Dragos Logo

Dragos

Senior OT Threat Hunter

Posted 21 Minutes Ago
Be an Early Applicant
Remote
Hiring Remotely in United States
140K-140K Annually
Senior level
Remote
Hiring Remotely in United States
140K-140K Annually
Senior level
Lead hypothesis-driven threat hunts across industrial control system and operational technology networks. Investigate suspicious activity, escalate high-severity alerts, configure Dragos Platform hunt profiles, develop hunting content, analyze network telemetry, and improve detection capabilities. Advise customers during critical security events, produce technical reports, create repeatable tooling, and mentor junior team members on OT protocols, adversary tactics, and threat intelligence.
The summary above was generated by AI

At Dragos, the mission is personal. The systems we protect deliver the water you drink, power your home, and keep the hospitals your community depends on running. Those critical infrastructure systems that power our civilization around the world are under attack every day by adversaries. When those systems fail, people are immediately at risk. We are the global leader in xOT cybersecurity, combining technology, threat intelligence, and expert services. The people here chose this work because they understand what is at stake. Here, you will find a remote-first mission-driven team across North America, Europe, the Middle East, and APAC built on authenticity, transparency, and trust. If safeguarding the systems that protect your family, friends, and community is the kind of work that matters to you, you are in the right place. 

About the Role: 

As a Senior OT Threat Hunter on the OT Watch team, you will serve as a key contributor to a strategic and persistent threat hunting solution designed to identify adversaries operating within customer OT networks using the Dragos Platform. The technology solution provides deep access and visibility into ICS/OT environments, and our team are expected to leverage their expertise to uncover sophisticated threats and drive measurable improvements to the overall program. OT Watch prioritizes strategic views of suspicious activities, normal events, platform detections (also known as "notifications"), and analytical responses to these activities. In this role, you will independently lead hunting operations, act as an escalation point for the broader team, and collaborate cross-functionally with Intelligence, Services and and Engineering teams to continuously elevate detection and offering capabilities. You will also serve as a trusted advisor to customers during critical security events, delivering clear and actionable guidance. 

Responsibilities: 

  • Lead hands-on, hypothesis-driven threat hunts across industrial (ICS/OT) networks — working with Intelligence, R&D, and Engineering to find adversaries and uncover attack patterns others miss.
  • Act as the top escalation point for high-severity alerts, guiding OT Hunters and analysts, and communicating directly with clients about critical findings, remediation steps, and technical questions.
  • Configure and optimize the Dragos Platform and hunt profiles for each customer environment to catch real threats while cutting down false alarms.
  • Develop new hunting hypotheses and hunt content based on real operational experience, and give structured feedback to Detection Engineering and Intelligence teams to sharpen indicators, reports, and platform outputs.
  • Dig into suspicious network activity, validate what triggers alerts, and contribute to clear incident summaries and custom reports for both technical and non-technical audiences.
  • Create scripts, workflows, and tooling to make hunting faster and more repeatable, while mentoring junior team members in OT protocols, adversary tactics, and threat intelligence.

Qualifications: 

  • Demonstrated experience in hypothesis-based threat hunting. Able to reason from an intelligence source to a testable hunt and successful investigation. 
  • Experience analyzing network telemetry and identifying behavioral deviations/anomalies (not solely endpoint-focused). 
  • Strong understanding of networking concepts (e.g., TCP/IP, firewalls, DNS, packet analysis).
  • Experience with PCAP analysis, IDS/IPS, SIEM platforms, or other network traffic analysis tools in an OT context.
  • Deep familiarity with adversary tactics, techniques, and procedures (TTPs) relevant to OT environments, including MITRE ATT&CK for ICS.
  • Familiarity with threat intelligence workflows, including consumption and feedback loops with intelligence and detection engineering teams.
  • Proven ability to communicate complex security findings to clients and internal stakeholders, both verbally and in writing.
  • Experience acting as a technical escalation point or senior contributor in a security operations or threat hunting context.
  • Experience with ICS/OT environments is strongly preferred. 

