WPP is the trusted growth partner for the world’s leading brands. We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth. We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise. Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow. For more information, visit WPP.com. Why we're hiring: The Threat Hunter is responsible for proactively identifying advanced threats that evade traditional security controls. This role involves hypothesis-driven investigations, leveraging threat intelligence, and analyzing telemetry across endpoints, networks, and cloud environments to uncover stealthy adversary activity. The Threat Hunter plays a critical role in reducing dwell time and strengthening organizational resilience under the Autonomic Security Operations model. What you'll be doing: Proactive Threat Hunting Execute hypothesis-driven hunts based on adversary TTPs and threat intelligence. Analyze telemetry from SIEM, EDR/XDR, NDR, and cloud-native platforms to identify anomalies. Develop and maintain hunting queries and scripts for automation and repeatability. Validate detection coverage through purple team exercises and adversary emulation. Threat Intelligence Integration Incorporate emerging threat intelligence into hunting hypotheses and detection pipelines. Maintain awareness of global threat actor tactics, techniques, and procedures (MITRE ATT&CK). Continuous Improvem
Jobiba hiring network
Security Threat Hunting Specialist Jobs
15 active opportunities · Updated for September 2026
Fresh results
15 shown
Explore current security threat hunting specialist jobs. Use filters to narrow by work mode, employment type, experience and date posted.
Zscaler (NASDAQ: ZS) accelerates digital transformation so customers can be more agile, efficient, resilient, and secure. The Zscaler Zero Trust Exchange™️ platform protects thousands of customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location. Distributed across 160+ public exchanges globally and thousands of private exchanges at the edge, the SASE-based Zero Trust Exchange is the world’s largest in-line cloud security platform. We believe the future of work is Human + AI and are building an AI-native enterprise where human potential is amplified by machine intelligence to solve the world’s hardest security challenges. Driven by deep customer obsession, we are committed to the mission, outcome, and to each other. We bring these commitments to life through three core behaviors: ownership and collaboration, trust through outcomes and impact, and a challenge culture with ongoing feedback. Ready to make an impact at the company pioneering security transformation in the AI era? Join us at Zscaler. About the Role We are looking for a Product Sales Account Executive to join our Sales and Go-to-Market team. This role can be based in any major city within San Francisco, Rockies or OH Valley area, reporting to the Director, SecOps. You will support a specific region, acting as the primary specialist to drive revenue growth within the security operations product suite, including unified vulnerability management, deception and threat hunting. You will lead the charge in demonstrating the power of cloud transformation to cement our position as a global leader in cloud security. What you’ll do (Role Expectations) Serve as the primary specialist for customers, partners, and internal teams to drive revenue growth across the security operations product portfolio Partner with domain-expert solution engineers to capture customer requirements and craft compelling value propositions that close complex business deals Own the regio
Reports to: Senior Manager, Product Support Location: Remote Ireland Compensation Range: €32,000 to €42,000 base, plus bonus and equity. *This role requires Tuesday-Saturday work days.* What We Do: Cybercrime is growing, and more businesses are getting hit by threats that used to target only the biggest organizations. That pushes defenders like us to operate at the highest level, and it deepens our need for good people who want to make a meaningful impact. Founded in 2015 by former NSA cyber operators, Huntress is a remote-first team working to make enterprise-grade cybersecurity accessible to businesses of all sizes. We work closely with security teams and service providers protecting complex environments, often without the time or headcount to handle it all. That’s why we build our technology in-house and back it with a 24/7 human-led Security Operations Center (SOC). As a result, our platform is never disconnected from the experts who manage it, ensuring our customers' protection. Huntress now secures more than 5M endpoints and 11M identities worldwide. Those numbers keep growing because more businesses rely on us to help carry the load and operate with more confidence. Every day, you can see that commitment in how we stand with our customers and how we show up for each other. What We Do: Huntress is a fully remote, global team of passionate experts and ethical badasses on a mission to break down the barriers to cybersecurity. Whether creating purpose-built security solutions, hunting down hackers, or impacting our community, our people go above and beyond to change the security game and make a real difference. Founded in 2015 by former NSA cyber operators, Huntress protects all businesses—not just the 1%—with enterprise-grade, fully owned, and managed cybersecurity products at the price of an affordable SaaS application. The Huntress difference is our One Team advantage: our technology is designed with our industry-defining Security Operations Center (SOC
