Job Description
📋 Description Lead structured, hypothesis-driven threat hunting across Elastic’s environments. Design and execute adversary emulation to test detections and defenses. Collaborate with Detection Engineering, Incident Response, and Threat Intelligence. Develop scalable hunt programs and reusable emulation playbooks. Translate hunt findings into durable detections and hardened defenses. Partner with security teams to improve coverage across cloud, SaaS, endpoint, and CI/CD. 🎯 Requirements 8+ years in information security focused on threat hunting, detection engineering, IR, or Structured threat hunting in enterprise or cloud-native environments. Experience designing adversary emulation exercises or purple-team engagements. Familiarity with MITRE ATT&CK and related mappings; ability to map intel to hunt hypotheses. Experience in cloud (AWS/Azure/GCP), CI/CD, and tooling for automation. Strong written communication and ability to document findings for technical and executive audiences. 🎁 Benefits Distributed company with flexible locations and schedules. Health coverage for you and family in many locations. Generous vacation; 16 weeks parental leave; volunteer time allowances. Stock program eligibility and 401k with employer match. Opportunity to contribute to open-source tooling and security community. Comprehensive privacy and equal opportunity commitment.