CareerPlanSign in

Principal Threat Hunting and Emulation Engineer - InfoSec

United States🌐 Remote💼 Full-time💰 $159,800–$159,800🗓 2026-08-04 → 2026-09-26

Core

Lead hypothesis-driven threat hunting and adversary emulation to proactively defend Elastic's cloud, SaaS, endpoint, and CI/CD environments.

Role type

Principal Threat Hunting and Emulation Engineer

Builds

Threat hunting program, adversary emulation library, and production-ready detections

Domain

Cybersecurity, Threat Intelligence, Cloud Security

Deliverable

production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work

Required skills

Threat hunting frameworks (PEAK, TaHiTI), Adversary emulation, MITRE ATT&CK, AI-assisted analysis, Scripting/coding, Incident response, Detection engineering

Preferred skills

Cloud environment hunting (AWS, GCP, Azure), CI/CD threat hunting, Open-source contributions

Technologies

Elastic Stack, Atomic Red Team, Caldera, Scythe, GitHub Actions

Responsibilities

Design and execute adversary emulation exercises, translate hunt findings into detections, document methodologies and playbooks, partner with Threat Intelligence, identify visibility gaps, support incident response investigations

Seniority

Principal, hands-on IC

Sourced via greenhouse · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.