Skip to main content
Dragos

Associate Principal Adversary Hunter

RemoteUnited States only
Published
Role
Security
Experience
Principal
$175k+/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Expert-level adversary hunter with 5+ years in threat intelligence, adversary tracking, intrusion analysis, or threat hunting, specifically in ICS/OT threats. Must know network telemetry, malware/file analysis platforms, Synapse, Storm Query Language, MITRE ATT&CK for ICS, and be able to build tooling or automation in Python, C#, or similar languages. US-based remote role.

Core skills

SynapseStorm Query LanguageThreat hunting

Required skills

NetFlowCensysShodanVirusTotalJoe SandboxPython/C#

What you'll do

  • Provide expert-level coverage for one or more Threat Groups and TATs, independently authoring WorldView reports and representing the team as a subject matter expert in Year in Review (YIR) publications, customer briefings, webinars, and sales engagements.
  • Champion cross-team collaboration to reduce stovepiping and proactively support WorldView triage and reporting pipelines, ensuring intelligence flows efficiently across functions.
  • Enhance and document analysis methodologies while independently tracking new Threat Groups and TATs beyond assigned scope as intelligence needs evolve.
  • Demonstrate proficiency in network telemetry tools (e.g., NetFlow, Censys, Shodan) and file-based analysis platforms (e.g., VirusTotal, Joe Sandbox) to conduct advanced threat hunting and adversary infrastructure tracking.
  • Leverage Synapse and Storm Query Language for advanced data modeling, threat hunting, and investigative workflows; continuously improve data interrogation tooling and identify automation opportunities to scale team output.
  • Lead threat hunting efforts during incident response engagements and provide advanced analytical support during high-priority surge incidents (e.g., PIPEDREAM-class events), operating with minimal oversight.
  • Serve as a recognized data and tooling subject matter expert within the team, driving knowledge transfer initiatives and elevating the analytical capabilities of peers and junior analysts.

What they require

  • 5+ years of experience in threat intelligence, adversary tracking, intrusion analysis, or threat hunting, with demonstrated depth in ICS/OT-focused threat activity.
  • Proven ability to independently own and author finished intelligence products, including WorldView reports, YIR contributions, and customer-facing deliverables with minimal oversight.
  • Expert-level application of the Diamond Model, Kill Chain stages, and MITRE ATT&CK for ICS across complex, multi-stage intrusion investigations.
  • Hands-on proficiency with network telemetry tools (NetFlow, Censys, Shodan), file analysis platforms (VirusTotal, Joe Sandbox), and advanced working knowledge of Synapse and Storm Query Language for threat modeling and hunting automation.
  • Experience leading or significantly contributing to threat hunting operations during live incident response engagements, including high-tempo surge events.
  • Demonstrated ability to develop software tooling or analytical automation using Python, C#, or similar languages to enhance team workflows.
  • Strong analytical and written communication skills, with an external presence or track record of knowledge sharing through publications, conference presentations, webinars, or industry engagement.
  • All new hires must pass a background check as a condition of employment.

Benefits

  • Competitive Equity Package
  • Comprehensive Benefits Plan

Dragos is the global leader in xOT cybersecurity, combining technology, threat intelligence, and expert services to protect critical infrastructure systems.

CybersecurityEnterprise

What people say about this company

4.1/ 5

Details

Apply routeGreenhouse
$175k+/yr