Principal Threat Hunting and Emulation Engineer - InfoSec
Core
Lead hypothesis-driven threat hunting and adversary emulation to proactively defend Elastic's cloud, SaaS, endpoint, and CI/CD environments.
Role type
Principal Threat Hunting and Emulation Engineer
Builds
Threat hunting program, adversary emulation library, and production-ready detections
Domain
Cybersecurity, Threat Intelligence, Cloud Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Threat hunting frameworks (PEAK, TaHiTI), Adversary emulation, MITRE ATT&CK, AI-assisted analysis, Scripting/coding, Incident response, Detection engineering
Preferred skills
Cloud environment hunting (AWS, GCP, Azure), CI/CD threat hunting, Open-source contributions
Technologies
Elastic Stack, Atomic Red Team, Caldera, Scythe, GitHub Actions
Responsibilities
Design and execute adversary emulation exercises, translate hunt findings into detections, document methodologies and playbooks, partner with Threat Intelligence, identify visibility gaps, support incident response investigations
Seniority
Principal, hands-on IC