The Problem
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
- Lead end-to-end threat hunting campaigns across cloud environments, IoT hardware systems, and corporate applications to detect advanced persistent threats and visibility gaps.
- Partner with the Offensive Security team to validate custom detection rules and translate findings into high-fidelity detections mapped to the MITRE ATT&CK framework.
- Design and execute technical exercise scenarios and tabletop exercises that test incident response readiness against real-world cyber risks.
- Serve as a technical escalation point for deep-dive root cause analysis on complex incidents and mentor junior engineers to elevate team technical capabilities.
- Integrate security automation platforms and intelligent workflows to streamline threat analysis and accelerate operational response capabilities., * This isn’t a routine SOC analyst or Tier 1 triage job, you will focus on proactive threat hunting, deep adversary pursuit, and advanced detection engineering.
- This is not a purely offensive red-teaming role, you will collaborate with offensive security to validate detections and improve overall defense and response posture.
- This isn’t a hands-off strategic management position, you will execute technical threat hunts, analyze suspicious binaries, and write detection logic directly.
Requirements
- Demonstrated experience in digital forensics, incident response, and threat hunting across cloud platforms, enterprise infrastructure, and operational or IoT environments.
- Hands-on expertise using enterprise security tooling, developing custom scripts, and authoring high-fidelity detection rules in Splunk SPL, YARA, or Sigma.
- Practical capability in security automation integrations, malware analysis, or sandboxing technologies to accelerate threat investigation workflows.
- Strong cross-functional technical communication skills to collaborate with Engineering, Product, and Infrastructure teams on architecture improvements.
- Deep understanding of cyber threat intelligence frameworks, MITRE ATT&CK mapping, and technical threat modeling.
Benefits & conditions
3.1 Remote Remote $140,000 - $175,000 a year - Full-time, * $140K - $175K * Offers Equity, In this role, you’ll receive a starting salary between $140,000 and $175,000 as well as Flock Stock Options. Base salary is determined by job-related experience, education/training, as well as market indicators. Your recruiter will discuss this in depth with you during our first chat.
About the company
Every community deserves to be safe. Flock builds the technology that makes that real: last year we supported over 1 million criminal investigations and helped locate more than 10,000 missing people. We’re 1,700 people building the impossible with over $1B in funding, and the expectations are high on purpose. If you want a role where the stakes are real and the pace matches, this is it.
Some problems get solved faster in the same room, so we prioritize candidates in Atlanta and Boston. Hub-based roles mean real in-person time with your coworkers. Remote roles exist, and when a posting is open to remote work, it says so.
Building the impossible takes every kind of mind. Flock is an equal opportunity employer, and we know the best solutions come from diverse perspectives, experiences, and skills working together with mutual respect. Everyone is welcome to apply. If you need assistance or an accommodation due to a disability, email recruiting@flocksafety.com; your information stays confidential and is used only to arrange the right accommodation for your interviews.
On compensation: we pay fairly for the work. Base salary is determined by job-related experience, education, training, and market indicators. The range in this posting covers base salary only and doesn’t include equity, sales bonus plans where applicable, or benefits. The range may be adjusted over time, and this posting may span more than one career level.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
Dev Digest 134 - Where pixels sing?
Understanding and Mitigating Common Web Vulnerabilities
The Overflow: Security and Privacy