About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture. About the Role OpenAI is seeking to build an investigative capability for Secure Manufacturing & Stealth programs. The risk surface for unreleased products, prototypes, confidential hardware, infrastructure, supply chain, manufacturing, and launch-readiness efforts spans employees, vendors, suppliers, logistics partners, physical movement of assets, procurement records, manufacturing workflows, access systems, device telemetry, and adversarial collection. This role is intended to build and run investigations across that specialized environment. In this role, you will: Lead complex SMS investigations to proactively identify and mitigate risks to unreleased products, prototypes, confidential hardware, secure manufacturing programs, and launch-readiness efforts. Investigate unauthorized disclosure, suspected leaks, insider risk, supplier compromise, vendor misconduct, theft, diversion, tampering, counterfeiting, surveillance, adversarial collection, and suspicious activity involving sensitive programs. Connect digital evidence, physical access activity, supply chain records, manufacturing data, vendor behavior, employee activity, collaboration metadata, procurement records, shipping data, and OSINT into clear findings and risk-reduction actions. Conduct proactive threat hunting to surface early indicators of compromise, collection, leakage, or insider activity affecting sensitive programs. Develop investigative playbooks, evidence-handling standards,
The Team: As a Security Engineer 2 on the Cyber Threat Intelligence team, you will help Datadog stay ahead of evolving threats by identifying, analyzing, and operationalizing intelligence on threat actors, campaigns, and emerging threats. Working within Security Engineering, you will partner closely with security teams to translate intelligence into actionable security improvements across the company. You will serve as a subject matter expert on how the cyber threat landscape intersects with Datadog and contribute to intelligence-led decision making during both steady-state operations and active security incidents. This role provides opportunities to influence detection, response, and security strategy through technical analysis, collaboration, and intelligence-driven initiatives. At Datadog, we place value in our office culture - the relationships and collaboration it builds and the creativity it brings to the table. We operate as a hybrid workplace to ensure our Datadogs can create a work-life harmony that best fits them. What You’ll Do: Develop and maintain tooling that automates the collection, processing, analysis, and dissemination of threat intelligence. Assess emerging vulnerabilities, threat activity, and security events to help stakeholders understand potential impact to Datadog. Conduct threat hunting and infrastructure analysis to identify adversary activity relevant to Datadog and improve defensive controls. Partner with security teams to operationalize intelligence into detections, investigations, and response workflows. Coordinate with information-sharing communities to gather, evaluate, and disseminate actionable intelligence. Produce technical briefings, threat reports, and intelligence products for security and engineering stakeholders. Who You Are: Experienced in writing and presenting operational and technical intelligence for threat detection, response, and security stakeholders. Skilled in partnering with detection and response te
Reports to: Senior Manager, Detection Engineering & Threat Hunting Location: Remote Australia Compensation Range: $150,000 to $170,000 AUD base plus bonus and equity What We Do: Cybercrime is growing, and more businesses are getting hit by threats that used to target only the biggest organizations. That pushes defenders like us to operate at the highest level, and it deepens our need for good people who want to make a meaningful impact. Founded in 2015 by former NSA cyber operators, Huntress is a remote-first team working to make enterprise-grade cybersecurity accessible to businesses of all sizes. We work closely with security teams and service providers protecting complex environments, often without the time or headcount to handle it all. That’s why we build our technology in-house and back it with a 24/7 human-led Security Operations Center (SOC). As a result, our platform is never disconnected from the experts who manage it, ensuring our customers' protection. Huntress now secures more than 5M+ endpoints and 15M+ identities worldwide. Those numbers keep growing because more businesses rely on us to help carry the load and operate with more confidence. Every day, you can see that commitment in how we stand with our customers and how we show up for each other. What You’ll Do: Members of the Huntress DE&TH team wake up every morning with the honor of impeding threat actors through a combination of detection engineering and threat hunting. This team sits alongside our 24x7 Security Operations Center, and our Adversary Tactics & Tactical Response function, and plays a pivotal role in detecting threats actors before they get a chance to impact our partner environments. As a Senior Detection Engineering and Threat Hunting (DE&TH) Analyst you should be drawn to the hard problems: detecting stealthy intrusions, managing false positives and false negatives at scale, and uncovering clues that may expose an evolving campaign across Huntres
