Source Job

US Unlimited PTO

  • Hunt for emerging exploitation activity and attacker infrastructure across VulnCheck's data.
  • Turn discoveries into durable detections including rules, queries, and tooling.
  • Investigate payloads and post-exploitation activity and produce threat intelligence.

Threat Hunting Detection Engineering Malware Analysis Scripting

20 jobs similar to Principal Threat Hunter

Jobs ranked by similarity.

US 12w maternity 12w paternity

  • Triage, investigate, and respond to alerts from the Huntress platform, reviewing EDR telemetry and forensic artifacts.
  • Perform tactical malware analysis and investigate suspicious M365 activity to determine root cause and provide remediations.
  • Assist in escalations, contribute to detection engineering, and collaborate on projects to improve analyst and partner outcomes.

Huntress is a fully remote, global team of cybersecurity experts on a mission to break down barriers to security. Founded in 2015 by former NSA operators, they protect over 4 million endpoints with enterprise-grade products, serving underresourced IT teams.

US

  • Conduct vulnerability research to identify net-new vulnerabilities across operating systems, platforms, and devices.
  • Reverse engineer firmware and software to author original exploits and detection artifacts.
  • Apply agentic approaches to scale vulnerability discovery and exploit development.

VulnCheck delivers structured exploit intelligence on what is actively weaponized in the wild. Founded in 2021, it has a transparent, collaborative culture with a team of smart, humble, and supportive experts.

Global 12w maternity 12w paternity

  • Lead incident response across platforms and applications, from triage to recovery.
  • Hunt proactively for threats using system logs, user behavior, and threat intelligence.
  • Build and automate incident response workflows and strengthen detection with MITRE ATT&CK.

Xplor provides cloud-based technology solutions that help small and medium-sized businesses manage operations and get paid securely. With over 130,000 businesses in 72+ countries processing $47B annually, the company fosters a culture of simplicity, purpose, and community.

US

  • Monitor and analyze sophisticated cyber threats targeting Anduril's products, infrastructure, and personnel.
  • Research and anticipate emerging technical trends in the threat landscape, collaborating with detection and response teams.
  • Enhance tooling for threat actor tracking and intelligence data integration, engaging with external partners.

Anduril Industries is a defense technology company focused on transforming military capabilities with advanced technology, including AI-powered systems and autonomy. The company is known for its fast-paced, innovative culture and its commitment to bringing cutting-edge solutions to the defense industry.

Philippines

  • Monitor customer environments on the ERM intelligence platform and produce actionable alerts and reports.
  • Investigate urgent issues like cyber attacks, including threat actors and techniques.
  • Resolve Tier 1 technical issues, answer follow-ups, and troubleshoot complex systems.

Check Point Infinity External Risk Management, also known as Cyberint, continuously reduces external cyber risk with a unified solution. We are a team focused on managing and mitigating external cyber threats for customers.

Global

  • Analyze data to identify confirmed relationships and document threat actor tactics.
  • Initiate communication with international government agencies and build relationships.
  • Respond promptly to user needs and stay abreast of industry trends.

Kodex is a secure data exchange platform that revolutionizes how organizations handle sensitive subpoenas and data requests from law enforcement and government agencies. Backed by leading investors like Andreessen Horowitz and Y Combinator, the company is growing, innovative, and trusted by over 15,000 government agencies in 190 countries.

Poland

  • Lead investigation and resolution of complex cybersecurity incidents in the Security Operations Centre.
  • Analyze and correlate security events from SIEM, IDS, EDR, and other sources.
  • Conduct digital forensic investigations and provide expert guidance throughout the incident response lifecycle.

Eurofins Scientific is an international life sciences company providing analytical testing services to make life and the environment safer, healthier, and more sustainable. With over 65,000 employees across 950+ laboratories in 60 countries, they are a global leader in testing and laboratory services.

Argentina

  • Perform log source onboarding and telemetry analysis to support security assessments.
  • Write and tune detection logic, cut false positives, and build content for coverage gaps.
  • Conduct vulnerability analysis and turn scanner output into prioritized remediation.

EVOCS empowers businesses with advisory expertise and technology solutions to help them grow and prosper. Founded by a team of passionate experts, we have grown into a trusted partner with a commitment to quality, consistency, and client success, operating with an employee-managed culture.

$171,500–$245,000/yr
US

  • Dissect and outmaneuver sophisticated cyber attack techniques across endpoint and cloud environments.
  • Translate complex threat research into scalable detection recommendations and engineer attack code.
  • Collaborate with detection engineers, intelligence analysts, and threat hunters to prioritize and refine deliverables.

Zscaler provides a cloud security platform that securely connects users to applications, protecting customers from cyberattacks and data loss. It is the world's largest in-line cloud security platform with an AI-native culture.

$120,000–$180,000/yr
Unlimited PTO

  • Own detection problems end-to-end, from emerging threats to production coverage, using AI to automate repetitive investigative work.
  • Partner with Product and Engineering on signals, detection logic, and validation, and work with customers and GTM on real-world TTPs.
  • Bring deep practitioner judgment from detection engineering, SOC/IR, or threat intelligence, and turn messy failures into durable fixes.

