> Markdown version of [/jobs/ext/3036585-detection-engineering-and-threat-hunting-de-th-analyst](https://www.wearedevelopers.com/jobs/ext/3036585-detection-engineering-and-threat-hunting-de-th-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Detection Engineering and Threat Hunting (DE&TH) Analyst - **Company:** HUNTRESS - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $150,000.0 - $170,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Artificial Intelligence, Apple Mac Systems, Microsoft Azure, Query Languages, Linux, Intrusion Detection and Prevention, Performance Tuning, Kusto Query Language, Security Information and Event Management, Snort (Software), Malware, Git Flow, Cybercrime, Gsuite, Splunk, Automation Anywhere - **Published:** September 23, 2026 - **Apply:** https://startup.jobs/senior-detection-engineering-threat-hunting-analyst-huntress-10157235 ## About the Role * 2+ years of experience in detection engineering, threat hunting, SOC, MDR, or incident response. * Intermediate knowledge of Windows internals. * Working knowledge of Linux, macOS, Microsoft 365, Azure, and Google Workspace. * Experience developing, testing, tuning, and documenting detections or analytics from threat intelligence, IOCs, hypotheses, or real-world investigations. * Ability to communicate findings through clear written reports. * Strong familiarity with detection languages such as Sigma, Suricata, Snort, or YARA, and query languages such as KQL, EQL, ES|QL, or Splunk SPL. * A sound understanding of adversary tradecraft, including techniques used for persistence, privilege escalation, defense impairment, lateral movement, discovery, and collection on a system. * A sound understanding of the roles different threat actors play and their associated goals, such as initial access brokers, ransomware affiliates, and state-sponsored entities. * Ability to orchestrate reusable AI workflows that improve threat hunting, detection development, or analysis, and can verify AI-generated outputs before they reach production environments., * Intermediate knowledge of Linux and MacOS internals. * Hands-on experience using tools to remotely discover evidence of compromise, such as OSquery, Velociraptor, and EDR/MDR/XDR platforms. * Previous use of forensic tooling such as Eric Zimmerman's EZ Tools, RegRipper, Hayabusa, or Chainsaw to analyze endpoint artifacts. * Intermediate malware analysis skills. ## Description As a Senior Detection Engineering and Threat Hunting (DE&TH) Analyst, you should be drawn to the hard problems: detecting stealthy intrusions, managing false positives and false negatives at scale, and uncovering clues that may expose an evolving campaign across Huntress partners. In this role, you will turn threat intelligence, or a hypothesis, into detections that help the SOC find real intrusions faster. While the SOC is responding to alerts within minutes, this team is developing detections and reviewing more ambiguous signs of attacker activity on a daily & weekly basis. On the Detection Engineering side of the role, you will play a part in designing, building, and maintaining a resilient, scalable, and high-fidelity detection portfolio that enables the SOC to rapidly identify and respond to adversary activity. This will involve working with engineering and other adjacent teams to achieve a shared goal across multiple domains, which includes identities and endpoints. On the Threat Hunting side of the role, you will get to research new attacker tradecraft, test new theories, and review hunting data at scale for millions of endpoints to proactively hunt for and disrupt stealthy threat actor techniques that evade initial defenses. If you love Detection Engineering and Threat Hunting at scale, whilst in the environment and energy of a SOC, this is the role for you!, * Contribute to all parts of the detection lifecycle by creating new rules, testing them before deployment, monitoring efficacy, and tuning, promoting, or retiring rules based on their performance. * Develop rules across a variety of Huntress products and operating systems, including Identity Threat Detection and Response (ITDR), Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), Windows, Linux, and macOS. * Manage any DE&TH requests raised internally or escalated from our partners. * Undertake hypothesis-driven hunts across Huntress telemetry, prioritizing techniques and tradecraft that may evade high-fidelity detections and initial SOC review. * Consume threat intelligence and translate IOCs, TTPs, and internal findings into new or refined detections through Git-based workflows. * Build and refine hunting dashboards or queries required to surface potential intrusions. * Review ambiguous signs of attacker activity across Huntress products, and surface likely intrusions that require deeper investigation. * Investigate or escalate likely intrusions identified to ensure partners receive clear incident reports with accurate advice. * Contribute findings to community-driven projects and create Huntress content such as blogs, social posts, videos, podcasts, and webinars. * Use AI-assisted workflows to prototype queries, enrich analysis, and develop a scaffolding for detection rules, ensuring you apply sound judgment to validate the AI output. We expect everyone at Huntress to be able to use AI as a real part of how they work, not occasionally, but genuinely embedded in core workflows. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Getting under the skin: The Social Engineering techniques](https://www.wearedevelopers.com/videos/38-getting-under-the-skin-the-social-engineering-techniques) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf) - [Dev Digest 166: Sycophancy, Zip bombs and AI Native Development](https://www.wearedevelopers.com/magazine/585-dev-digest-166-sycophancy-zip-bombs-and-ai-native-development)