Dragos Logo

Dragos

Senior Capabilities Hunter

Reposted Yesterday
Be an Early Applicant
Remote
Hiring Remotely in United States
Senior level
Remote
Hiring Remotely in United States
Senior level
Hunt, identify, and analyze adversary tools, malware, and tradecraft targeting ICS/OT. Develop and maintain analysis tools and scripts, contribute to threat assessments and customer advisories, leverage intel and network analysis tools, recommend automation and telemetry improvements, and support incident response and external communications.
The summary above was generated by AI

At Dragos, the mission is personal. The systems we protect deliver the water you drink, power your home, and keep the hospitals your community depends on running. Those critical infrastructure systems that power our civilization around the world are under attack every day by adversaries. When those systems fail, people are immediately at risk. We are the global leader in xOT cybersecurity, combining technology, threat intelligence, and expert services. The people here chose this work because they understand what is at stake. Here, you will find a remote-first mission-driven team across North America, Europe, the Middle East, and APAC built on authenticity, transparency, and trust. If safeguarding the systems that protect your family, friends, and community is the kind of work that matters to you, you are in the right place. 

About the Role: 

Dragos' Threat Hunt and Research teams focus intensely on adversary capabilities targeting ICS/OT networks. As a Senior Capabilities Hunter, you'll hunt for, identify, and analyze the tools, techniques, and methodologies that threat actors deploy against critical infrastructure. You'll serve as a technical specialist understanding how adversaries build and deploy their arsenals—from custom malware and exploits to novel attack tradecraft. Working closely with Adversary Hunters and cross-functional teams, you'll develop tools and scripts for capability analysis that inform detection strategies, threat assessments, and customer advisories. Your work directly enhances Dragos' ability to defend against the most advanced threats targeting critical infrastructure globally.

Responsibilities: 

  • Develop and maintain tools and documentation for capability identification and analysis, collaborating across threat hunt, research, intelligence, product, and engineering teams.
  • Uphold technical excellence through robust code, testing frameworks, and independent problem-solving on complex defects.
  • Hunt for and analyze adversary capabilities across assigned threat groups, contributing to threat assessments, WorldView reporting, and customer advisories.
  • Leverage Synapse, Storm Query Language, intel tools (NetFlow, Censys, VirusTotal, Joe Sandbox, Shodan) to support threat tracking and investigative workflows.
  • Identify automation opportunities in analysis methodologies and recommend solutions for telemetry and data visibility gaps.
  • Represent the team in external communications, including webinars, industry partnerships, and Year in Review initiatives.
  • Provide hunting and triage support during surge events and incident response engagements.

Qualifications: 

  • 2–3 years of experience in Capabilities Development, Threat Hunting, Network-Based Intrusion Analysis, Vulnerability Analysis, and/or Detections Development. 
  • Experience with software development in C#, Python, or similar languages.
  • Familiarity with pivoting across the Diamond Model, all stages of the Kill Chain, and MITRE ATT&CK.
  • Strong report writing skills, with experience producing technical intelligence reports for operational teams and customer-facing audiences.
  • Demonstrated knowledge of adversarial Threat Groups, including tactics, techniques, procedures, and the adversary lifecycle.
  • Experience contributing to cross-functional projects and collaborating with internal and external teams.
  • Knowledge of network analysis and common malware functionality and operations. 

Compensation: 

  • Salary: $152,000
  • Competitive Equity Package  
  • Comprehensive Benefits Plan 

 

#LI-JF1 #LI-REMOTE   

 


Dragos is an Equal Opportunity Employer and considers applicants for employment without regard to race, color, religion, sex, orientation, national origin, age, disability, genetics, or any other basis forbidden under federal, state, or local laws. All new hires must pass a background check as a condition of employment.

Similar Jobs at Dragos

2 Hours Ago
Remote
Senior level
Senior level
Security • Cybersecurity
Lead and manage an adversary hunting team focused on OT threat groups. Perform hands-on hunting using Synapse and Storm Query Language, produce WorldView reports and detection artifacts, collaborate with intelligence and malware analysis, refine KPIs, support incident response surges, recruit and develop staff, and represent the team externally.
Top Skills: CensysDiamond ModelIcs Cyber Kill ChainJoe SandboxMitre Att&Ck For IcsNetflowShodanStorm Query LanguageSynapseVirustotalYara
Yesterday
Remote
Senior level
Senior level
Security • Cybersecurity
Design, build, and deploy production-grade ML systems for ICS/xOT cybersecurity, including threat detection, anomaly detection, NLP/LLM applications, and scalable data pipelines with observability and MLOps practices for cloud and on-prem environments.
Top Skills: Ci/CdDockerGoHuggingfaceJavaKubernetesLlmsMessage QueuingMlopsModel VersioningNlpPipeline OrchestrationPythonPyTorchRetrieval-Augmented Generation (Rag)RustScikit-LearnSQLStream ProcessingTensorFlow
Yesterday
Remote
Senior level
Senior level
Security • Cybersecurity
Design, build, and deploy production ML systems for ICS/xOT cybersecurity, including threat detection, anomaly detection, NLP/LLM features, data pipelines, observability, MLOps, and containerized deployments across cloud and on-prem environments.
Top Skills: Ci/CdCloud-Native ArchitecturesContainerized DeploymentDockerGoHuggingfaceJavaJvmKubernetesLlmsMessage QueuingMlflow (Or Similar)Model VersioningNlpPipeline OrchestrationPythonPyTorchRagRustScikit-LearnSQLStream ProcessingTensorFlow

What you need to know about the London Tech Scene

London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account