Elastic19 days ago
Principal Threat Hunting and Emulation Engineer - InfoSec
Salary not specified
MARKET
16,667 ₽median for this role
Data Scientist · 69 jobs with disclosed pay
5,800half of the offers: 12,760–20,58333,750
The employer didn't disclose pay — compare with the market yourself.
United States
Responsibilities
- 01Lead structured, hypothesis-driven threat hunting operations across Elastic’s cloud, SaaS, endpoint, and CI/CD environments using frameworks such as PEAK, TaHiTI, or equivalent
- 02Develop and maintain a threat hunting program at scale
- 03Defining hunt hypotheses based on threat intelligence, ATT&CK mappings, and environmental risk profiles
- 04Design and execute adversary emulation exercises and purple team engagements to validate detection pipelines, identify coverage gaps, and simulate real-world threat actor TTPs
- 05Build and maintain a threat emulation library of reusable attack simulations, leveraging tools such as Atomic Red Team, Caldera, Scythe, or custom-developed tooling
- 06Leverage AI and machine learning capabilities to accelerate hypothesis generation, anomaly detection, and the analysis of large, complex datasets during hunts
- 07Translate hunt findings into production-ready detections, collaborating closely with Detection Engineering to ensure durable coverage
- 08Document and codify hunt methodologies, playbooks, and emulation plans so that findings are repeatable, reviewable, and transferable
- 09Partner with Threat Intelligence to inform hunt hypotheses based on emerging adversary campaigns, newly disclosed vulnerabilities, and sector-specific threat profiles
- 10Identify visibility gaps exposed through hunting and emulation, and collaborate with Security Engineering to onboard the log sources needed to close them
- 11Support incident response activities by applying hunting skills to accelerate investigation, scope incidents, and identify attacker dwell time or lateral movement
- 12Contribute to the broader security community through blog posts, conference talks, open-source tooling, and other public knowledge sharing
Requirements
- 01At least 8 years of experience in information security with a focus on threat hunting, detection engineering, incident response, or red/purple team operations with the Elastic Stack
- 02Demonstrated experience in conducting structured and hypothesis-driven threat hunts in complex enterprise or cloud-native environments
- 03Familiarity with threat hunting frameworks such as PEAK, TaHiTI, or Sqrrl, and the ability to apply them operationally and at scale
- 04Experience designing and executing adversary emulation exercises or purple team engagements, including scoping, execution, and post-exercise reporting
- 05Working knowledge of adversary TTPs through frameworks such as MITRE ATT&CK, and the ability to map real-world threat intelligence to hunt hypotheses
- 06Experience using AI-assisted tooling or large language models to support threat hunting workflows, such as hypothesis generation, log summarization, or anomaly triage
- 07Scripting or coding ability to automate repetitive hunt tasks or build custom tooling
- 08A curious, research-driven mindset
- 09Strong written communication skills with an ability to document technical findings clearly for both technical and executive audiences
- 10Is eligible to work in Department of Defense (DoD) Impact Level 4 or above cloud service environments
What we offer
- 01Compensation for this role is in the form of base salary
- 02This role does not have a variable compensation component
- 03The typical starting salary range for new hires in this role is listed below
- 04In select locations (including Seattle WA, Los Angeles CA, the San Francisco Bay Area CA, and the New York City Metro Area), an alternate range may apply as specified below