RemoteHunt

Senior OT Threat Hunter

Dragos · United States · posted Sep 10, 2026

seniorindustrial control systems

What this role actually asks for

Extracted by RemoteHunt

Must have

  • Hypothesis-driven threat hunts in ICS/OT networks
  • Analyze suspicious activities and platform detections
  • Collaborate with Intelligence, R&D, and Engineering
  • Serve as escalation point for threat hunting team
  • Advise customers during critical security events

Nice to have

  • Experience with ICS/OT cybersecurity
  • Familiarity with threat intelligence platforms

Tools and technologies

Dragos Platform

The full posting

<div class="content-intro"><p><span class="TextRun SCXW107525881 BCX8" lang="EN-US" data-contrast="none"><span class="NormalTextRun SCXW107525881 BCX8">At Dragos, the mission is personal. The systems we protect deliver the water you drink, power your home, and keep the hospitals your community depends on running. Those critical infrastructure systems that power our civilization around the world are under attack every day by adversaries. When those systems fail, people are&nbsp;</span><span class="NormalTextRun SCXW107525881 BCX8">immediately</span><span class="NormalTextRun SCXW107525881 BCX8">&nbsp;at risk.&nbsp;</span><span class="NormalTextRun SCXW107525881 BCX8">We are the global leader in&nbsp;</span><span class="NormalTextRun SCXW107525881 BCX8">xOT</span><span class="NormalTextRun SCXW107525881 BCX8">&nbsp;cybersecurity, combining technology, threat intelligence, and expert services. The people here chose this work because they understand&nbsp;</span><span class="NormalTextRun SCXW107525881 BCX8">what is</span><span class="NormalTextRun SCXW107525881 BCX8">&nbsp;at stake</span><span class="NormalTextRun SCXW107525881 BCX8">. Here, you will find a remote-first mission-driven team across North America, Europe, the Middle East, and APAC built on authenticity, transparency, and trust. If safeguarding the systems that protect your family, friends, and community is the kind of work that matters to you, you are in the right place.</span></span><span class="EOP Selected SCXW107525881 BCX8" data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:160,&quot;335559740&quot;:360}">&nbsp;</span></p></div><p><strong><span data-contrast="auto">About the Role</span></strong><span data-contrast="auto">:</span><span data-ccp-props="{}">&nbsp;</span></p> <p><span data-contrast="auto">As a Senior OT Threat Hunter on the OT Watch team, you will serve as a key contributor to a strategic and persistent threat hunting solution designed to identify adversaries operating within customer OT networks using the Dragos Platform. The technology solution provides deep access and visibility into ICS/OT environments, and our team are expected to leverage their expertise to uncover sophisticated threats and drive measurable improvements to the overall program.</span> <span data-contrast="auto">OT Watch prioritizes strategic views of suspicious activities, normal events, platform detections (also known as "notifications"), and analytical responses to these activities. In this role, you will independently lead hunting operations, act as an escalation point for the broader team, and collaborate cross-functionally with Intelligence, Services and and Engineering teams to continuously elevate detection and offering capabilities. You will also serve as a trusted advisor to customers during critical security events, delivering clear and actionable guidance.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}">&nbsp;</span></p> <p><strong><span data-contrast="auto">Responsibilities</span></strong><span data-contrast="auto">:</span><span data-ccp-props="{}">&nbsp;</span></p> <ul> <li>Lead hands-on, hypothesis-driven threat hunts across industrial (ICS/OT) networks — working with Intelligence, R&amp;D, and Engineering to find adversaries and uncover attack patterns others miss.</li> <li>Act as the top escalation point for high-severity alerts, guiding OT Hunters and analysts, and communicating directly with clients about critical findings, remediation steps, and technical questions.</li> <li>Configure and optimize the Dragos Platform and hunt profiles for each customer environment to catch real threats while cutting down false alarms.</li> <li>Develop new hunting hypotheses and hunt content based on real operational experience, and give structured feedback to Detection Engineering and Intelligence teams to sharpen indicators, reports, and platform outputs.</li> <li>Dig into suspicious network activity, validate what triggers alerts, and contribute to clear incident summaries and custom reports for both technical and non-technical audiences.</li> <li>Create scripts, workflows, and tooling to make hunting faster and more repeatable, while mentoring junior team members in OT protocols, adversary tactics, and threat intelligence.</li> </ul> <p><strong><span data-contrast="auto">Qualifications</span></strong><span data-contrast="auto">:</span><span data-ccp-props="{}">&nbsp;</span></p> <ul> <li><span data-contrast="auto">Demonstrated experience in hypothesis-based threat hunting. Able to reason from an intelligence source to a testable hunt and successful investigation.&nbsp;</span></li> <li><span data-contrast="auto">Experience analyzing network telemetry and identifying behavioral deviations/anomalies (not solely endpoint-focused).&nbsp;</span></li> <li data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Strong understanding of networking concepts (e.g., TCP/IP, firewalls, DNS, packet analysis).</span></li> <li data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="3" data-aria-level="1">Experience with PCAP analysis, IDS/IPS, SIEM platforms, or other network traffic analysis tools in an OT context. </li> <li data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="3" data-aria-level="1">Deep familiarity with adversary tactics, techniques, and procedures (TTPs) relevant to OT environments, including MITRE ATT&amp;CK for ICS. </li> <li data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="3" data-aria-level="1">Familiarity with threat intelligence workflows, including consumption and feedback loops with intelligence and detection engineering teams. </li> <li data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="3" data-aria-level="1">Proven ability to communicate complex security findings to clients and internal stakeholders, both verbally and in writing. </li> <li data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="3" data-aria-level="1">Experience acting as a technical escalation point or senior contributor in a security operations or threat hunting context.</li> <li data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="3" data-aria-level="1"><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}">Experience with ICS/OT environments is strongly preferred.&nbsp;</span></li> </ul> <p><strong><span data-contrast="auto">Compensation</span></strong><span data-contrast="auto">:</span><span data-ccp-props="{}">&nbsp;</span></p> <ul> <li data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="none">Salary: $140,000</span></li> <li data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="1" data-aria-level="1">Competitive Equity Package <span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335557856&quot;:16777215,&quot;335559738&quot;:0,&quot;335559739&quot;:0}">&nbsp;</span></li> <li data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="1" data-aria-level="1">Comprehensive Benefits Plan<span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335557856&quot;:16777215,&quot;335559738&quot;:0,&quot;335559739&quot;:0}">&nbsp;</span></li> </ul> <p><span data-ccp-props="{}">&nbsp;</span></p> <p><span data-contrast="none">#LI-JF1 #LI-REMOTE&nbsp;</span> <span data-ccp-props="{}">&nbsp;</span></p> <p>&nbsp;</p><div class="content-conclusion"><p>Dragos is an Equal Opportunity Employer and considers applicants for employment without regard to race, color, religion, sex, orientation, national origin, age, disability, genetics, or any other basis forbidden under federal, state, or local laws. All new hires must pass a background check as a condition of employment.</p></div>

Is this one actually worth your time?

RemoteHunt scores every remote job 0–100 against your own resume, so you apply to the handful that fit instead of the hundred that don't. Free plan, no card required.