1

Threat Hunting Jobs (NOW HIRING)

Threat Hunting Analyst Department: Cyber Security - Threat Detection and Response Reports To: Associate Director, Threat Hunting Role Purpose The Threat Hunting Analyst is responsible for proactively ...

Threat Hunting Consultant Remote Fulltime Microsoft Security Stack Expertise * Extensive hands-on experience with Microsoft Defender for Endpoint (MDE) * Proficiency with Microsoft 365 Defender (XDR ...

New

In this role, you'll focus on hypothesisdriven threat hunting across customer environments-identifying threats that evade automated detection, validating complex escalations, and translating findings ...

Threat Hunter

Tampa, FL · On-site

$80 - $120/hr

In this role, you'll focus on hypothesis‑driven threat hunting across customer environments--identifying threats that evade automated detection, validating complex escalations, and translating ...

New

Responsibilities : • Conduct Threat Hunting Perform hypothesis‑driven hunts across customer environments, prioritized by threat intelligence and detection gaps • Operationalize Detection ...

next page

Showing results 1-20

Threat Hunting information

See salary details

$47

$60

$72

How much do threat hunting jobs pay per hour?

As of Aug 21, 2026, the average hourly pay for threat hunting in the United States is $60.46, according to ZipRecruiter salary data. Most workers in this role earn between $55.77 and $65.87 per hour, depending on experience, location, and employer.

What is a threat hunting?

A Threat Hunting job involves proactively searching for cyber threats within an organization's network to identify and mitigate security risks before they cause harm. Threat hunters analyze logs, investigate anomalies, and use threat intelligence to detect hidden adversaries. Unlike traditional security monitoring, which relies on alerts and automated tools, threat hunting is a manual, hypothesis-driven process. The goal is to identify advanced threats that evade standard security measures, helping to strengthen overall cybersecurity defenses.

What does a threat hunting do?

A typical day for a Threat Hunter involves proactively searching through security data to identify hidden threats, analyzing unusual network activity or system behaviors, and developing strategies to detect or stop potential attacks. You’ll often work closely with incident response teams, IT administrators, and other cybersecurity professionals to share findings and support ongoing investigations. The role requires a mix of hands-on technical analysis, collaboration, and regularly updating stakeholders about new risks or trends. Expect to spend time researching the latest cyber threats and tuning detection tools to improve your organization’s security posture.

What are the key skills and qualifications needed to thrive in threat hunting, and why are they important?

To thrive in Threat Hunting, you need strong cybersecurity fundamentals, knowledge of network protocols, and experience in analyzing threat intelligence, often backed by a degree in information security or a related field. Familiarity with SIEM platforms, endpoint detection and response (EDR) tools, scripting languages, and certifications like GIAC Certified Incident Handler (GCIH) or Certified Ethical Hacker (CEH) is highly valuable. Critical thinking, attention to detail, and the ability to communicate findings clearly set standout professionals apart. These skills enable effective identification, investigation, and mitigation of emerging threats before they can impact the organization.

More about Threat Hunting jobs

What cities are hiring for Threat Hunting jobs?

Cities with the most Threat Hunting job openings:

What are the most commonly searched types of Threat Hunting jobs?

The most popular types of Threat Hunting jobs are:

What states have the most Threat Hunting jobs?

States with the most job openings for Threat Hunting jobs include:

Infographic showing various Threat Hunting job openings in the United States as of August 2026, with employment types broken down into 92% Full Time, 6% Part Time, and 2% Contract. Highlights an 88% Physical, 4% Hybrid, and 8% Remote job distribution, with an average salary of $125,752 per year, or $60.5 per hour.

Full-time

Re-posted 16 days ago


Job description

Job Description Centurion is looking for multiple Threat Hunting Analyst for a remote opportunity Role Title: Threat Hunting Analyst Department: Cyber Security - Threat Detection and Response Reports To: Associate Director, Threat Hunting Role Purpose The Threat Hunting Analyst is responsible for proactively identifying malicious activity and emerging threats across the organization's global technology environment before they result in material incidents. This role focuses on hypothesis-driven hunts, advanced analysis of security telemetry, and development of high-fidelity detections that enhance the organisation's ability to detect and respond to sophisticated adversaries. Threat Hunting Analyst works closely with Security Incident Response, SOC analysts, and Threat Intelligence to turn attacker tradecraft and knowledge of the environment into actionable hunts, detections, and security improvements.

