Lead Windows threat detection research and EDR sensor development for SMB customers. Requires deep Windows kernel expertise, reverse engineering, EDR bypass testing, and AI-augmented research to build innovative, automated defenses.
200k – 230k/yr
Remote7+ YOESecurity Engineering
About the role
What You’ll Do
Identify innovative ways to detect Windows OS threats
Develop cross-platform features that leverage telemetry from common OS subsystems such as file system, memory, process, and network activity
Research and development of sensor capabilities to provide visibility and detection support for attack techniques across supported Windows OS versions
Work collaboratively with internal engineering and detection teams to implement detection logic
Identify and evaluate new telemetry opportunities
Identify and address gaps in product coverage
Respond to product escalations
Perform False Positive and False Negative investigations
Lead product research initiatives to develop and evaluate security product strategies and technologies
Coordinate with Product and Engineering teams to integrate and operationalize solutions developed by Threat Operations teams
Applies AI as a practical part of day-to-day product research work to improve the speed, quality, and impact of research outputs
Uses AI to support information gathering, analysis, prototyping, and production of clear, decision-useful work products while maintaining accountability for the final output
Builds and reuses lightweight prompts, templates, or workflows for recurring research tasks rather than relying on one-off use
Build internal and external technical documentation to educate customers and communicate research findings to adjacent teams about security risks and opportunities
Mentor and teach technical expertise to advance the broader community
Promote Huntress’ reputation through media interaction, public speaking, CFPs, CTFs, and blogs
Qualifications
Expert in Windows OS internals, components, APIs, and design
Prior experience with Windows OS kernel coding and device drivers
Experience testing EDRs, bypasses, and evasion techniques
Comfortable with reverse engineering and using debuggers
Proficiency in multiple programming/scripting languages, such as C/C++/C#, PowerShell, and Python
Applies AI to improve research quality, speed, and outputs in day-to-day work
Commitment to clear documentation of research findings
Experience with MITRE ATT&CK matrix, SIGMA, Yara, and Elasticsearch/Kibana
What We Offer
100% remote work environment
Generous paid time off policy, including vacation, sick time, and paid holidays
12 weeks of paid parental leave
Highly competitive and comprehensive medical, dental, and vision benefits plans
401(k) with a 5% contribution regardless of employee contribution
Life and Disability insurance plans
Stock options for all full-time employees
One-time $500 reimbursement for building/upgrading home office
Annual allowance for education and professional development assistance
$75 USD/month digital reimbursement
Access to the BetterUp platform for coaching, personal, and professional growth
Skills
windows os internalskernel codingdevice driversedr testingreverse engineeringdebuggersc/c++C#PowerShellPythonAImitre att&ckSigmayaraElasticsearch
Leads threat intelligence research, aggregates data for customer and marketing reports, builds threat intelligence programs using internal/external sources, and collaborates with security/product teams on roadmaps. Requires SIEM expertise, threat hunting, OSINT, and development skills.
200k – 225k/yr
RemoteSecurity Engineering
Principal Product Security Researcher
ChainguardUnited States
As a Principal Product Security Researcher, you will lead Chainguard's product security research, mapping emerging threats and shaping security direction across products and platforms. This role involves identifying systematic weaknesses and driving multi-quarter initiatives to reduce risk and improve security maturity.
201k – 226k/yr
RemoteSecurity Engineering
Principal Security Engineer, Data Security
UpstartUnited States
Principal-level security engineer defining infrastructure security strategy and leading cross-functional efforts to secure cloud, Kubernetes, and developer platforms at scale.
191k – 264k/yr
Remote8+ YOESecurity Engineering
Principal Network Architect
CommandLinkUnited States
Principal-level network architect to design, expand, and commercialize private connectivity, cloud interconnect, and transport services. Own edge deployments, carrier negotiations, and product packaging for a fully remote infrastructure role.
180k – 250k/yr
Remote7+ YOESecurity Engineering
Principal Information Security Engineer
SentiLinkAustin, TX +5
SentiLink is seeking a Principal Information Security Engineer to lead and enhance security across infrastructure, applications, and internal systems. This hands-on role involves building scalable security foundations, designing secure systems, and improving detection and response capabilities.