Generate a McCoy IQ challenge in 30 seconds.
See how candidates think and approach the work this role demands, before the phone screen. We'll build a video challenge from this posting, and you can edit or share it before it goes live.
Key details
Job Description
<div class="content-intro"><p><span class="TextRun SCXW107525881 BCX8" lang="EN-US" data-contrast="none"><span class="NormalTextRun SCXW107525881 BCX8">At Dragos, the mission is personal. The systems we protect deliver the water you drink, power your home, and keep the hospitals your community depends on running. Those critical infrastructure systems that power our civilization around the world are under attack every day by adversaries. When those systems fail, people are&nbsp;</span><span class="NormalTextRun SCXW107525881 BCX8">immediately</span><span class="NormalTextRun SCXW107525881 BCX8">&nbsp;at risk.&nbsp;</span><span class="NormalTextRun SCXW107525881 BCX8">We are the global leader in&nbsp;</span><span class="NormalTextRun SCXW107525881 BCX8">xOT</span><span class="NormalTextRun SCXW107525881 BCX8">&nbsp;cybersecurity, combining technology, threat intelligence, and expert services. The people here chose this work because they understand&nbsp;</span><span class="NormalTextRun SCXW107525881 BCX8">what is</span><span class="NormalTextRun SCXW107525881 BCX8">&nbsp;at stake</span><span class="NormalTextRun SCXW107525881 BCX8">. Here, you will find a remote-first mission-driven team across North America, Europe, the Middle East, and APAC built on authenticity, transparency, and trust. If safeguarding the systems that protect your family, friends, and community is the kind of work that matters to you, you are in the right place.</span></span><span class="EOP Selected SCXW107525881 BCX8" data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:160,&quot;335559740&quot;:360}">&nbsp;</span></p></div><p><strong><span data-contrast="auto">About the Role</span></strong><span data-contrast="auto">:</span><span data-ccp-props="{}">&nbsp;</span></p>
<p>Our Threat Intelligence team is seeking an expert-level Adversary Hunter to serve as a recognized authority in tracking and disrupting threats targeting ICS/OT environments. In this autonomous role, you'll independently own one or more Threat Groups and Temporary Activity Threads (TATs), author authoritative intelligence products, and shape our analytical tradecraft.&nbsp;You'll lead proactive and reactive threat hunting engagements, collaborate across functions, and represent Dragos externally through publications, customer briefings, and industry events. As both a technical operator and force multiplier, you'll advance our data and tooling capabilities while elevating team expertise through mentorship and knowledge sharing.&nbsp;This is a role designed for a seasoned professional who operates with high autonomy, drives methodology development, and operates as a recognized subject matter expert.</p>
<p><strong><span data-contrast="auto">Responsibilities</span></strong><span data-contrast="auto">:</span><span data-ccp-props="{}">&nbsp;</span></p>
<ul>
<li><span data-contrast="auto">Provide expert-level coverage for one or more Threat Groups and TATs, independently authoring WorldView reports and representing the team as a subject matter expert in Year in Review (YIR) publications, customer briefings, webinars, and sales engagements.</span><span data-ccp-props="{}">&nbsp;</span></li>
<li><span data-contrast="auto">Champion cross-team collaboration to reduce stovepiping and proactively support WorldView triage and reporting pipelines, ensuring intelligence flows efficiently across functions.</span> </li>
<li>Enhance and document analysis methodologies while independently tracking new Threat Groups and TATs beyond assigned scope as intelligence needs evolve. </li>
<li>Demonstrate proficiency in network telemetry tools (e.g., NetFlow, Censys, Shodan) and file-based analysis platforms (e.g., VirusTotal, Joe Sandbox) to conduct advanced threat hunting and adversary infrastructure tracking. </li>
<li>Leverage Synapse and Storm Query Language for advanced data modeling, threat hunting, and investigative workflows; continuously improve data interrogation tooling and identify automation opportunities to scale team output. </li>
<li>Lead threat hunting efforts during incident response engagements and provide advanced analytical support during high-priority surge incidents (e.g., PIPEDREAM-class events), operating with minimal oversight. </li>
<li>Serve as a recognized data and tooling subject matter expert within the team, driving knowledge transfer initiatives and elevating the analytical capabilities of peers and junior analysts.<span data-ccp-props="{}">&nbsp;</span></li>
</ul>
<p><strong><span data-contrast="auto">Qualifications</span></strong><span data-contrast="auto">:</span><span data-ccp-props="{}">&nbsp;</span></p>
<ul>
<li>5+ years of experience in threat intelligence, adversary tracking, intrusion analysis, or threat hunting, with demonstrated depth in ICS/OT-focused threat activity.</li>
<li>Proven ability to independently own and author finished intelligence products, including WorldView reports, YIR contributions, and customer-facing deliverables with minimal oversight.</li>
<li>Expert-level application of the Diamond Model, Kill Chain stages, and MITRE ATT&amp;CK for ICS across complex, multi-stage intrusion investigations.</li>
<li>Hands-on proficiency with network telemetry tools (NetFlow, Censys, Shodan), file analysis platforms (VirusTotal, Joe Sandbox), and advanced working knowledge of Synapse and Storm Query Language for threat modeling and hunting automation.</li>
<li>Experience leading or significantly contributing to threat hunting operations during live incident response engagements, including high-tempo surge events.</li>
<li>Demonstrated ability to develop software tooling or analytical automation using Python, C#, or similar languages to enhance team workflows.</li>
<li>Strong analytical and written communication skills, with an external presence or track record of knowledge sharing through publications, conference presentations, webinars, or industry engagement.</li>
</ul>
<p><strong><span data-contrast="auto">Compensation</span></strong><span data-contrast="auto">:</span><span data-ccp-props="{}">&nbsp;</span></p>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="none">Salary: $175,000</span></li>
<li data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="1" data-aria-level="1">Competitive Equity Package <span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335557856&quot;:16777215,&quot;335559738&quot;:0,&quot;335559739&quot;:0}">&nbsp;</span></li>
<li data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="1" data-aria-level="1">Comprehensive Benefits Plan<span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335557856&quot;:16777215,&quot;335559738&quot;:0,&quot;335559739&quot;:0}">&nbsp;</span></li>
</ul>
<p><span data-ccp-props="{}">&nbsp;</span></p>
<p><span data-contrast="none">#LI-JF1 #LI-REMOTE&nbsp;</span> <span data-ccp-props="{}">&nbsp;</span></p>
<p>&nbsp;</p>
<p>&nbsp;</p><div class="content-conclusion"><p>Dragos is an Equal Opportunity Employer and considers applicants for employment without regard to race, color, religion, sex, orientation, national origin, age, disability, genetics, or any other basis forbidden under federal, state, or local laws. All new hires must pass a background check as a condition of employment.</p></div>
Audit details(provenance, verification trail, raw fields)
Core fields
dragos:5254557008Provenance
dragosVerification trail
This posting hasn't been probed by our closure verifier yet. Stream C runs on a rolling schedule against postings approaching the close-decision threshold.
See how we measure for definitions, or our corrections log for known issues. Found something wrong? Flag a correction.