Key Responsibilities Proactive Threat Hunting Plan and execute hypothesis-driven hunts across endpoints, network, cloud, and identity platforms using SIEM, EDR, NDR, and other security telemetry sources. Use the MITRE ATT&CK framework and knowledge of adversary TTPs to design and prioritise hunt campaigns. Identify anomalous behaviours, stealthy attack patterns, and indicators of compromise that evade standard alerting.

Detection Engineering and Continuous Improvement Translate successful hunts into robust, high-quality detections, alert logic, and playbooks for SOC and Incident Response teams. Tune existing rules and playbooks to reduce false positives and improve signal-tonoise ratio. Contribute to documentation of hunt playbooks, detection use cases, and detection coverage maps.

Threat Intelligence Consumption Integrate internal and external threat intelligence into hunt hypotheses and detection logic. Monitor relevant threat actor activity, campaigns, and malware families targeting the organization and its sector. Provide feedback to Threat Intelligence teams on observed behaviors and collection gaps.

Incident Support Support Incident Response activities by assisting in scoping, impact assessment, and root cause identification when threats are discovered during hunts. Provide detailed analysis, timeline reconstruction, and artefact review to support containment and eradication actions. Data Analysis and Tool Usage Use advanced search and query languages (e.g

KQL, SPL, SQL) to interrogate large volumes of security telemetry. Apply basic scripting or automation (e.g. Python, PowerShell) to support data enrichment, correlation, and hunt execution

Collaborate with platform owners (e.g. SIEM, EDR, cloud security platforms) to ensure appropriate data sources and visibility for effective hunting. Reporting and Collaboration Document hunt plans, methodologies, findings, and detection improvements in a clear and repeatable format

Present hunt outcomes and insights to SOC, Incident Response, and other security stakeholders. Work with infrastructure, application, and cloud teams to validate findings and remediate root causes. Qualifications, Skills and Experience Required: Experience (typically 2-4 years) in at least one of the following areas: threat hunting, SOC operations, incident response, malware analysis, digital forensics, or security engineering.

Practical experience with at least one enterprise SIEM (e.g. Splunk, Microsoft Sentinel) and one endpoint protection/EDR solution. Strong understanding of: Network and endpoint security concepts (Windows, Linux; identity/Active Directory/Azure AD; common network protocols)

The MITRE ATT&CK framework and common adversary techniques (e.g. lateral movement, credential access, persistence). Detection and alerting concepts, including correlation rules and playbooks

Ability to query and analyse large data sets using search / query languages (e.g. KQL, SPL, SQL). Strong analytical thinking, pattern recognition, and problem-solving skills

Clear written and verbal communication skills in English, with the ability to explain complex technical issues to both technical and non-technical audiences. Preferred: Experience working in a global or highly regulated environment (e.g. healthcare, pharmaceuticals, financial services, critical infrastructure)

Exposure to cloud platforms (e.g. Azure, AWS, GCP) and cloud security telemetry. Familiarity with UEBA, NDR, or identity security tools

Experience with scripting and automation (e.g. Python, PowerShell) to support hunts and data enrichment. Familiarity with digital forensics and incident response (DFIR) concepts (e.g.timelines, artefact analysis, memory/disk forensics)

Relevant security certifications (e.g. GIAC GCDA, GCIA, GCIH, GCFR, Azure/AWS security certifications, or equivalent). Key Competencies Strong investigative mindset and curiosity, with a focus on uncovering unknown threats rather than only responding to alerts

High attention to detail and rigor in documenting methods, assumptions, and findings. Collaborative approach to working with other cyber security teams, IT, and business stakeholders. Ability to manage multiple concurrent hunts and tasks, and to prioritize based on risk and business impact.

Commitment to continuous learning about new threats, tools, and hunting techniques