Source Job

$152,000–$152,000/yr
US

  • You will hunt for and analyze adversary capabilities targeting ICS/OT networks.
  • You will develop tools and scripts for capability analysis and inform detection strategies.
  • Your work directly enhances Dragos' ability to defend against advanced threats.

C# Python Threat Hunting Malware Analysis

20 jobs similar to Senior Capabilities Hunter

Jobs ranked by similarity.

US Australia

  • Analyze and respond to advanced threats ranging from commodity phishing to zero-day exploits.
  • Monitor and triage alerts from network security monitoring, EDR platforms, and other log sources.
  • Create detailed incident reports and collaborate with threat intelligence and incident response teams.

Volexity is a cybersecurity company specializing in threat intelligence and incident response. They have a growing, industry-leading security operations team and value diversity and equal opportunity.

$120,000–$140,000/yr
US

  • Develop and execute strategic plans for proactive threat-hunting initiatives to identify and mitigate potential security threats.
  • Conduct in-depth analysis of security logs, network traffic, and endpoint data to identify anomalous behavior and indicators of compromise.
  • Collaborate with cross-functional teams, including SOC analysts and incident responders, to prioritize and investigate potential threats.

Valiant Solutions is a security-focused IT solutions provider with public clients nationwide. Named one of the fastest growing privately held companies and Best Places to Work in DC area, they have an employee-centric culture and are committed to growing careers.

$128,400–$192,600/yr
North America Europe South America

  • Monitor and secure industrial control systems and manufacturing environments against cyber threats and anomalies.
  • Conduct OT vulnerability management, threat detection, and incident response using tools like Dragos and CrowdStrike.
  • Implement network segmentation and secure architectures for PLCs, HMIs, and embedded systems in plant operations.

Graham Packaging is a leader in sustainable packaging manufacturing, part of everyday life from kitchen to laundry. The company is values-based with a Blue Culture that emphasizes collaboration, continuous improvement, and employee growth, fostering a diverse and connected workforce.

US

  • Perform incident response and forensic analysis of compromised systems, identifying and recommending remediation.
  • Formulate and direct incident response efforts, prioritizing actions and creating detailed reports on compromise vectors and attacker methodologies.
  • Build incident response plans, playbooks, and attack scenarios for customer tabletop exercises, maintaining sandbox environments to evaluate malicious code.

Check Point Software Technologies is the world's leading vendor of cyber security, facing sophisticated threats and attacks. Honored by Time Magazine as one of the World's Best Companies and on Forbes' list of the World's Best Places to Work, we have a global team of driven and innovative people.

India

  • Investigate and analyze security alerts and incidents across endpoint, network, cloud, and identity environments.
  • Conduct proactive threat hunting, malware analysis, and deobfuscation of suspicious scripts.
  • Collaborate with senior analysts, document findings, and provide remediation recommendations.

The company operates a global Managed Detection and Response environment, protecting organizations from cyber threats. It has a remote-first culture with a collaborative team and opportunities for professional growth.

Global

  • Lead and mentor a remote team of SOC analysts while driving resolution for high-priority security incidents.
  • Architect sophisticated detection strategies using CrowdStrike Query Language (CQL) and oversee proactive threat-hunting operations.
  • Collaborate with cross-functional teams to strengthen security controls and document actionable remediation recommendations.

Arista Networks is a leader in data-driven, client-to-cloud networking for large data center, campus, and routing environments. The company is profitable with over $9 billion in revenue and a global, engineering-centric culture that values diversity, inclusion, and innovation.

Global 1w paternity

  • Monitor and triage security alerts from SIEM, EDR, and other sources to identify threats.
  • Perform initial investigations to validate alerts, assess severity, and determine root cause.
  • Document findings and communicate with clients and internal teams for effective incident response.

Netrix Global provides holistic IT solutions to help businesses run and scale securely. The company is a top system integrator ranked in the CRN VAR500, with a culture focused on ownership, collaboration, and respect.

$140,000–$200,000/yr
Canada India US Unlimited PTO

  • Monitor the threat landscape and deliver actionable intelligence through Flash Reports.
  • Administer the Threat Intelligence Platform and automate intelligence collection with Python.
  • Support incident response and collaborate on Purple Team exercises to improve defenses.

GitLab provides an intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity and improve security. With over 50 million users and more than 50% of the Fortune 100 as customers, GitLab fosters a high-performance culture driven by values and continuous knowledge exchange.

Global

  • Own, administer, and optimize SIEM and EDR platforms, including detection content and automation workflows.
  • Design SOAR playbooks and integrations across security tools to streamline triage, enrichment, and containment.
  • Investigate security events, conduct threat hunts, and support incident response alongside CSIRT Analysts.

Vultr provides high-performance cloud infrastructure for enterprises and AI innovators worldwide, with 33 global data centers. As the world's largest privately-held cloud infrastructure company, Vultr has grown significantly and values inclusion, offering comprehensive benefits and professional development.

US 12w maternity 12w paternity

  • Identify innovative ways to detect Windows OS threats and develop cross-platform features leveraging telemetry from OS subsystems.
  • Collaborate with Product, Engineering, and Security teams to implement detection logic and address gaps in product coverage.
  • Apply AI to improve research quality and speed, and mentor team members to advance technical expertise.

