Cybersecurity Threat Hunter
Job Description
Binary Defense is hiring a Threat Hunter in Houston, TX (remote) to track attacker techniques and translate intelligence into actionable detection and client threat hunts.
Responsibilities
- Monitor emerging threat actor techniques using breaking research, threat intelligence reporting, and firsthand observation, then evaluate relevance to client environments
- Conduct original research from observed malware and threat actor TTPs, including extracting IOCs and identifying detection opportunities
- Build and tune client-facing threat hunts as queries across customer EDR and SIEM platforms
- Act as a technical point of contact for clients by communicating hunt findings, methodology, and recommendations to improve security posture
- Perform static and dynamic malware analysis to understand malicious behavior, execution flow, and common evasion techniques
- Review telemetry, logs, and alerts to identify suspicious behavior across Windows, Linux, and macOS
- Collaborate with Threat Hunters and SOC analysts to support investigations and deliver technical findings
- Stay current on the latest threat actor techniques and cybersecurity developments affecting client networks
- Support and mentor less experienced team members as the role grows
Requirements
- Hands-on threat hunting experience using EDR and/or SIEM platforms such as Microsoft Sentinel, Splunk, and CrowdStrike
- Ability to build and tune hunting and detection queries using platform-native query languages (for example KQL and SPL)
- Strong written and verbal communication to explain technical findings clearly to clients and teammates
- Working knowledge of threat actor techniques, defense evasion, and the current threat landscape
- Experience converting threat intelligence into deployable hunt and detection logic
- Familiarity with malware analysis techniques and the ability to interpret and apply results
- Network traffic analysis experience
- Experience with Windows environments, with working familiarity across Linux and macOS
- Strong research and technical analysis skills, with problem-solving, interpersonal, organizational strengths, and attention to detail
- Associate’s degree in Computer Science, Information Security, Incident Response, Forensics, or a related field (or 2+ years hands-on experience)
Technologies
- Microsoft Defender, Microsoft Sentinel, Splunk, CrowdStrike
- EDR, SIEM
- KQL, SPL
- PowerShell, VBA, JavaScript, .NET, Python, Bash
Benefits
- Competitive medical, dental, and vision coverage for employees and dependents
- 401k match which vests every payroll
- Flexible and remote-friendly work environment
- Training opportunities to expand your skill set
Preferred Qualifications
- Bachelor’s or master’s degree in computer science or Cybersecurity (or 4+ years hands-on experience)
- 2+ years of experience in threat hunting, detection engineering, incident response, or a SOC role
- Experience analyzing or de-obfuscating scripts (PowerShell, VBA, JavaScript, .NET, and similar)
- Scripting or programming experience (for example Python, PowerShell, or Bash) to support analysis and internal tooling
- Experience publishing original research through blog posts, public reporting, or conference talks
- Malware reverse engineering experience (static and dynamic)
- Digital forensics and incident response experience
- Experience mentoring other analysts