Cyber Threat Hunter
$80k - $110kJobvite
About the Role
We are looking for a Threat Hunter to join our Cyber Threat Intelligence function and run proactive, hypothesis-driven hunts across our environment. This is a dedicated hunting role at the front of a detection pipeline: you will turn intelligence and adversary tradecraft into concrete hunts and turn what you find into detection packages that our tooling team operationalizes and our SOC consumes as tuned, documented alerts.
You will sit at the intersection of threat intelligence, detection engineering, and offensive validation. Working from CTI and from our red teamer's findings, you will hunt for activity that never trips an existing alert, novel techniques, living-off-the-land tradecraft, misconfiguration abuse, and long-dwell intrusions, and close those gaps by feeding durable detections and configuration fixes back into the organization. It is a role for a curious, methodical hunter who is energized by long-horizon investigation rather than the pace of the alert queue.
Location: We are flexible on remote working from home, if you are located in the USA and reside in one of the following states: CA, CO, CT, FL, GA, *IL, KS, MA, MD, ME, NJ, NC, NY, OH, OR, TN, TX, VA, and WA . We have physical offices in Austin, TX and Tampa, FL , if you prefer a hybrid option.
*Onsite interviews may be required for this role.
What You'll Be Doing
- Plan and run hypothesis-driven hunts (intel-led, TTP-led, and behavior-led) across endpoint, identity, cloud, and network telemetry
- Consume CTI and red-team/purple-team findings to prioritize hunts against the adversary behaviors most relevant to us
- Map hunts and findings to MITRE ATT&CK to track coverage and expose blind spots
- Translate hunt findings into detection packages and recommendations, including detection logic, required context and enrichment, and draft SOP guidance, for the tooling team to operationalize
- Partner with the red teamer on purple validation of configuration faults and security-posture gaps
- Surface configuration faults and posture gaps discovered during hunts, and drive recommendations to close them
- Document hypotheses, methods, and outcomes so hunting knowledge lives in reusable artifacts rather than in one person's head
- Contribute threat context and hunt-derived intelligence during declared Sev 1 incidents, in an advisory (non-primary) capacity
- Other duties as needed
Required Qualifications
- 5+ years in a security operations, detection engineering, CTI, or incident response role, with meaningful hands-on threat-hunting responsibility
- Demonstrated experience running hypothesis-driven hunts, forming a hypothesis, testing it against telemetry, and driving it to a conclusion, not solely alert triage
- Strong working knowledge of adversary tactics, techniques, and procedures, and practical fluency with the MITRE ATT&CK framework
- Proficiency querying and pivoting across security telemetry at scale in a SIEM and/or EDR/XDR (e.g., KQL, SPL, or equivalent query languages)
- Solid understanding of endpoint, identity, cloud, and network telemetry, and a sense of what normal and abnormal look like in each
- Ability to turn a hunt finding into a detection recommendation, including logic, supporting context, and fidelity/signal-to-noise considerations
- Understanding of the detection lifecycle and why signal-to-noise quality matters to a SOC
- Clear written communication for documentation, detection packages, and SOP recommendations
- Able to plan and sustain long-horizon hunt campaigns with limited day-to-day direction
Preferred Qualifications
- Experience consuming red-team or purple-team output to drive and prioritize hunts
- Scripting for automation and enrichment (Python preferred)
- Familiarity with detection-as-code workflows and version-controlled detection content
- Depth in cloud-native and SaaS telemetry (CloudTrail, Entra ID/Azure AD, SaaS audit logs)
- Experience with a threat intelligence platform (TIP) and structured intel workflows
- Exposure to an IR-capable or standing-response team environment
- Relevant certifications, one or more (preferred, not required):
- GCTI, GCFA, GCDA, GCIA, or similar GIAC certifications
- OSCP or comparable (for offensive-tradecraft awareness)
- Cloud security certifications (AWS, Azure, or GCP), or equivalent
Key Skills
- Adversary mindset, thinks in behaviors and TTPs, not indicators alone
- Patience and persistence for long-horizon threads that may not pay off immediately
- Strong analytical and data-pivoting skills across large, varied datasets
- Translates findings into durable, reusable detections and clear documentation
- Communicates effectively across CTI, tooling, and SOC audiences
- Curiosity and a genuine drive to find what existing alerting misses
About Us
NinjaOne unifies IT to simplify work for nearly 40,000 customers in 140+ countries. The NinjaOne Unified IT Operations Platform delivers endpoint management, autonomous patching, backup, and remote access in a single console to improve efficiency, increase resilience, and reduce spend. By automating IT and managing all endpoints, organizations give employees a great technology experience at work. NinjaOne is obsessed with customer success and has retained a 98% customer satisfaction score for more than 5 years.
