat hunting operations...CyberContract workWork at officeWorldwideMonday to FridayWeekend workAfternoon shift
- ...can build, innovate, and secure your career. Sentar is seeking a Cybersecurity Threat Hunter in Columbus, OH! Role Description: The DLA JETS 2.0 Cyber Security Services Provider Support Services (CSSP) effort focuses on providing...CyberTemporary workFor contractorsFlexible hours
- ...Defense and Federal customers. We are hiring a Cybersecurity Threat Hunter to support an enterprise-level program within a federal environment... ...Responsibilities Proactively identifies and investigates cyber threats that may be operating undetected within the network,...CyberFor contractorsWork at officeLocal areaRemote work
$120k - $135k
## Cybersecurity Threat HunterApplylocations: (North America) Adelphi, MDtime type: Full... ...timeStateside Exempt 3.4**Cybersecurity Threat Hunter****Security Operations****Full-time,... ...consultation on threat hunting methodologies and cyber adversary techniques.* Maintain awareness...CyberFull timePart timeImmediate startFlexible hours- Job Title: Senior Exposure Threat HunterLocation: Austin, USARole SummaryWe are seeking an... ...and highly analytical Exposure Threat Hunter to join our Information Security team. This... ...investigative workflows.Solid understanding of the cyber-attack lifecycle and common attacker...CyberFull timeWork at officeLocal area
$106.58k - $177.63k
...organization, apply now.We are currently seeking a Security Analysis Threat Hunter - Addison, TX Hybrid to join our team in Addison, Texas (US-TX... ...intelligence feedsBasic Requirements10+ years’ experience in Cyber SecurityAdditional Skills & ExperienceStrong understanding of...CyberFull timeTemporary workWork at officeLocal areaRemote workFlexible hours$80k - $128k
ResponsibilitiesPeraton requires a Cyber Threat Hunter to support the Special Operation Command Information Technology Enterprise Contract (SITEC) - 3 EOM. This position is located at MacDill AFB in Florida.The purpose of the Special Operations Forces Information Technology...CyberContract workShift work$104k - $166k
ResponsibilitiesPeraton's Cyber Mission sector is looking for a Sr Threat Hunter to support a SOC.Location: Chandler, AZ or Washington DC.Role and Responsibility:Conduct proactive, intelligence-driven threat hunting to identify malicious activity that evades traditional...CyberContract workShift work$110k
...Cybersecurity Threat Hunter AGE Solutions is a premier technology and professional services company, providing in-depth consulting, advanced... ...defending complex enterprise environments against advanced cyber threats. In this role, you will go beyond traditional...CyberFull timeContract workWork at officeImmediate start$137k - $263k
...Verizon Cybersecurity integrates advanced threat intelligence, governance, cutting-edge... ...systems and services.As a Distinguished Threat Hunter and operational lead, you will play a... ...against advanced, persistent, and emerging cyber threats. In this high-impact role, you...CyberFull timeTemporary workPart timeWork experience placementRemote workWork from homeShift work$101k - $194k
...#VTeamLife.What you’ll be doing...The Network Threat Hunting role is crucial for maintaining... ...time-sensitive analysis during cyber investigations, including active network... ...looking for...We're looking for a threat hunter with strong critical thinking and analytical...CyberFull timeTemporary workPart timeWork experience placementWork at officeWork from homeShift work3 days per week$110.8k - $179.23k
...accountability, and shared success where your work truly matters.Job SummaryThreat Hunter (MTH) - Job Description Your impactHelp multinational organizations stay one step ahead of adversaries and cyber threats.Collaborate and guide our customers on the best ways to enhance their...CyberFull timeRemote workVisa sponsorshipWork visa$94.1k - $150k
...Position Overview The Cyber Threat Hunter proactively protects enterprise environments from advanced cyber threats by analyzing network, endpoint, and log data to identify malicious activity that may evade conventional security controls. This role establishes normal...CyberContract workWork at office- Electrosoft Services, LLC is seeking a Cybersecurity Threat Hunter to proactively search for threats within the network and lead investigations into unusual activity. The role collaborates with Threat Detection and Incident Response teams to analyze logs and network data...Cyber
