Senior Tactical Response Analyst

permanent
Fully Remote

Only accepting applications from: United States

  • Lead or support cases involving confirmed active adversaries, hands-on-keyboard activity, serious intrusions, or complex coordination requirements.
  • Investigate across endpoint, identity, cloud, SIEM, VPN, firewall, Windows, Linux, macOS, and other available telemetry.
  • Build clear, evidence-based timelines and narratives that explain what happened and what must happen next.
  • Provide practical remediation, eviction, recovery, and recurrence-prevention guidance.
  • Explain complex findings clearly to technical teams, executives, and other stakeholders.
  • Participate in partner calls with calm, authoritative, and empathetic communication.
  • Identify where an incident demonstrates the value of an existing Huntress capability or indicates a need for additional coverage.
  • Facilitate warm technical handoffs and support post-incident or executive briefings.
  • Research emerging attacker tradecraft and test hypotheses against Huntress telemetry and partner environments.
  • Develop and improve scripts, automations, dashboards, playbooks, methodology modules, and data-normalization workflows.
  • Contribute validated field intelligence and case-derived material to enablement, briefings, blogs, webinars, and case studies when appropriate.
  • Mentor responders and represent Tactical Response in cross-functional discussions.

Experience

  • Typically 3–5+ years of experience in SOC, MDR, threat hunting, digital forensics, or incident response.
  • Experience leading or participating in external-customer incident response engagements.
  • Demonstrated ability to investigate complex or multi-host intrusions with limited oversight.
  • Strong understanding of initial access, persistence, lateral movement, credential access, remote access, and ransomware activity.
  • Ability to reconstruct attacker activity across systems, data sources, and time periods.
  • Experience with Microsoft 365, Azure, identity, VPN, firewall, SIEM, or cloud telemetry.
  • Experience with endpoint and forensic tools such as osquery, Velociraptor, EDR platforms, Eric Zimmerman tools, RegRipper, Hayabusa, Chainsaw, or equivalents.
  • Strong knowledge of common forensic artefacts, including event logs, registry data, prefetch, jump lists, shellbags, scheduled tasks, services, browser artefacts, and authentication activity.
  • Working knowledge of Windows internals; Linux and macOS experience is beneficial.
  • Working knowledge of static and dynamic malware analysis, indicator extraction, and basic unpacking or deobfuscation.
  • Familiarity with OSINT and attacker infrastructure research.
  • Strong working knowledge of KQL, EQL, ES|QL, Splunk SPL, or equivalent query languages.
  • Experience with Sigma, YARA, Suricata, Snort, or comparable detection formats.
  • Scripting or automation experience with Python, PowerShell, Bash, JavaScript, PHP, Ruby, or similar.
  • Ability to identify product, telemetry, detection, and workflow gaps and express them as actionable requirements.
  • Demonstrated ability to write concise technical notes, investigation reports, and executive summaries.
  • Strong verbal communication, judgement, empathy, and composure during high-pressure partner engagements.
  • Experience collaborating with Product, Engineering, Detection Engineering, Sales Engineering, TAM, or other cross-functional teams.
  • Experience designing reusable investigation playbooks or methodology modules (helpful, but not required).
  • Experience developing production-quality automation or data-normalization workflows (helpful, but not required).
  • Experience creating technical enablement, case studies, webinars, blogs, or conference content (helpful, but not required).
  • Relevant certifications or equivalent practical experience in forensics, incident response, threat hunting, or offensive security (helpful, but not required).

Salary and Perks

Pay range: $125K - $135K

  • 100% remote work environment - since our founding in 2015
  • Generous paid time off policy, including vacation, sick time, and paid holidays
  • 12 weeks of paid parental leave
  • Highly competitive and comprehensive medical, dental, and vision benefits plans
  • 401(k) with a 5% contribution regardless of employee contribution
  • Life and Disability insurance plans
  • Stock options for all full-time employees
  • One-time $500 reimbursement for building/upgrading home office
  • Annual allowance for education and professional development assistance
  • $75 USD/month digital reimbursement
  • Access to the BetterUp platform for coaching, personal, and professional growth

About Huntress

Managed cybersecurity without the complexity. EDR, M365 & SAT for the mid-sized and small businesses who need it most.

Managed cybersecurity without the complexity. EDR, M365 & SAT for the mid-sized and small businesses who need it most.

View all devops and sysadmin jobs

Workster

Remote Jobs for US Residents

We've built a new platform specifically for US residents to find remote work.

Discover Workster

Power Search

Find the jobs that don't get advertised

We've built a tool to help you discover all of the remote jobs that never get advertised.

Discover Power Search