1

Threat Hunting Jobs (NOW HIRING)

In this role, you'll focus on hypothesis-driven threat hunting across customer environments-identifying threats that evade automated detection, validating complex escalations, and translating ...

Responsibilities : • Conduct proactive cyber threat hunting activities across Department of Defense networks to identify and mitigate advanced threats before they impact operations. • Investigate ...

You will ensure the threat hunting tools and methodologies employed by the company will scale with Galvanick's growth and success. This is a great opportunity to leverage the data collected by ...

Showing results 21-40

Threat Hunting information

See salary details

$47

$60

$72

How much do threat hunting jobs pay per hour?

As of Sep 12, 2026, the average hourly pay for threat hunting in the United States is $60.46, according to ZipRecruiter salary data. Most workers in this role earn between $55.77 and $65.87 per hour, depending on experience, location, and employer.

What is a threat hunting?

A Threat Hunting job involves proactively searching for cyber threats within an organization's network to identify and mitigate security risks before they cause harm. Threat hunters analyze logs, investigate anomalies, and use threat intelligence to detect hidden adversaries. Unlike traditional security monitoring, which relies on alerts and automated tools, threat hunting is a manual, hypothesis-driven process. The goal is to identify advanced threats that evade standard security measures, helping to strengthen overall cybersecurity defenses.

What does a threat hunting do?

A typical day for a Threat Hunter involves proactively searching through security data to identify hidden threats, analyzing unusual network activity or system behaviors, and developing strategies to detect or stop potential attacks. You’ll often work closely with incident response teams, IT administrators, and other cybersecurity professionals to share findings and support ongoing investigations. The role requires a mix of hands-on technical analysis, collaboration, and regularly updating stakeholders about new risks or trends. Expect to spend time researching the latest cyber threats and tuning detection tools to improve your organization’s security posture.

What are the key skills and qualifications needed to thrive in threat hunting, and why are they important?

To thrive in Threat Hunting, you need strong cybersecurity fundamentals, knowledge of network protocols, and experience in analyzing threat intelligence, often backed by a degree in information security or a related field. Familiarity with SIEM platforms, endpoint detection and response (EDR) tools, scripting languages, and certifications like GIAC Certified Incident Handler (GCIH) or Certified Ethical Hacker (CEH) is highly valuable. Critical thinking, attention to detail, and the ability to communicate findings clearly set standout professionals apart. These skills enable effective identification, investigation, and mitigation of emerging threats before they can impact the organization.

More about Threat Hunting jobs

What cities are hiring for Threat Hunting jobs?

Cities with the most Threat Hunting job openings:

What are the most commonly searched types of Threat Hunting jobs?

The most popular types of Threat Hunting jobs are:

What states have the most Threat Hunting jobs?

States with the most job openings for Threat Hunting jobs include:

Infographic showing various Threat Hunting job openings in the United States as of September 2026, with employment types broken down into 94% Full Time, 5% Part Time, and 1% Contract. Highlights an 90% Physical, 3% Hybrid, and 7% Remote job distribution, with an average salary of $125,752 per year, or $60.5 per hour.

Staff Threat Hunting, Intelligence Engineer

California, MO • On-site

Other

Posted 8 days ago


Job description

  • Report to the Senior Manager, Threat Hunting and Intelligence within Cisco’s Global Security Operations organization
  • Collaborate with Detection Engineering, SOC, Advanced Response, and other multifunctional peer teams
  • Deliver actionable threat intelligence during active incidents, including indicators, TTPs, behavioral patterns, and threat actor context
  • Produce cadenced and ad-hoc intelligence products informing hunts, detections, and business decisions
  • Plan and conduct retrospective, project-based, and ad-hoc threat hunts
  • Build and maintain scripts, API integrations, and automation for intelligence and hunting use cases
  • Improve threat-data ingestion, processing, and enrichment while reducing cycle time
  • Apply AI to accelerate intelligence analysis, hunting, and tooling development
  • Identify adversary activity missed by current detection rules and provide findings to Detection Engineering
  • Create written products, presentations, and RFI responses for technical and non-technical audiences
  • Mentor analysts and engineers developing across threat intelligence, hunting, and engineering
  • Participate in an on-call rotation and provide afterhours support during major incidents
Requirements
  • 8+ years of professional cybersecurity experience, with demonstrable time across cyber threat intelligence and/or threat hunting
  • Experience with sophisticated searching and reporting in Splunk
  • Ability to build and interpret SPL fluidly
  • Experience translating large datasets into meaningful information
  • Understanding of attacker behavior
  • Ability to translate intelligence and hunt findings into repeatable, automated capabilities
  • Experience applying AI to accelerate development and analysis
  • Experience leading threat actor and campaign attribution
  • Strong programming proficiency in one or more languages for scripts and API automation
  • Experience delivering tactical threat intelligence in support of incident response
  • Hands-on experience with DevOps, infrastructure-as-code, and CI/CD tooling
  • Willingness to participate in an on-call rotation, including afterhours support during major incidents
  • Expertise in uncovering adversary activity missed by industry detection rules
  • Experience with network and host-based logs
  • Understanding of common services including DNS, DHCP, email, proxy, VPN, and firewall
  • Proficiency in AWS, GCP, or Azure
  • Robust understanding of Linux
  • Must be a U.S. Person for work on U.S. Government classified environments
  • Some work may require being a U.S. citizen on U.S. soil
Core Competencies

Demonstrates extensive experience in Cybersecurity, particularly in Threat Intelligence and Threat Hunting, with a strong ability to analyze and automate intelligence processes. Proficient in utilizing AI for intelligence analysis and capable of delivering actionable insights to enhance incident response and detection capabilities.

Highest-signal resume keywords
  • Cyber Threat Intelligence
  • Threat Hunting
  • Splunk Proficiency
  • Programming for Automation
  • Cloud Proficiency (AWS, GCP, Azure)
Hard Skills
  • Cybersecurity Experience
  • SPL Interpretation
  • Data Analysis
  • AI Application in Cybersecurity
  • Incident Response Support
  • DevOps Practices
  • Infrastructure-as-Code
  • CI/CD Tooling
  • Linux Proficiency
  • Adversary Activity Detection
Soft Skills
  • Collaboration
  • Mentoring
  • Communication
Industry Keywords
  • Threat Actor Attribution
  • TTPs
  • Behavioral Patterns
  • Threat Intelligence Products
  • Network Logs
  • Host-Based Logs
  • DNS
  • DHCP
  • Email
  • Firewall
Tools & Technologies
  • Splunk
  • AWS
  • GCP
  • Azure
  • API Integrations
#J-18808-Ljbffr