Join SentinelOne as a Threat Hunter to deliver proactive threat hunting services to clients, build and maintain a high-quality library of hunts and rules, and collaborate with cross-functional teams to respond to emerging threats.
Requirements
- 3+ years in security operations and/or adjacent disciplines (threat hunting, incident response, DFIR, malware analysis, SOC, or penetration testing)
- Strong familiarity with EDR telemetry (process, file, network, persistence) - SentinelOne experience is a plus
- Proficiency with Python and Git/GitHub workflows (branches, PRs, code review); ability to turn hunt logic into robust, reusable code
- Broad OS internals knowledge across Windows, Linux, and macOS
- Applied CTI skills: consume and operationalize IOCs/TTPs; track actors/campaigns; pivot with OSINT to enrich hunts
- Experience collaborating with cross-functional teams (MDR, IR, Labs, Detection Engineering) to cycle from research → hunt → detection → outcome
- Clear, concise writing and reporting for client-facing communications (advisories, AARs, executive summaries), and comfort presenting technical analysis directly to clients when necessary
- Familiarity with MITRE ATT&CK and mapping hunts to relevant techniques
- U.S. citizenship required due to FedRAMP program requirements
Benefits
- Medical, Vision, Dental, 401(k), Commuter, Health and Dependent FSA
- Unlimited PTO
- Leading Total Rewards including Restricted Stock Program
- 16-weeks of gender-neutral parental leave
- Paid company holidays and sick time
- Flexible working hours
- Employee stock purchase program
- Disability and life insurance
- Employee assistance program
- Gym membership reimbursement
- Internet/Mobile allowance
- Learning & development at every level for every function
- Opportunity to strengthen communities globally through our S Foundation