> Markdown version of [/jobs/ext/3376838-tactical-response-analyst](https://www.wearedevelopers.com/jobs/ext/3376838-tactical-response-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Tactical Response Analyst - **Company:** HUNTRESS - **Location:** Columbia, MD, United States (Remote available) - **Experience:** Expert - **Salary:** $125,000.0 - $135,000.0 - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), PHP (Programming Language), Microsoft Windows, Apple Mac Systems, Microsoft Azure, Bash Shell, Cloud Computing, Query Languages, Linux, Digital Forensics, Event Logging, Statistical Hypothesis Testing, Intrusion Detection and Prevention, Virtual Private Networks (VPN), Python (Programming Language), Open Source Intelligence, Windows PowerShell, Remote Access Technology, Ruby, Kusto Query Language, Security Information and Event Management, Forensic Toolkit, Snort (Software), Scripting, Malware, Firewalls (Computer Science), Cybercrime, Splunk - **Published:** September 30, 2026 - **Apply:** https://www.juju.com/job/16_e72e7e10 ## About the Role * Typically 3-5+ years of experience in SOC, MDR, threat hunting, digital forensics, or incident response. * Experience leading or participating in external-customer incident response engagements. * Demonstrated ability to investigate complex or multi-host intrusions with limited oversight. * Strong understanding of initial access, persistence, lateral movement, credential access, remote access, and ransomware activity. * Ability to reconstruct attacker activity across systems, data sources, and time periods. Experience with Microsoft 365, Azure, identity, VPN, firewall, SIEM, or cloud telemetry. * Experience with endpoint and forensic tools such as osquery, Velociraptor, EDR platforms, Eric Zimmerman tools, RegRipper, Hayabusa, Chainsaw, or equivalents. * Strong knowledge of common forensic artefacts, including event logs, registry data, prefetch, jump lists, shellbags, scheduled tasks, services, browser artefacts, and authentication activity. * Working knowledge of Windows internals; Linux and macOS experience is beneficial. * Working knowledge of static and dynamic malware analysis, indicator extraction, and basic unpacking or deobfuscation. * Familiarity with OSINT and attacker infrastructure research. * Strong working knowledge of KQL, EQL, ES|QL, Splunk SPL, or equivalent query languages. * Experience with Sigma, YARA, Suricata, Snort, or comparable detection formats. * Scripting or automation experience with Python, PowerShell, Bash, JavaScript, PHP, Ruby, or similar. * Ability to identify product, telemetry, detection, and workflow gaps and express them as actionable requirements. * Demonstrated ability to write concise technical notes, investigation reports, and executive summaries. * Strong verbal communication, judgement, empathy, and composure during high-pressure partner engagements. * Experience collaborating with Product, Engineering, Detection Engineering, Sales Engineering, TAM, or other cross-functional teams. Helpful, but not required: * Experience designing reusable investigation playbooks or methodology modules. * Experience developing production-quality automation or data-normalization workflows. * Experience creating technical enablement, case studies, webinars, blogs, or conference content. * Relevant certifications or equivalent practical experience in forensics, incident response, threat hunting, or offensive security. ## Description * Lead or support cases involving confirmed active adversaries, hands-on-keyboard activity, serious intrusions, or complex coordination requirements. * Investigate across endpoint, identity, cloud, SIEM, VPN, firewall, Windows, Linux, macOS, and other available telemetry. * Build clear, evidence-based timelines and narratives that explain what happened and what must happen next. * Provide practical remediation, eviction, recovery, and recurrence-prevention guidance. * Explain complex findings clearly to technical teams, executives, and other stakeholders. * Participate in partner calls with calm, authoritative, and empathetic communication. * Identify where an incident demonstrates the value of an existing Huntress capability or indicates a need for additional coverage. * Facilitate warm technical handoffs and support post-incident or executive briefings. * Provide the technical evidence and narrative; account-facing teams own the commercial relationship, pricing, and sales process. Research emerging attacker tradecraft and test hypotheses against Huntress telemetry and partner environments. * Develop and improve scripts, automations, dashboards, playbooks, methodology modules, and data-normalization workflows. * Contribute validated field intelligence and case-derived material to enablement, briefings, blogs, webinars, and case studies when appropriate. * Mentor responders and represent Tactical Response in cross-functional discussions. What success looks like: * Partners receive clear answers, actionable guidance, and confidence during serious incidents. * Cases close with defensible root-cause, remediation, and recovery outcomes. * Technical notes give account-facing teams credible context for retention, expansion, and competitive conversations. * Investigation findings become Product feedback, detection improvements, workflow changes, playbooks, or automation. * Your work improves the quality, consistency, and scalability of future Tactical Response engagements. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [ The attacker's footprint](https://www.wearedevelopers.com/videos/375-the-attacker-s-footprint) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Top 6 Hackathons for Developers in 2023](https://www.wearedevelopers.com/magazine/263-top-6-hackathons-for-developers-in-2023) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [The Geometry of Incidents: Connecting User Impact to Architecture](https://www.wearedevelopers.com/magazine/764-the-geometry-of-incidents-connecting-user-impact-to-architecture) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)