Doppel builds an AI-native platform for social engineering defense, protecting enterprises from phishing, impersonation, and fraud. Backed by top investors, this Series C startup is growing fast with a remote-first culture that values respect, collaboration, and meaningful work.

$144,300–$216,500/yr
US

  • Proactively hunt for advanced threats and dissect complex fraud vectors using hypothesis-driven threat hunting operations.
  • Apply and enrich the FT3 taxonomy to standardize threat intelligence across kill chain phases and API endpoints.
  • Collaborate cross-functionally to integrate threat intelligence, build agentic simulation workflows, and eliminate product vulnerabilities.

Stripe is a financial infrastructure platform for businesses, enabling millions of companies to accept payments and grow revenue. They are a large, global company with a mission to increase the GDP of the internet and a culture of innovation and collaboration.

Brazil

  • Work hands-on with IBM QRadar to support security monitoring, detection, and investigation.
  • Create and maintain detection rules and use cases to identify suspicious activity.
  • Perform threat hunting activities to investigate potential threats and improve detection.

Our partner is a cybersecurity firm specializing in SIEM and security operations, particularly with IBM QRadar. They offer a structured career plan with semi-annual reviews and a remote-first culture, supporting large-scale Security Operations Center initiatives.

United States

  • Independently triage security alerts and incident reports.
  • Investigate incidents using forensic and threat hunting skills.
  • Drive incidents to closure and enhance response platforms.

LinkedIn is the world's largest professional network, built to create economic opportunity for every member of the global workforce. The company is committed to a culture built on trust, care, inclusion, and fun, offering transformational opportunities for employees.

US

  • Design and implement scalable detection logic to identify insider threats and data exfiltration across corporate and production environments.
  • Conduct proactive threat hunting and incident response, collaborating with HR, Legal, and engineering teams during complex investigations.
  • Develop automation and detection models using Python and SQL to strengthen security response capabilities and reduce risk exposure.

The company is a technology organization specializing in security and threat detection. They operate in a fast-paced, collaborative environment with a focus on insider threat prevention and response.

Europe

  • Conduct research across open and restricted-access sources to uncover emerging threats and actor behaviors.
  • Produce clear, concise, and actionable intelligence reporting for technical and non-technical audiences.
  • Collaborate with a globally distributed team while operating autonomously on proactive research initiatives.

Jobgether uses AI-powered matching to ensure applications are reviewed quickly and fairly. The company fosters a remote-friendly culture built on trust, collaboration, and autonomy.

US

  • Support the security team by monitoring and triaging security activity, investigating potential threats, and improving security operations across endpoint, network, and cloud platforms.
  • Assist with developing SIEM detection rules, analyzing security telemetry for anomalous behavior, and conducting targeted threat-hunting activities.
  • Work with vulnerability management, threat intelligence, and documentation to strengthen security practices and ensure adherence to policies.

SimSpace is an AI Proving Ground that helps organizations train, test, and outmaneuver adversaries through realistic cyber simulations. Founded in 2015 by experts from U.S. Cyber Command and MIT Lincoln Laboratory, the company fosters a culture of continuous learning and professional growth, consistently outperforming industry benchmarks in internal mobility and promotions.

$165,000–$175,000/yr
US 12w maternity 12w paternity

  • Partner with customers to increase their security posture by reviewing potential threats and positioning Huntress as a solution.
  • Collaborate across Sales, Marketing, Support, and Engineering to voice customer needs and drive improvements in a fast-moving environment.
  • Provide technical first impressions by diving into product details and offering insightful guidance to prospective customers.

Founded in 2015 by former NSA cyber operators, Huntress is a remote-first team working to make enterprise-grade cybersecurity accessible to businesses of all sizes. They now secure more than 5 million endpoints and 14 million identities worldwide, backed by a 24/7 human-led Security Operations Center.

  • Proactively search for signs of malicious activities within network and systems.
  • Swiftly assess and prioritize security incidents to minimize potential impact.
  • Participate in incident response, analyze phishing, create user education, and dissect malware.

They are a tech pioneer offering adult entertainment and games on safe, popular platforms. With an international team of dynamic innovators, they focus on safe user experiences and community empowerment, with offices in Montreal, Austin, and Nicosia.

$157,675–$238,500/yr
US

  • Build, deploy, and continuously improve MITRE ATT&CK–aligned detections across cloud, endpoint, identity, email, and application telemetry with clear false-positive thresholds.
  • Own the full detection lifecycle from hypothesis and data validation through deployment, tuning, and retirement.
  • Advance the detection-as-code platform with version control, peer review, automated testing, CI/CD, and improved pipeline reliability and observability.

Samsara is the pioneer of the Connected Operations™ Cloud, helping organizations that depend on physical operations to harness IoT data for actionable insights. They are a recently public company with a high-caliber team, embracing a flexible working model that supports remote and hybrid work.

$500–$500/mo
APAC

  • Analyze technical data, including IP addresses and usage logs, to identify potential software misuse.
  • Conduct deep online research to verify corporate entities and surface accurate contact information.
  • Maintain organized case records in CRM and compile findings into clear reports for internal stakeholders.

Ruvixx partners with leading global software companies to fight piracy and promote license compliance. We are a remote-first, collaborative team focused on making software usage safer and fairer across the globe.