Logo for Dragos, Inc.

Senior Capabilities Hunter

Role overview

Qualifications

  • 2–3 years of experience in Capabilities Development, Threat Hunting, Network-Based Intrusion Analysis, Vulnerability Analysis, and/or Detections Development
  • Experience with software development in C#, Python, or similar languages
  • Familiarity with pivoting across the Diamond Model, all stages of the Kill Chain, and MITRE ATTCK
  • Strong report writing skills, with experience producing technical intelligence reports for operational teams and customer-facing audiences

Responsibilities

  • Develop and maintain tools and documentation for capability identification and analysis, collaborating across threat hunt, research, intelligence, product, and engineering teams
  • Uphold technical excellence through robust code, testing frameworks, and independent problem-solving on complex defects
  • Hunt for and analyze adversary capabilities across assigned threat groups, contributing to threat assessments, WorldView reporting, and customer advisories
  • Leverage Synapse, Storm Query Language, intel tools (NetFlow, Censys, VirusTotal, Joe Sandbox, Shodan) to support threat tracking and investigative workflows

Key facts

  • Remote from: United States
  • Full time
  • Senior (5-10 years)
  • English

Other skills

  • Problem Solving
  • Collaboration
  • Communication

About the company

Dragos, Inc. logo

Dragos, Inc.

Dragos has a global mission to safeguard civilization from those trying to disrupt the industrial infrastructure we depend on every day. The Dragos Platform offers the most effective industrial cybersecurity technology, giving customers visibility into their ICS/OT assets, vulnerabilities, threats, and response actions. The strength behind the Dragos Platform comes from our ability to codify Dragos's industry-leading OT threat intelligence, and insights from the Dragos services team, into the software. Our community-focused approach gives you access to the largest array of industrial organizations participating in collective defense, with the broadest visibility available.  Our solutions protect organizations across a range of industries, including electric, oil & gas, manufacturing, building automation systems, chemical, government, water, food & beverage, mining, transportation, and pharmaceutical. Dragos is privately held and headquartered in the Washington, DC area with regional presence around the world, including Canada, Australia, New Zealand, Europe, and the Middle East.

Company details

Company size501 - 1000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

At Dragos, the mission is personal. The systems we protect deliver the water you drink, power your home, and keep the hospitals your community depends on running. Those critical infrastructure systems that power our civilization around the world are under attack every day by adversaries. When those systems fail, people are immediately at risk. We are the global leader in xOT cybersecurity, combining technology, threat intelligence, and expert services. The people here chose this work because they understand what is at stake. Here, you will find a remote-first mission-driven team across North America, Europe, the Middle East, and APAC built on authenticity, transparency, and trust. If safeguarding the systems that protect your family, friends, and community is the kind of work that matters to you, you are in the right place. 

About the Role: 

Dragos' Threat Hunt and Research teams focus intensely on adversary capabilities targeting ICS/OT networks. As a Senior Capabilities Hunter, you'll hunt for, identify, and analyze the tools, techniques, and methodologies that threat actors deploy against critical infrastructure. You'll serve as a technical specialist understanding how adversaries build and deploy their arsenals—from custom malware and exploits to novel attack tradecraft. Working closely with Adversary Hunters and cross-functional teams, you'll develop tools and scripts for capability analysis that inform detection strategies, threat assessments, and customer advisories. Your work directly enhances Dragos' ability to defend against the most advanced threats targeting critical infrastructure globally.

Responsibilities: 

  • Develop and maintain tools and documentation for capability identification and analysis, collaborating across threat hunt, research, intelligence, product, and engineering teams.
  • Uphold technical excellence through robust code, testing frameworks, and independent problem-solving on complex defects.
  • Hunt for and analyze adversary capabilities across assigned threat groups, contributing to threat assessments, WorldView reporting, and customer advisories.
  • Leverage Synapse, Storm Query Language, intel tools (NetFlow, Censys, VirusTotal, Joe Sandbox, Shodan) to support threat tracking and investigative workflows.
  • Identify automation opportunities in analysis methodologies and recommend solutions for telemetry and data visibility gaps.
  • Represent the team in external communications, including webinars, industry partnerships, and Year in Review initiatives.
  • Provide hunting and triage support during surge events and incident response engagements.

Qualifications: 

  • 2–3 years of experience in Capabilities Development, Threat Hunting, Network-Based Intrusion Analysis, Vulnerability Analysis, and/or Detections Development. 
  • Experience with software development in C#, Python, or similar languages.
  • Familiarity with pivoting across the Diamond Model, all stages of the Kill Chain, and MITRE ATT&CK.
  • Strong report writing skills, with experience producing technical intelligence reports for operational teams and customer-facing audiences.
  • Demonstrated knowledge of adversarial Threat Groups, including tactics, techniques, procedures, and the adversary lifecycle.
  • Experience contributing to cross-functional projects and collaborating with internal and external teams.
  • Knowledge of network analysis and common malware functionality and operations. 

Compensation: 

  • Salary: $152,000
  • Competitive Equity Package  
  • Comprehensive Benefits Plan 

 

#LI-JF1 #LI-REMOTE   

 

 

Dragos is an Equal Opportunity Employer and considers applicants for employment without regard to race, color, religion, sex, orientation, national origin, age, disability, genetics, or any other basis forbidden under federal, state, or local laws. All new hires must pass a background check as a condition of employment.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Related jobs

Other jobs at Dragos, Inc.

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.