Principal Threat Hunting and Emulation Engineer - InfoSec

Elastic
United States
Full timeUSD 159,800 - 252,800 annuallyFunction: CybersecurityExperience: 8+ yearsSkills: ["Analytical thinking","Written communication","Research mindset","Curiosity"]

Lead structured, hypothesis-driven threat hunts across Elastic’s global cloud, SaaS, endpoint, and CI/CD environments. Design adversary emulation and purple team engagements to validate detection coverage, uncover gaps, and harden defenses. Build scalable threat hunting and emulation programs and libraries using tools like Atomic Red Team, Caldera, and Scythe, while leveraging AI/ML to accelerate analysis and translate findings into production-ready detections.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Elastic
Elastic
2 days ago

Principal Threat Hunting and Emulation Engineer - InfoSec

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 3 hours agoStatus: Live

Job Summary

Lead structured, hypothesis-driven threat hunts across Elastic’s global cloud, SaaS, endpoint, and CI/CD environments. Design adversary emulation and purple team engagements to validate detection coverage, uncover gaps, and harden defenses. Build scalable threat hunting and emulation programs and libraries using tools like Atomic Red Team, Caldera, and Scythe, while leveraging AI/ML to accelerate analysis and translate findings into production-ready detections.
Location: United States
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Lead structured, hypothesis-driven threat hunting across Elastic’s cloud, SaaS, endpoint, and CI/CD environments using PEAK/TaHiTI or equivalent frameworks.
  • •Develop and run a scalable threat hunting program by defining hypotheses from threat intelligence, ATT&CK mappings, and environmental risk profiles.
  • •Design and execute adversary emulation and purple team engagements to validate detection pipelines and simulate real-world threat actor TTPs.
  • •Build and maintain a reusable threat emulation library using tools such as Atomic Red Team, Caldera, Scythe, or custom tooling.
  • •Collaborate with Detection Engineering and Threat Intelligence to convert hunt findings into durable detections, document methodologies and playbooks, and support incident response investigations.

Pay and Benefits

Salary: USD 159,800 - 252,800 annually
Equity and Bonus:Equity
Perks:Health Insurance401kParental LeaveEquity

Key Requirements

  • •At least 8 years of information security experience focused on threat hunting, detection engineering, incident response, or red/purple team operations with the Elastic Stack.
  • •Experience conducting structured, hypothesis-driven threat hunts in complex enterprise or cloud-native environments (proactive hunts, not only reactive investigation).
  • •Familiarity with threat hunting frameworks such as PEAK, TaHiTI, or Sqrrl, and ability to apply them operationally at scale.
  • •Hands-on experience designing and executing adversary emulation exercises or purple team engagements, including scoping, execution, and reporting.
  • •Working knowledge of adversary TTPs using MITRE ATT&CK and the ability to map threat intelligence to hunt hypotheses; strong scripting/coding skills to automate hunt workflows.
Experience:8+ yearsInformation securityThreat huntingCloud securityIncident responseRed team
Skills:Analytical thinkingWritten communicationResearch mindsetCuriosity
Tech Stack:Elastic StackPEAKTaHiTISqrrlMITRE ATT&CKAtomic Red TeamCalderaScytheAIMachine learningLarge language modelsLLMsCI/CDGitHub ActionsAWSGCPAzureScriptingCodingLog summarization

Company Brief

Elastic
Builds the Elastic Stack (Elasticsearch, Kibana, Beats, Logstash) and provides search, observability, and security solutions that enable organizations to search, analyze, and protect data in real time across applications, infrastructure, and enterprises.
Industry: Data Infrastructure
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: Amsterdam, Netherlands
Founded: 2012
WebsiteLinkedIn