Our Purpose Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential. Title and Summary Lead Threat Intelligence Analyst Overview This is an exciting position for a Lead Threat Intelligence Analyst to join Vocalink’s dedicated Threat Intelligence function. You will be play an integral leading role in the Vocalink Threat Intelligence Team, working closely with the SOC and internal security teams to deliver actionable intelligence. You will support a diverse range of customers and contribute to key initiatives such as threat hunting, vulnerability management, and insider threat detection. Collaboration is at the heart of this position. You will work alongside Mastercard’s global threat intelligence capabilities and engage proactively with a wide network of stakeholders, including vendors, industry groups, our customers, and government organisations. This is a unique chance to help shape and grow a fast-evolving threat intelligence capability that serves Vocalink and its customers. If you are passionate about cyber security and eager to make an impact, this role offers an exciting platform to develop your leadership expertise and to help to grow and mature a threat intelligence function in a critical national infrastructure provider. Role Lead the day-to-day operations of the threat intelligence function within the Vocalink Security Operations Cent
Squarespace is looking for a Security Engineer with a focus on Investigations and Incident Response to join a dedicated team responsible for monitoring and responding to attacks on our platform. You'll partner with teams across the organization as you investigate security events specific to our platform and corporate environment. This is a hybrid role working from our Dublin office 3 days per week and you will report to the Detection and Response Manager. You’ll Get To… You will investigate security events through our SIEM and SOAR technology Design alerts to monitor both our customer and corporate environments for anomalous behavior Share insights gleaned from SOAR case work with relevant security team members in order to drive more security feature implementation to the product or corporate environment You will respond to ongoing incidents, investigate historical compromises, and provide adept analysis and findings Establish strategies for threat detection, alerting, and response You will initiate reactive threat hunting engagements by performing endpoint, network, application, and log analysis Establish processes and build 'playbooks' of operational response to security events and/or incidents Familiarity with Threat Intelligence and keeping up-to-date on modern threats and InfoSec news Build and support security-focused tools and services Provide Mentorship and technical expertise to junior team members to assist their technical development Who We’re Looking For 5+ years experience in the security industry Certifications (preferred not required): OSCP, OSCE, OSWP Experience working with SIEM and SOAR technologies Knowledgeable of cloud & container security, and infrastructure as code Working understanding of malware analysis, reverse engineering, and host-based and memory forensics Proficiency in programming or scripting languages (preference to Python, Go, JavaScript, or Bash) is a plus Knowledge of network and web related protocols (e.g., TCP/I
Role Summary We are seeking an experienced SOC / Security Operations Lead to oversee and strengthen the organization's Security Operations Center (SOC), threat detection, incident response, vulnerability management, data protection, and security monitoring capabilities. The ideal candidate will possess extensive experience in managing enterprise security operations, SIEM/SOAR platforms, threat hunting, incident response, DLP, endpoint security, and vulnerability management programs. The role requires leadership of a multi-functional security operations team responsible for protecting critical business systems, customer data, and digital assets while ensuring compliance with RBI regulations and industry security standards. Key Responsibilities Security Operations Center (SOC) Management -Lead and manage 24x7 Security Operations Center (SOC) functions. -Establish and enhance SOC processes, playbooks, escalation procedures, and operational metrics. -Ensure timely detection, triage, investigation, containment, and remediation of security incidents. -Develop SOC maturity roadmaps aligned with industry best practices and regulatory expectations. -Monitor security KPIs, SLAs, MTTR, MTTD, and incident response effectiveness. SIEM, XSIAM & Threat Detection -Lead implementation, administration, and optimization of: -Palo Alto Cortex XSIAM -SIEM Platforms -SOAR Platforms -UEBA Solutions -Threat Intelligence Platforms -Develop and tune correlation rules, detection logic, and analytics use cases. -Enhance detection coverage across cloud, endpoints, applications, networks, and third-party environments. -Drive threat hunting and proactive security monitoring initiatives. Incident Response & Threat Management -Lead enterprise cyber incident response activities. -Develop and maintain incident response plans, runbooks, and communication procedures. -Coordinate investigations involving malware, ransomware, phishing, insider threats, account compromise, fraud, and adv