What You'll Love
- A collaborative, kind, and curious community
- Full-time work that is hybrid remote, honoring your flexibility needs
- A comprehensive benefits package, including medical, dental, and vision insurance
- A 401(k) plan to help you prepare for your financial future
- Unlimited PTO that prioritizes your work-life balance
- Opportunity for growth and advancement
Additional Information
This position is NOT eligible for Visa sponsorship. Due to federal government security requirements associated with our FedRAMP-authorized environment, candidates must be U.S. citizens or lawful permanent residents.
Due to operational policies, NinjaOne is unable to hire for this role within the city limits of Chicago. We will consider all qualified candidates who reside outside of the city proper or are willing to self-relocate.
Starting pay for the successful applicant depends on a variety of job-related factors, including but not limited to location, market demands, experience, job-related knowledge, and skills. The benefits available for this position include medical, dental, vision, 401(k) plan, life insurance coverage, and PTO. For roles based in California, Colorado, Maryland, New Jersey, or Washington, the base salary hiring range for this position is $80,000 to $110,000 per year.
For roles based in New York, the base salary hiring range for this position is $80,000 to $110,000 per year.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, genetic information, marital status, veteran status, or any other status protected by applicable law. We are committed to providing an inclusive and diverse work environment.
#J-18808-Ljbffr- Job Title: Senior Exposure Threat HunterLocation: Austin, USARole SummaryWe are seeking an... ...and highly analytical Exposure Threat Hunter to join our Information Security team. This... ...investigative workflows.Solid understanding of the cyber-attack lifecycle and common attacker...CyberFull timeWork at officeLocal area
$110.8k - $179.23k
...accountability, and shared success where your work truly matters.Job SummaryThreat Hunter (MTH) - Job Description Your impactHelp multinational organizations stay one step ahead of adversaries and cyber threats.Collaborate and guide our customers on the best ways to enhance their...CyberFull timeRemote workVisa sponsorshipWork visa- A cybersecurity firm in Austin, Texas is looking for a Threat Intelligence & Testing Manager to lead a team focused on cyber threat analysis and testing. The ideal candidate should have extensive experience in cyber threat intelligence, strong leadership abilities, and...Cyber
- NXP Semiconductors—an Austin, Texas based cybersecurity role—seeks a Cyber Threat Intelligence & Exposure Management Analyst to identify, analyze, and communicate threats and exposures across the enterprise. The role combines threat intel, attack surface visibility, vulnerability...Cyber
- Cosmenta in Austin, Texas is seeking a Cybersecurity Analyst to safeguard its digital infrastructure against evolving threats. The role involves monitoring systems for vulnerabilities, detecting anomalies, and responding promptly to security incidents. You will be responsible...Cyber
$163.4k - $322.1k
Position Summary Senior Manager, Advanced Cyber Threat Response, Forensics and Technical Remediation Integration LeadDeloitte’s Cyber Defense & Resilience practice helps organizations prepare for, respond to, and recover from cyber incidents. As a Senior Manager...CyberLocal areaVisa sponsorship$178.5k - $265.1k
...- and they push us to ensure we take care of ourselves, each other, and our communities.Job Summary:This job is recognized as a cyber threat management expert, independently resolving complex challenges and providing strategic direction across the security domain. It involves...CyberFull timeWork at officeLocal areaImmediate startFlexible hours- Job DescriptionThe Role: The Cyber Threat Intelligence Analyst is a critical individual-contributor role within GM's Security Operations organization that turns internal and external threat and vulnerability data into timely, actionable intelligence—directly enabling GM...CyberFull timeLocal areaWork from homeRelocation package
$160k - $250k
...products. In this role, you will bring your in-depth knowledge of the Threat Detection market to help guide the evolution of CrowdStrike’s... ...technologies. If you are passionate about staying ahead of cyber threats and have a proven track record in product management, we...CyberFull timeWork experience placementWork at officeLocal areaRemote workWorldwide3 days per week1 day per week$132.5k - $338.3k
...conventional practices. And we are looking to add an experienced Threat Informed Defense Senior Manager to an already outstanding team.... ...customized turnkey solutions. We blend risk strategy, digital identity, cyber defense, application security and managed service solutions to...CyberFull timeWork experience placementLive inWork at officeLocal area- ...each day to pursue your passions.THE CHALLENGEWe are looking for a Threat Intelligence Engineer. In this role, you will be on the front... ...Intelligence Operations: Support the day-to-day operations of the cyber threat intelligence (CTI) program by managing threat feeds,...CyberCasual workFlexible hours
- Role SummaryThe Cyber Threat Intelligence & Exposure Management Analyst is responsible for identifying, analyzing, and communicating cyber threats and organizational exposures that present risk to the enterprise. This role combines cyber threat intelligence, attack surface...CyberFull timeWork at officeLocal area
