Principal Threat Hunting Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Requirements
Proactively defending Elastic’s products and services, the full-time Principal Threat Hunting and Emulation Engineer will lead structured threat hunting operations, design adversary emulation exercises, and collaborate with cross-functional teams to enhance detection capabilities in a remote environment.Key responsibilitiesLead hypothesis-driven threat hunting operations across various environments using established frameworksDesign and execute adversary emulation exercises to validate detection pipelines and identify coverage gapsTranslate findings from hunts into production-ready detections, ensuring collaboration with Detection EngineeringRequired qualificationsAt least 8 years of experience in information security, focusing on threat hunting and detection engineeringDemonstrated experience conducting structured threat hunts in complex enterprise or cloud-native environmentsFamiliarity with threat hunting frameworks such as PEAK and TaHiTIExperience designing and executing adversary emulation exercises or purple team engagementsWorking knowledge of adversary TTPs and ability to map threat intelligence to hunt hypotheses
Proactively defending Elastic’s products and services, the full-time Principal Threat Hunting and Emulation Engineer will lead structured threat hunting operations, design adversary emulation exercises, and collaborate with cross-functional teams to enhance detection capabilities in a remote environment.Key responsibilitiesLead hypothesis-driven threat hunting operations across various environments using established frameworksDesign and execute adversary emulation exercises to validate detection pipelines and identify coverage gapsTranslate findings from hunts into production-ready detections, ensuring collaboration with Detection EngineeringRequired qualificationsAt least 8 years of experience in information security, focusing on threat hunting and detection engineeringDemonstrated experience conducting structured threat hunts in complex enterprise or cloud-native environmentsFamiliarity with threat hunting frameworks such as PEAK and TaHiTIExperience designing and executing adversary emulation exercises or purple team engagementsWorking knowledge of adversary TTPs and ability to map threat intelligence to hunt hypotheses
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on careersingovernment.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Fully Remote Software Engineer Jobs
The 12 Best Jobs for Software Engineers