Everpure (NYSE: P) has evolved from storage pioneer to data platform, closing fiscal 2026 with $3.7 billion in revenue, its first billion-dollar quarter, and accelerating growth into FY27. Our strategic agenda spans the companies defining the next era of technology - hyperscalers, AI labs, the AI hardware supply chain, data platform providers, and the broader AI ecosystem. This type of work—work that changes the world—is what the tech industry was founded on. So, if you're ready to seize the endless opportunities and leave your mark, come join us. THE ROLE As a hands-on senior leader for our India SecOps team, you will shape and safeguard Everpure’s security posture at the intersection of detection engineering, threat hunting, attack surface management, and incident response. Positioned as a strategic cornerstone in Bangalore, you will empower an elite engineering team, optimize critical SecOps pipelines, and partner cross-functionally across global engineering and infrastructure groups. By driving execution excellence and high team morale, you ensure our enterprise platform and global telemetry remain resilient against evolving threats. WHAT YOU'LL DO Scale & Lead SecOps Operations: Architect, mentor, and grow the India SecOps team to foster an environment of high morale, technical excellence, and rapid execution across detection engineering and incident response. Proactively Manage & Remediate Attack Surface: Own end-to-end Attack Surface Management (ASM) across cloud environments, SaaS applications, endpoints, and secrets management to measurably minimize enterprise exposure and mitigate risk. Optimize Telemetry & Incident Response: Mature SIEM and SOAR automation pipelines to drastically reduce mean time to detect, contain, and respond (MTTD/MTTC/MTTR) while continuously elevating alert fidelity and signal confidence. Drive Cross-Functional Alignment & RCA Postmortems: Lead continuous validation through purple-teaming and incident postmortems alo
As a Senior Security Engineer focused on Datadog’s Cloud SIEM product, you will help shape the future of security operations by transforming real-world security expertise into scalable detection, investigation, and response capabilities. You will develop high-impact threat detection content, improve AI-assisted security workflows, and help defenders identify and respond to threats across cloud-native and enterprise environments. Working closely with Product, Engineering, and Security Research teams, you will influence the evolution of Datadog Security products while advancing detection coverage across emerging technologies and attack surfaces. This role offers the opportunity to contribute to open source initiatives, publish security research, and help define the next generation of agentic security operations capabilities. At Datadog, we place value in our office culture - the relationships and collaboration it builds and the creativity it brings to the table. We operate as a hybrid workplace to ensure our Datadogs can create a work-life harmony that best fits them. What You'll Do: Research attacker techniques, defensive strategies, and emerging threats, translating findings into scalable security capabilities that protect customers at cloud scale. Design and improve AI-powered investigation, threat hunting, and response workflows that support Datadog’s agentic SOC capabilities. Own the lifecycle of threat detections and automated security workflows, from research and design through deployment, measurement, and continuous improvement. Develop high-fidelity detection content across cloud platforms, SaaS applications, identity systems, endpoints, networks, and other modern attack surfaces. Partner with Product, Engineering, Security Research, and customers to influence roadmap decisions and improve security outcomes across the platform. Mentor security engineers and drive improvements through automation, tooling, rapid prototyping, and data-driven optimization. Who Yo
As a Senior Security Engineer focused on Datadog’s Cloud SIEM product, you will help shape the future of security operations by transforming real-world security expertise into scalable detection, investigation, and response capabilities. You will develop high-impact threat detection content, improve AI-assisted security workflows, and help defenders identify and respond to threats across cloud-native and enterprise environments. Working closely with Product, Engineering, and Security Research teams, you will influence the evolution of Datadog Security products while advancing detection coverage across emerging technologies and attack surfaces. This role offers the opportunity to contribute to open source initiatives, publish security research, and help define the next generation of agentic security operations capabilities. At Datadog, we place value in our office culture - the relationships and collaboration it builds and the creativity it brings to the table. We operate as a hybrid workplace to ensure our Datadogs can create a work-life harmony that best fits them. What You'll Do: Research attacker techniques, defensive strategies, and emerging threats, translating findings into scalable security capabilities that protect customers at cloud scale. Design and improve AI-powered investigation, threat hunting, and response workflows that support Datadog’s agentic SOC capabilities. Own the lifecycle of threat detections and automated security workflows, from research and design through deployment, measurement, and continuous improvement. Develop high-fidelity detection content across cloud platforms, SaaS applications, identity systems, endpoints, networks, and other modern attack surfaces. Partner with Product, Engineering, Security Research, and customers to influence roadmap decisions and improve security outcomes across the platform. Mentor security engineers and drive improvements through automation, tooling, rapid prototyping, and data-driven optimization. Who Yo