- ...maintains a strong risk posture through independent oversight and risk-informed assurance activities. TRM has an opening in the Cyber Threat & Insider Risk discipline for an individual contributor to serve as the primary subject matter expert for second line oversight,...CyberFull timeWork at officeWork from homeRelocationMonday to Friday
- ...committed to helping secure both Cloudflare and our customers. The Threat Detection Automation and Intelligence Team is responsible for... ...detect (MTTD) and mean time to respond (MTTR) to sophisticated cyber threats. Responsibilities Intelligence Collection & Analysis: Proactively...CyberTemporary workLocal areaFlexible hours
- CrowdStrike is seeking a self-starting Security Researcher to join our Counter Adversary Operations Team in the Austin area. You will track Latam-language eCrime actors, collect unique, timely intelligence from diverse sources including the deep and dark web, and deliver...Cyber
- ...test current capabilities, processes, and documentation, drive new cyber detection capability, and establish the baseline for strategic... ...into improved detections, integrations, documentation, and threat hunting outcomes.Support AO innovation priorities across platforms...CyberFull timeLocal areaWork from homeRelocation package
- ...Cyber Incident Response Analyst Location: Austin, TX / San Antonio, TX (Onsite) Duration: 12 Months Contract Interview... ...Forensics, Windows & Linux Security, SIEM, EDR, IDS/IPS, Threat Hunting, Malware Analysis, Memory & Disk Forensics, MITRE ATT&CK...CyberContract work
$185k
...TX or Austin, TX (3 days a week onsite). This individual will be joining the Cyber organization, and will lead the Vulnerability Management, Attack Surface Management, and Continuous Threat Exposure Management (CTEM) programs, with responsibility for identifying, prioritizing...Cyber3 days per week$98k - $134k
...best in the cybersecurity industry, with a deep technical understanding of cybersecurity products, integrations, and the critical cyber threats facing our potential customers' environments. Your ImpactLearn the technical aspects and business value of Palo Alto Networks...CyberFull timeWork at officeVisa sponsorshipWork visa$105.4k - $207.8k
...Summary As a Physical Security Senior Consultant in Deloitte’s Cyber Defense & Resilience team, you will help clients strengthen... ...be responsible for:Conducting physical security assessments, threat and vulnerability analyses, and risk evaluations for facilities,...CyberLocal areaVisa sponsorship$163.4k - $322.1k
...environmentsConducting security risk assessments, vulnerability assessments, and threat evaluations and developing mitigation strategies and security... ...mentor and provide clear guidance to othersThe teamDeloitte’s Cyber Defense & Resilience practice helps organizations protect people...CyberLocal areaVisa sponsorship- The Cyber Security Architect role is primarily responsible for designing, building, and maintaining secure data, systems and applications... ...identity access management systemsEvaluate new cybersecurity threats and IT trends and develop effective security measuresWork very closely...CyberFull timeFlexible hours
$239k - $278.75k
...continuous self-improvement and learning to sustain technical leadership across relevant technologies (e.g., security technologies, cyber threat intelligence, risk and regulatory topics, emerging technologies)Work closely with Sales and Solution Consulting leadership, Unit...CyberFull timeRemote workVisa sponsorshipWork visa- ...the Principal Advisor will drive thought leadership and inspired cyber security solutions powered by our ecosystem of people, products,... ...responsive communicationThorough understanding of the current threat landscape, vulnerabilities, and defensive controls as it pertains...CyberFull timeLocal areaRemote workWork from home
$134.5k - $265.1k
Position Summary Our Deloitte Cyber Defense & Resilience team recognizes that resilient organizations must protect not only data... ...Security consulting team to help clients address evolving threats through integrated security strategies, technologies, and managed...CyberContract workLocal areaVisa sponsorship$99k - $232k
...using systems like Azure Active Directory and CyberArk Management- Developing secure systems and solutions to safeguard data from cyber threats- Leading teams in the execution of cybersecurity initiatives and mentoring junior staff- Analyzing system interactions to...CyberFull timeH1b$132.4k - $251.6k
...meet the needs of today’s mission and stay ahead of tomorrow’s threat. We deliver solutions that help our nation and allies defend freedoms... ...is responsible for researching, developing, and integrating cyber-compliant, standardized system solutions using innovative designs...CyberTemporary workWork experience placementWork at officeRemote workWork from homeRelocationFlexible hours- ...Job Description Job Description We are seeking an experienced Cyber Manager for a contract-to-hire (W2 only) hybrid role in Austin,... ...management. * Understanding SIEM, security monitoring, and threat detection. * Excellent communication, presentation, and client...CyberContract workLocal area
- Position Summary Analyst, Cyber Strategy & TransformationOur Deloitte Cyber team understands the unique challenges and opportunities... ...to powerful solutions that help clients navigate an evolving threat landscape. Through solutions and managed services that simplify...CyberVisa sponsorship
$124k - $280k
...PrivacyManagement LevelSenior ManagerJob Description & SummaryAt PwC, our people in cybersecurity focus on protecting organisations from cyber threats through advanced technologies and strategies. They work to identify vulnerabilities, develop secure systems, and provide...CyberFull timeH1b
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Threat Hunter. Be the first to apply!