- ...services firm focused on high-profile, high-threat public and private sector customers who... ...Perks: As recognized members of the Cyber Elite, we work together in partnership to... ...Senior Incident Responder / Threat Hunter for a potential opportunity with demonstrated...CyberContract workWork experience placement
$121.56k
...community of more than 12,000 banks and financial institutions. The Cyber Fusion Centre (CFC) is looking for a Lead SOC (Security... ...SOC Analyst, you will provide input to security strategy , the threat hunting program, and control of systems, networks, physical infrastructure...CyberFull timeWork experience placementCasual workOverseasShift work- ...Description Job Description Title: Senior Cybersecurity Threat Hunter III Location: Colorado Springs, CO Clearance: TS/SCI with... ...hands-on experience conducting threat hunting, advanced cyber analysis, or adversary-focused investigations Strong knowledge...Cyber
- Sabree Software Services, Inc. is seeking a Cyber Threat Hunter to proactively detect, investigate, and mitigate threats within a large enterprise environment. You will base hunts on the HMM-4 approach and use the MITRE ATT&CK framework to identify attacker techniques and...Cyber
- As a Cyber Threat Hunter, you will be responsible for proactively detecting, investigating, and mitigating cyber threats within our large enterprise environment. Your primary focus will be on hypothesis-based threat hunting utilizing the HMM-4 approach and leveraging the...Cyber
$113.2k - $172.6k
...opportunities and development for our teams. GENERAL PURPOSE The Security Engineer II position is responsible for proactive threat hunting and cyber threat intelligence analysis to identify emerging threats, mitigate risks, and strengthen the organization's overall...CyberFull timeWork at officeLocal areaRemote workNight shift- ...Premera is seeking a Threat Response Engineer III on a hybrid basis at our Mountlake Terrace campus. You will act as the spear in investigations, protecting personal and financial data while working within a threat intel and response team. The role requires strong...Cyber
- Piper Companies seeks a Threat Hunting Investigator for a long term remote consulting opportunity. You will identify insider risk activity... ...across enterprise environments. The role requires 8+ years in cyber investigations or related fields, expertise in Splunk (SPL,...CyberRemote job
$125k - $150k
...prioritizing speed, ownership, and execution over bureaucracy. Senior Threat Hunter Analyst Location: Washington, DC, Ft. Collins, CO, or Kansas... ...better over time. You work in close coordination with the Cyber Threat Intelligence team, maintaining threat indicator feeds...CyberFull timeWork experience placementLocal areaRemote workFlexible hoursShift work- ...Vision insurance SarelaTech is seeking an experienced Cybersecurity Threat Hunter to support a Department of War (DoW) cybersecurity mission. This position will proactively search for cyber threats that may exist undetected within the network and initiate...Cyber
- ...Job Description Job Description CYBERSECURITY THREAT HUNTER Location: Columbus, OH Security Clearance: Must possess a Top Secret... ...approach. Key Responsibilities Proactively searches for cyber threats that exist undetected within the network. Initiates investigations...Cyber
- ...who manages all applications and next steps. Our partner is looking for a Cybersecurity Threat Hunter based in United States. This role focuses on proactively identifying cyber threats that may remain undetected within complex network environments. You will investigate...CyberRemote jobFull timeContract workTemporary work
- ...Job Description Job Description cFocus Software seeks a Mid Level Cyber Threat Hunter to join our program supporting US Courts in Washington, DC. This position is 4 days a week onsite in DC and one day remote. Required Qualifications include: ~5+ years of experience...CyberWork at officeRemote work
- ...Summary Strategic Operational Solutions (STOPSO) is seeking a Threat Hunter to support the U.S. Army Reserve Command (USARC) Defensive... ...hypothesis-driven hunts that combine defensive telemetry and cyber threat intelligence. The Threat Hunter develops findings and detection...CyberWork at officeLocal areaShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Threat Hunter. Be the first to apply!