Compensation: 

  • Salary: $140,000
  • Competitive Equity Package  
  • Comprehensive Benefits Plan 

 

#LI-JF1 #LI-REMOTE   


Dragos is an Equal Opportunity Employer and considers applicants for employment without regard to race, color, religion, sex, orientation, national origin, age, disability, genetics, or any other basis forbidden under federal, state, or local laws. All new hires must pass a background check as a condition of employment.

Similar Jobs at Dragos

6 Hours Ago
Remote
United States
152K-152K Annually
Senior level
152K-152K Annually
Senior level
Security • Cybersecurity
Own end-to-end delivery of technical IT projects from intake and procurement through deployment and closeout. Manage SaaS rollouts, system integrations, requirements, vendor milestones, security reviews, testing, go-live, risks, dependencies, and stakeholder communications. Maintain project plans and reporting in Jira and Confluence, enforce lifecycle handoffs, manage change control, and report portfolio health. Improve delivery processes through templates, automation, intake criteria, and standardized reporting while coordinating Procurement, Engineering, IT Security, vendors, and business stakeholders.
Top Skills: Ai ToolsApi IntegrationsConfluenceJIRAJira AutomationMicrosoft 365ExcelMicrosoft TeamsMiddlewareSAMLSharepointSso
6 Hours Ago
In-Office or Remote
176K-176K Annually
Senior level
176K-176K Annually
Senior level
Security • Cybersecurity
Serve as a trusted technical advisor for critical infrastructure customers across Australia and APAC. Lead onboarding, adoption, workshops, training, account reviews, and value-realization planning while improving customers’ OT cybersecurity maturity. Guide integrations, security workflows, risk reduction, and cyber resilience initiatives. Monitor account health, address adoption risks, collaborate with internal teams, and provide customer feedback. Travel throughout Australia, New Zealand, and APAC up to 30%.
Top Skills: AescsfDcsIsa/Iec 62443Nist CsfOt/Ics CybersecuritySans Ics Five Critical ControlsScada
6 Hours Ago
Remote
United States
154K-154K Annually
Senior level
154K-154K Annually
Senior level
Security • Cybersecurity
Serve as the primary technical advisor for federal customers using the Dragos OT cybersecurity platform. Lead onboarding, implementation, adoption, account reviews, roadmap alignment, optimization, customer health monitoring, and recovery plans. Partner with Customer Success, Support, Product, and Sales while delivering cybersecurity training, workshops, and executive briefings. Apply ICS/OT expertise to help customers operationalize security use cases, improve maturity, mitigate risk, and achieve measurable value.
Top Skills: DcsDragos PlatformElasticFirewallsFortisiemIcsQradarScadaSIEMSpan/TapsSplunkVlans

What you need to know about the Chicago Tech Scene

With vibrant neighborhoods, great food and more affordable housing than either coast, Chicago might be the most liveable major tech hub. It is the birthplace of modern commodities and futures trading, a national hub for logistics and commerce, and home to the American Medical Association and the American Bar Association. This diverse blend of industry influences has helped Chicago emerge as a major player in verticals like fintech, biotechnology, legal tech, e-commerce and logistics technology. It’s also a major hiring center for tech companies on both coasts.

Key Facts About Chicago Tech

  • Number of Tech Workers: 245,800; 5.2% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: McDonald’s, John Deere, Boeing, Morningstar
  • Key Industries: Artificial intelligence, biotechnology, fintech, software, logistics technology
  • Funding Landscape: $2.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Pritzker Group Venture Capital, Arch Venture Partners, MATH Venture Partners, Jump Capital, Hyde Park Venture Partners
  • Research Centers and Universities: Northwestern University, University of Chicago, University of Illinois Urbana-Champaign, Illinois Institute of Technology, Argonne National Laboratory, Fermi National Accelerator Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account