Senior Capabilities Hunter
Dragos
- Location
- United States
- Work model
- Remote
- Level
- Senior
- Salary
- $152k/yr
- Posted
- 5h ago
Skills
About this role
At Dragos, the mission is personal. The systems we protect deliver the water you drink, power your home, and keep the hospitals your community depends on running. Those critical infrastructure systems that power our civilization around the world are under attack every day by adversaries. When those systems fail, people are immediately at risk. We are the global leader in xOT cybersecurity, combining technology, threat intelligence, and expert services. The people here chose this work because they understand what is at stake . Here, you will find a remote-first mission-driven team across North America, Europe, the Middle East, and APAC built on authenticity, transparency, and trust. If safeguarding the systems that protect your family, friends, and community is the kind of work that matters to you, you are in the right place. About the Role : Dragos' Threat Hunt and Research teams focus intensely on adversary capabilities targeting ICS/OT networks. As a Senior Capabilities Hunter, you'll hunt for, identify, and analyze the tools, techniques, and methodologies that threat actors deploy against critical infrastructure. You'll serve as a technical specialist understanding how adversaries build and deploy their arsenals—from custom malware and exploits to novel attack tradecraft. Working closely with Adversary Hunters and cross-functional teams, you'll develop tools and scripts for capability analysis that inform detection strategies, threat assessments, and customer advisories. Your work directly enhances Dragos' ability to defend against the most advanced threats targeting critical infrastructure globally. Responsibilities :
Develop and maintain tools and documentation for capability identification and analysis, collaborating across threat hunt, research, intelligence, product, and engineering teams. Uphold technical excellence through robust code, testing frameworks, and independent problem-solving on complex defects. Hunt for and analyze adversary capabilities across assigned threat groups, contributing to threat assessments, WorldView reporting, and customer advisories. Leverage Synapse, Storm Query Language, intel tools (NetFlow, Censys, VirusTotal, Joe Sandbox, Shodan) to support threat tracking and investigative workflows. Identify automation opportunities in analysis methodologies and