Who We Are At Justworks, you’ll enjoy a welcoming and casual environment, great benefits, wellness program offerings, company retreats, and the ability to interact with and learn from leaders in the startup community. We work hard and care about our most prized asset - our people. We’re helping businesses get off the ground by enabling them to focus on running their business. We solve HR issues. We’re data-driven and never stop iterating. If you’d like to work in a supportive, entrepreneurial environment, are interested in building something meaningful and having fun while doing it, we’d love to hear from you. We're united by shared goals and shared motivations at Justworks. These are best summed up in our company values, which are reflected in our product and in our team. Our Values If this sounds like you, you’ll fit right in. Who You Are Justworks is looking for an experienced security engineer skilled in detection and response, who can help enhance and mature Justworks’ Security. As a Senior Detection Engineer, you’ll design, build, and maintain the detection logic that powers our platform, conduct proactive threat hunting, and drive continuous improvements across our detection and incident handling workflows. You’ll collaborate closely with IT, Engineering, Platform, and other members of the Security team to identify attacker behaviors, build high‑fidelity detections, and strengthen our defenses. You’ll also play a key role in designing and conducting table‑top exercises, improving processes, and building automation that reduces friction and accelerates response. You’ll help explore how AI can enhance detection, hunting, and operational efficiency. Your Success Profile What You Will Work On Build, tune, and deploy high‑quality detections across our platform Develop and refine detections using telemetry from EDR, threat intel, endpoint & cloud posture platforms and native AWS cloud services Conduct proactive threat hunting to uncover threat actor behaviors a
ABOUT THE ROLE Peloton continues to grow and deliver the connected fitness platform of the future to help our members be the best version of themselves. As a technology-enabled business, our approach to security operations must evolve and grow alongside our services and members. We are looking for a Security Engineer with a diverse set of skills that can thrive in a challenging, fast-paced, and rewarding environment. We do not have a traditional SOC tier structure, so you can expect to help us improve our detections as well as create additional detections, build automations, and research & help define the solutions roadmap to achieve scale. The right candidate should have a strong focus on results, be self-driven, and be excited by working on a diverse set of problems, threats, and alerts. YOUR DAILY IMPACT AT PELOTON Directly support Peloton’s Security Program while conducting in-depth research and strategic analysis of intelligence data from various sources to leverage in threat hunting Stay up to date with relevant vulnerabilities, threat actors, indicators of compromise (IOCs) tactics, techniques, and procedures (TTPs), and trends, identifying actionable areas of interest and threats Provide intel-driven insights into existing and emerging threats, use insights to search Peloton enterprise for activity that is anomalous and/or malicious Work with Security Engineering and the Security Operations Center to baseline user behaviors and events as well as build out new detections and response workflows Provide triage support for incident response and investigation efforts as part of Peloton’s Security and Operations team and other internal teams Recommend and build countermeasures based on threat analysis, intelligence, and forecasting Develop, implement, and maintain security incident playbooks/runbooks Prepare and present analysis with findings and recommendations in the form of briefings, reports, and dashboards to
Location Details: At GoDaddy the future of work looks different for each team. Some teams work in the office full-time, others have a hybrid arrangement (they work remotely some days and in the office some days) and some work entirely remotely. This is a remote position, so you’ll be working remotely from your home. You may occasionally visit a GoDaddy office to meet with your team for events or meetings. This position is not eligible to be performed in Alaska, Mississippi, North Dakota, or the Virgin Islands. GoDaddy is not currently considering candidates for this role in California, Seattle, or NYC. Join Our Team... We are seeking a highly skilled Senior Security Engineer to join our advanced Security Operations team. This role is focused on leading complex incident response and forensic investigations across Windows, macOS, Linux, and AWS environments while helping modernize security operations through automation and AI-driven capabilities. The ideal candidate is a hands-on security expert with deep AWS security expertise, strong threat detection and digital forensic skills, and experience leveraging AI and machine learning technologies to improve detection, response, and operational efficiency. You will play a key role in protecting critical assets, conducting high-impact investigations, mentoring team members, and driving the evolution of our security program against sophisticated and emerging threats. What You'll Get to Do... Lead high-priority incident response and forensic investigations, serving as the primary escalation point for advanced analysis, containment, recovery, root cause determination, and executive-level reporting. Drive threat detection and response across AWS, Windows, macOS, Linux, and endpoint security platforms, leveraging services such as GuardDuty, Security Hub, Detective, CloudTrail, IAM, VPC Flow Logs, and SentinelOne. Conduct malware analysis, host and cloud forensics, evidence collection, and threat hunting activi
Get new security threat hunting specialist jobs by email
Daily job updates · Unsubscribe anytime