Huntress is a cybersecurity company founded by former NSA operators that provides enterprise-grade cybersecurity to businesses of all sizes. They are a remote-first team securing over 5 million endpoints and 11 million identities, with a culture focused on collaboration and making a meaningful impact.

US

  • Deploy and support Scout products in real customer environments, building and improving deployment automations.
  • Prototype integrations with customer systems and turn repeatable issues into actionable product requirements.
  • Communicate clearly with technical and non-technical customers while researching cybersecurity trends.

Volexity is a cybersecurity company that builds products used in real-world security environments, including incident response and threat intelligence. The company values diversity and is an equal opportunity employer, hiring based on qualifications and merit.

$103,600–$148,000/yr
US

  • Perform investigations into detected threats using EDR, Network, and Identity telemetry to analyze, contain, and remediate threats in customer environments
  • Identify, scope, and manage ongoing customer incidents, developing remediation plans and providing thorough reports
  • Collaborate with Detection Engineering, Intelligence, Research, and Product Management teams to develop new approaches to threat remediation

Zscaler provides a cloud-native Zero Trust Exchange platform that secures users, devices, and applications from cyberattacks and data loss. They foster a culture of transparency, collaboration, and customer obsession with a focus on impact and accountability.

US

  • Responsible for daily incident management of customer incidents, including incident response and forensic analysis of compromised systems.
  • Formulate and direct incident response efforts, prioritize response actions, and create legible incident reports describing compromise vectors and attacker methodologies.
  • Build and maintain incident response plans, playbooks, and sandbox/test lab environments to evaluate malicious code.

We protect over 100,000 organizations worldwide from increasingly sophisticated cyber and AI-driven threats, securing their AI transformation with a prevention-first approach. We are recognized by TIME, Newsweek, and Forbes for our excellence and workplace culture, and we value ownership, curiosity, and solving complex problems.

$65–$75/hr
United States

  • Monitor, investigate, and respond to security detections across the SIEM, driving alerts to resolution.
  • Develop, tune, and maintain SIEM use cases and correlation rules to improve detection coverage.
  • Build and deliver operational reports and dashboards from available SIEM log source data.

Authentic8 provides Silo, a cloud-native platform that enables digital analysts to conduct secure, anonymous investigations across the globe. They serve over 750 of the world's most sophisticated organizations, from government agencies to commercial entities, with a culture of integrity, collaboration, and transparency.

$127,453–$152,944/yr
US

  • Design, implement, and maintain scalable security architectures across IT, OT, cloud (Azure/M365), and on-premise environments, balancing risk reduction with operational reliability.
  • Lead security architecture reviews, M&A due diligence, and cross-functional initiatives to ensure secure-by-design solutions and measurable risk reduction.
  • Serve as senior subject matter expert for incident response, vulnerability management, and OT/ICS security, partnering with SOC and engineering teams.

SOLV Energy is a leading provider of infrastructure services to the power industry, designing, building and maintaining utility scale solar, battery storage and high voltage substation facilities across the United States. It is a national organization that offers broad opportunities for career growth, rooted in core values of Safety, Quality, Innovation and Teamwork.

Global

  • Handle complex security incidents, leading deep investigations and driving remediation actions.
  • Participate in a 24/7 on-call rotation to ensure timely response to critical security incidents.
  • Mentor L1/L2 analysts and drive improvements in detection capabilities and incident readiness.

Eurofins is an international life sciences company providing analytical testing services to ensure products are safe and authentic. With over 65,000 staff across 950+ laboratories in 59 countries, it offers a multicultural and entrepreneurial work environment.

$113,800–$139,000/yr
US

  • Monitor and respond to security alerts from SIEM, EDR/XDR, IDS/IPS, and other platforms.
  • Perform incident response, threat hunting, and log analysis to identify vulnerabilities and improve security controls.
  • Provide practical security guidance and participate in initiatives to ensure compliance with industry standards.

The company provides enterprise information security services for the real estate industry. They value integrity, kindness, and grit, and emphasize long tenure and career development.

UK

  • Monitor security events and provide technical analysis on alerts.
  • Lead information security incidents and employee insider investigations.
  • Coordinate building of services and technologies to support security operations.

Samsara is the pioneer of the Connected Operations Cloud, enabling organizations to harness IoT data for actionable insights. A recently public company, it fosters a collaborative and growth-minded culture focused on safety, efficiency, and sustainability.

$1,739–$2,065/mo
Europe

  • Manage and optimize SIEM use cases to enhance threat detection and incident response.
  • Analyze security events and lead threat hunting activities to identify emerging risks.
  • Investigate incidents and produce technical documentation for corrective actions.

Inetum is a European leader in digital services, helping businesses and public sector entities achieve digital transformation. With 28,000 consultants and specialists across 19 countries, the company generated €2.5 billion in sales in 2023 and fosters a collaborative and innovative culture.

Global

  • Provide expert cybersecurity advice to hedge funds and family offices.
  • Implement and maintain security programs, including vulnerability management and incident response.
  • Conduct best practice reviews and develop actionable security plans.

Arootah is a talent solutions firm purpose-built for the alternative investment industry, covering the full talent spectrum from entry to exit. They have a network of 700+ vetted advisors and 600+ coaches, with a team of experienced operators who have run alternative investment firms at the highest levels.