> Markdown version of [/jobs/ext/2383453-cybersecurity-threat-hunter-remote](https://www.wearedevelopers.com/jobs/ext/2383453-cybersecurity-threat-hunter-remote). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Threat Hunter - REMOTE - **Company:** Binary Defense - **Location:** Houston, TX, United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), .NET Framework, Microsoft Windows, Apple Mac Systems, Bash Shell, Cyber Security, Computer Programming, Computer Networks, Query Languages, Linux, Digital Forensics, Intrusion Detection and Prevention, Python (Programming Language), Network Forensics, Windows PowerShell, Kusto Query Language, Reverse Engineering, Security Information and Event Management, Scripting, Malware, Cyber Threat Analysis, Falcon Platform, Information Technology, Cybercrime, Vba Programming Language, Microsoft Sentinel, Splunk - **Published:** August 3, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=ad6cea8db03bfa05 ## About the Role * Hands-on experience hunting for threat actor activity using EDR and/or SIEM platforms such as Microsoft Sentinel, Splunk, and CrowdStrike. * Ability to build and tune hunting and detection queries in platform-native query languages (for example KQL and SPL). * Excellent written and verbal communication, with the ability to explain technical findings clearly to clients and teammates. * Working knowledge of threat actor techniques, defense evasion, and the current threat landscape. * Experience turning threat intelligence into deployable hunt and detection logic. * Familiarity with malware analysis techniques and the ability to interpret and apply results. * Network traffic analysis experience. * Experience with Windows environments, with working familiarity across Linux and macOS. * Strong research and technical analysis skills. * Well-developed problem-solving and interpersonal skills, strong organizational skills, and acute attention to detail. * Associate's degree (or 2 or more years hands-on experience) in Computer Science, Information Security, Incident Response, Forensics, or a related field. Preferred * Bachelor's or master's degree in computer science or Cybersecurity (or 4 or more years hands-on experience). * 2 or more years of experience in threat hunting, detection engineering, incident response, or a SOC role. * Experience analyzing or de-obfuscating scripts (PowerShell, VBA, JavaScript, .NET, and similar). * Scripting or programming experience (for example Python, PowerShell, or Bash) to support analysis and internal tooling. * Experience publishing original research through blog posts, public reporting, or conference talks. * Malware reverse engineering experience, both static and dynamic. * Digital forensics and incident response experience. * Experience mentoring other analysts. ## Description Binary Defense is seeking a Threat Hunter to join our Threat Hunting Team. This role is built for someone who can hit the ground running: tracking threat actor techniques as they break, turning that intelligence into original research, and building the hunts that surface those threats across client environments. The Threat Hunter position requires an experienced, analytical person who understands the techniques threat actors use to compromise systems and evade detection. A successful candidate will study those techniques, translate them into hunting and detection logic across multiple SIEM and EDR platforms, and clearly communicate findings to clients. The work spans researching breaking threat intelligence, hands-on analysis, detection engineering, and written communication, in a client-facing environment. Hunts are delivered across EDR and SIEM platforms including Microsoft Defender, Sentinel, Splunk, and CrowdStrike. Threat Hunters produce client deliverables each week, with opportunities to publish original research as blog posts and to present research at security conferences. Responsibilities * Track emerging threat actor techniques from breaking research, threat intelligence reporting, and firsthand observation, and assess their relevance to client environments. * Develop original research from observed malware and threat actor TTPs, including extraction of indicators of compromise (IOCs) and detection opportunities. * Build and tune client-facing threat hunts as queries across customer EDR and SIEM platforms * Serve as a technical point of contact for clients, clearly communicating hunt findings, methodology, and recommendations to improve their security posture. * Perform static and dynamic malware analysis to understand malicious behavior, execution flow, and common evasion techniques. * Analyze telemetry, logs, and alerts to identify suspicious behavior across Windows, Linux, and macOS. * Work closely with Threat Hunters and SOC analysts to support investigations and deliver technical findings. * Keep current on the latest threat actor techniques and cybersecurity developments relevant to defending client networks. * Support and mentor less experienced team members as you grow in the role. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) - [Training Bots on Deliveroo Data, Alexa Can Swear and Mushroom Electronics - Julia Kordick](https://www.wearedevelopers.com/videos/1839-training-bots-on-deliveroo-data-alexa-can-swear-and-mushroom-electronics-julia-kordick) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The Best Job Search Websites of 2025](https://www.wearedevelopers.com/magazine/368-the-best-job-search-websites-of-2025) - [Find a Developer Job: 12 Best Job Sites For Developers](https://www.wearedevelopers.com/magazine/165-find-a-developer-job-12-best-job-sites-for-developers)