Senior Capabilities Hunter

Dragos · United States · Other

Posted 2026-07-21

Apply for this role →

About the Role:

Dragos' Threat Hunt and Research teams focus intensely on adversary capabilities targeting ICS/OT networks. As a Senior Capabilities Hunter, you'll hunt for, identify, and analyze the tools, techniques, and methodologies that threat actors deploy against critical infrastructure. You'll serve as a technical specialist understanding how adversaries build and deploy their arsenals—from custom malware and exploits to novel attack tradecraft. Working closely with Adversary Hunters and cross-functional teams, you'll develop tools and scripts for capability analysis that inform detection strategies, threat assessments, and customer advisories. Your work directly enhances Dragos' ability to defend against the most advanced threats targeting critical infrastructure globally.

Responsibilities:

Develop and maintain tools and documentation for capability identification and analysis, collaborating across threat hunt, research, intelligence, product, and engineering teams.

Uphold technical excellence through robust code, testing frameworks, and independent problem-solving on complex defects.

Hunt for and analyze adversary capabilities across assigned threat groups, contributing to threat assessments, WorldView reporting, and customer advisories.

Leverage Synapse, Storm Query Language, intel tools (NetFlow, Censys, VirusTotal, Joe Sandbox, Shodan) to support threat tracking and investigative workflows.

Identify automation opportunities in analysis methodologies and recommend solutions for telemetry and data visibility gaps.

Represent the team in external communications, including webinars, industry partnerships, and Year in Review initiatives.

Provide hunting and triage support during surge events and incident response engagements.

Qualifications:

2–3 years of experience in Capabilities Development, Threat Hunting, Network-Based Intrusion Analysis, Vulnerability Analysis, and/or Detections Development.

Experience with software development in C#, Python, or similar languages.

Familiarity with pivoting across the Diamond Model, all stages of the Kill Chain, and MITRE ATT&CK.

Strong report writing skills, with experience producing technical intelligence reports for operational teams and customer-facing audiences.

Demonstrated knowledge of adversarial Threat Groups, including tactics, techniques, procedures, and the adversary lifecycle.

Experience contributing to cross-functional projects and collaborating with internal and external teams.

Knowledge of network analysis and common malware functionality and operations.

Compensation:

Salary: $152,000

Competitive Equity Package

Comprehensive Benefits Plan

#LI-JF1 #LI-REMOTE

Apply for this role →

← Back to all jobs