Cyber Threat Hunter

NinjaOne, LLC
New York, NY, United States
4 days ago
Apply on www.builtincolorado.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$80,000.0 - $110,000.0
Working hours
Regular working hours

Tech stack

Amazon Web Services Audit Trail Software as a Service Cloud Computing Cloud Computing Security Cloud Engineering Cyber Security Computer Telephony Integration Query Languages Information Technology Operations Intrusion Detection and Prevention Python (Programming Language)
+7 more
Remote Access Technology Azure Active Directory Kusto Query Language Security Information and Event Management Scripting Mitre Att&ck Cyber Threat Analysis

Job description

We are looking for a Threat Hunter to join our Cyber Threat Intelligence function and run proactive, hypothesis-driven hunts across our environment. This is a dedicated hunting role at the front of a detection pipeline: you will turn intelligence and adversary tradecraft into concrete hunts and turn what you find into detection packages that our tooling team operationalizes and our SOC consumes as tuned, documented alerts.

You will sit at the intersection of threat intelligence, detection engineering, and offensive validation. Working from CTI and from our red teamer’s findings, you will hunt for activity that never trips an existing alert, novel techniques, living-off-the-land tradecraft, misconfiguration abuse, and long-dwell intrusions, and close those gaps by feeding durable detections and configuration fixes back into the organization. It is a role for a curious, methodical hunter who is energized by long-horizon investigation rather than the pace of the alert queue., * Plan and run hypothesis-driven hunts (intel-led, TTP-led, and behavior-led) across endpoint, identity, cloud, and network telemetry

  • Consume CTI and red-team/purple-team findings to prioritize hunts against the adversary behaviors most relevant to us
  • Map hunts and findings to MITRE ATT&CK to track coverage and expose blind spots
  • Translate hunt findings into detection packages and recommendations, including detection logic, required context and enrichment, and draft SOP guidance, for the tooling team to operationalize
  • Partner with the red teamer on purple validation of configuration faults and security-posture gaps
  • Surface configuration faults and posture gaps discovered during hunts, and drive recommendations to close them
  • Document hypotheses, methods, and outcomes so hunting knowledge lives in reusable artifacts rather than in one person’s head
  • Contribute threat context and hunt-derived intelligence during declared Sev 1 incidents, in an advisory (non-primary) capacity
  • Other duties as needed

Requirements

  • 5+ years in a security operations, detection engineering, CTI, or incident response role, with meaningful hands-on threat-hunting responsibility
  • Demonstrated experience running hypothesis-driven hunts, forming a hypothesis, testing it against telemetry, and driving it to a conclusion, not solely alert triage
  • Strong working knowledge of adversary tactics, techniques, and procedures, and practical fluency with the MITRE ATT&CK framework
  • Proficiency querying and pivoting across security telemetry at scale in a SIEM and/or EDR/XDR (e.g., KQL, SPL, or equivalent query languages)
  • Solid understanding of endpoint, identity, cloud, and network telemetry, and a sense of what normal and abnormal look like in each
  • Ability to turn a hunt finding into a detection recommendation, including logic, supporting context, and fidelity/signal-to-noise considerations
  • Understanding of the detection lifecycle and why signal-to-noise quality matters to a SOC
  • Clear written communication for documentation, detection packages, and SOP recommendations
  • Able to plan and sustain long-horizon hunt campaigns with limited day-to-day direction, * Experience consuming red-team or purple-team output to drive and prioritize hunts
  • Scripting for automation and enrichment (Python preferred)
  • Familiarity with detection-as-code workflows and version-controlled detection content
  • Depth in cloud-native and SaaS telemetry (CloudTrail, Entra ID/Azure AD, SaaS audit logs)
  • Experience with a threat intelligence platform (TIP) and structured intel workflows
  • Exposure to an IR-capable or standing-response team environment
  • Relevant certifications, one or more (preferred, not required):

  • GCTI, GCFA, GCDA, GCIA, or similar GIAC certifications
  • OSCP or comparable (for offensive-tradecraft awareness)
  • Cloud security certifications (AWS, Azure, or GCP), or equivalent

