Principal Threat Hunter
Listed on 2026-10-04
-
IT/Tech
Cybersecurity
Location: Remote, United States
Team: Product & Engineering
Employment Type: Full-Time, Remote
Exploitation prevention is only as strong as the intelligence driving those efforts, and most of the industry is still running on intelligence that lacks exploit context. Vuln Check, The Exploit Intelligence Company, delivers structured exploit intelligence on what is actively weaponized in the wild, purpose-built for the data lakes, ETL pipelines, automation, and AI and LLM workflows your infrastructure already runs on, raising the capability of everything it powers.
Aboutthe Role
Vuln Check is hiring a Principal Threat Hunter to discover, investigate, and document real-world exploitation and attacker infrastructure, and turn those discoveries into durable improvements to Vuln Check's detection capabilities.
Vuln Check operates infrastructure across the internet that gives us a direct view into attacker activity. Canary Intelligence deploys intentionally vulnerable systems and captures real exploitation attempts, giving researchers a steady stream of attacker binaries, source infrastructure, payloads, and exploitation techniques. Target Intelligence maintains a continuously updated view of internet-facing systems, including their exposure to known vulnerabilities and their relationships to scanners, proxies, C2 infrastructure, and other attack infrastructure.
Together, these datasets provide a foundation for research that is difficult to replicate elsewhere. You can observe exploitation as it happens rather than infer it from secondary telemetry, analyze what attackers deploy after gaining access, and pivot from an attacking host into the broader infrastructure behind it.
The role spans the full research process. You will hunt for interesting activity, investigate what you find, develop methods and detections to identify similar activity at scale, and turn those investigations into original threat intelligence. You will help build the tooling and detections needed to support your research and improve Vuln Check's ability to identify meaningful attacker activity.
You will be the first full-time threat hunter at Vuln Check, so there is no existing threat hunting pipeline or playbook to inherit. You will have substantial latitude to define areas of research and help establish how Vuln Check approaches threat hunting as the function grows.
This role is fully remote and open to candidates based anywhere in the United States.
What You'll Do- Hunt for emerging exploitation activity, attacker infrastructure, and novel attacker behavior across Vuln Check's data
- Turn discoveries from threat hunting into durable improvements to Vuln Check's detection capabilities, including new rules, queries, tooling, and automation
- Investigate exploitation attempts, attacker payloads, binaries, infrastructure, and post-exploitation activity
- Build tooling and automation to support threat hunting and large-scale analysis
- Pivot across vulnerabilities, hosts, IPs, domains, payloads, and other infrastructure to uncover relationships and broader activity
- Turn research findings into actionable threat intelligence for Vuln Check customers
- Write customer-facing threat intelligence reports and technical blog posts that clearly explain what you found and why it matters
- Present research at conferences and other industry events
- Work with vulnerability researchers and other members of the Vuln Check research team to connect observed exploitation with vulnerability intelligence
- Help shape the direction, methodology, and capabilities of Vuln Check's threat hunting function as it grows
- Use Vuln Check's data and products as an expert customer, identify gaps in our ability to detect or investigate attacker activity, and help drive improvements to close those gaps
- A demonstrated track record of communicating technical security research through public writing, threat intelligence reports, blogs, presentations, or other published work
- Experience hunting for threats, analyzing attacker activity, conducting threat intelligence research, or performing closely related security research
- The ability to read and analyze PCAPs and reason about network traffic and protocols
- Demonstrated experience developing and tuning detections, including Suricata and/or Snort rules, and translating research findings into repeatable detection capabilities
- Experience writing Nuclei templates or other scanners to identify vulnerabilities, exposed…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).