Principal Threat Hunting Engineer

Responsibility House
Beaumont, TX, United States
3 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours

Tech stack

Cloud Engineering Cyber Security Emulators Intrusion Detection and Prevention Cybercrime Purple Team (Cyber Security)

Requirements

Proactively defending Elastic’s products and services, the full-time Principal Threat Hunting and Emulation Engineer will lead structured threat hunting operations, design adversary emulation exercises, and collaborate with cross-functional teams to enhance detection capabilities in a remote environment.Key responsibilitiesLead hypothesis-driven threat hunting operations across various environments using established frameworksDesign and execute adversary emulation exercises to validate detection pipelines and identify coverage gapsTranslate findings from hunts into production-ready detections, ensuring collaboration with Detection EngineeringRequired qualificationsAt least 8 years of experience in information security, focusing on threat hunting and detection engineeringDemonstrated experience conducting structured threat hunts in complex enterprise or cloud-native environmentsFamiliarity with threat hunting frameworks such as PEAK and TaHiTIExperience designing and executing adversary emulation exercises or purple team engagementsWorking knowledge of adversary TTPs and ability to map threat intelligence to hunt hypotheses

Proactively defending Elastic’s products and services, the full-time Principal Threat Hunting and Emulation Engineer will lead structured threat hunting operations, design adversary emulation exercises, and collaborate with cross-functional teams to enhance detection capabilities in a remote environment.Key responsibilitiesLead hypothesis-driven threat hunting operations across various environments using established frameworksDesign and execute adversary emulation exercises to validate detection pipelines and identify coverage gapsTranslate findings from hunts into production-ready detections, ensuring collaboration with Detection EngineeringRequired qualificationsAt least 8 years of experience in information security, focusing on threat hunting and detection engineeringDemonstrated experience conducting structured threat hunts in complex enterprise or cloud-native environmentsFamiliarity with threat hunting frameworks such as PEAK and TaHiTIExperience designing and executing adversary emulation exercises or purple team engagementsWorking knowledge of adversary TTPs and ability to map threat intelligence to hunt hypotheses

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on careersingovernment.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

58 sec

Navigating limitations of local Cosmos DB emulators

Radu Vunvulea Radu Vunvulea · World Congress 2022

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:49 min

Testing with emulators, simulators, and real devices

Milica Aleksic Milica Aleksic · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all