Key Skills

  • Adversary mindset, thinks in behaviors and TTPs, not indicators alone
  • Patience and persistence for long-horizon threads that may not pay off immediately
  • Strong analytical and data-pivoting skills across large, varied datasets
  • Translates findings into durable, reusable detections and clear documentation
  • Communicates effectively across CTI, tooling, and SOC audiences
  • Curiosity and a genuine drive to find what existing alerting misses

Benefits & conditions

  • Full-time work that is hybrid remote, honoring your flexibility needs
  • A comprehensive benefits package, including medical, dental, and vision insurance
  • A 401(k) plan to help you prepare for your financial future
  • Unlimited PTO that prioritizes your work-life balance
  • Opportunity for growth and advancement, This position is NOT eligible for Visa sponsorship. Due to federal government security requirements associated with our FedRAMP-authorized environment, candidates must be U.S. citizens or lawful permanent residents.

Due to operational policies, NinjaOne is unable to hire for this role within the city limits of Chicago. We will consider all qualified candidates who reside outside of the city proper or are willing to self-relocate.

Starting pay for the successful applicant depends on a variety of job-related factors, including but not limited to location, market demands, experience, job-related knowledge, and skills. The benefits available for this position include medical, dental, vision, 401(k) plan, life insurance coverage, and PTO. For roles based in California, Colorado, Maryland, New Jersey, or Washington, the base salary hiring range for this position is $80,000 to $110,000 per year.

For roles based in New York, the base salary hiring range for this position is $80,000 to $110,000 per year., 100K-223K Annually Senior level 100K-223K Annually Senior level Machine Learning * Payments * Security * Software * Financial Services Leads and scales a team of Technology Integration Specialists while overseeing customer integration discovery, design, execution, and escalation support. Reviews architectures, APIs, and technical documentation; partners with Sales, Product, Engineering, Implementation, and Customer Success; and improves integration processes, standards, tooling, and delivery predictability. Provides technical consulting, requirements analysis, risk management, and strategic direction for payment and point-of-sale integrations. Top Skills: APIsPayment Processing SoftwarePoint-Of-Sale SoftwareSoftware Development Lifecycle (Sdlc) PNC Bank, 75K-125K Annually Mid level 75K-125K Annually Mid level Machine Learning * Payments * Security * Software * Financial Services Act as product owner for one to two enterprise platforms: define vision, prioritize and groom backlog, clarify requirements with Scrum teams, accept increments, communicate outcomes to stakeholders, and ensure alignment with Change@PNC processes and risk practices. Top Skills: APIsBatch File IngestionChange NavigatorConfluenceJIRAKafkaExcelMicrosoft PowerpointMicrosoft Word PwC

Procurement-Senior Associate

6 Hours Ago Remote or Hybrid Denver, CO, USA 151K-187K Annually Senior level 151K-187K Annually Senior level Artificial Intelligence * Professional Services * Business Intelligence * Consulting * Cybersecurity * Generative AI Executes procurement workstreams, manages purchase requests and orders, evaluates supplier proposals and contracts, supports sourcing strategies, and coordinates supplier relationships. Analyzes procurement data and market trends to identify cost savings and process improvements, assists with contract lifecycle activities, monitors vendor risk and performance, and maintains procurement records and reports. Guides junior team members and builds relationships with internal stakeholders.

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

About the company

NinjaOne unifies IT to simplify work for nearly 40,000 customers in 140+ countries. The NinjaOne Unified IT Operations Platform delivers endpoint management, autonomous patching, backup, and remote access in a single console to improve efficiency, increase resilience, and reduce spend. By automating IT and managing all endpoints, organizations give employees a great technology experience at work. NinjaOne is obsessed with customer success and has retained a 98% customer satisfaction score for more than 5 years.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.builtincolorado.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

1:53 min

Adopting Kubernetes and GitOps for standardized deployment environments

Lian Li · World Congress 2022

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

2:35 min

Exploring diverse resources for continuous security learning

Stefania Chaplin · World Congress 2022

3:56 min

Leveraging GitOps for AI auditing and instant rollbacks

Jaroslaw Gajewski Jaroslaw Gajewski · World Congress 2026 Europe

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all