Hiring.Camp

Threat Hunter/Purple Team Operator

Sixgeninc

·

Today

Location
Remote
Workplace
Remote
Type
Full-time
Department
Operations
Experience
3+ years
Clearance
Required
Source
Greenhouse

Description

Threat Hunter / Purple Team Operator

SIXGEN's mission is to deliver agile, mission-ready cybersecurity solutions that empower government and critical infrastructure organizations to stay ahead of advanced cyber threats. We combine innovation, deep expertise, and leading technical capabilities to uncover vulnerabilities, protect vital systems, and strengthen operational resilience.

POSITION OVERVIEW

  • Position: Mid-Level Threat Hunter / Purple Team Operator
  • Job Type: Full Time
  • Location: Remote with travel to customers and test locations as required
  • Clearance Requirement: Active Top Secret with SCI eligibility

WHAT YOU'LL DO

SIXGEN is seeking a mid-level Threat Hunter / Purple Team Operator to  identify threats that evade existing detection methods, develop and test hunting hypotheses, and feed findings back into detection engineering. This role will combine remote threat hunting and on-site purple team coordination in direct support of red team engagements to secure systems, strengthen the defenders, and build and validate detection methods that can catch offensive traffic in real time.

This role requires comfort working independently through remote hunts as well as the ability to translate adversary tradecraft into defensive guidance.

Responsibilities include:

  • Conduct hypothesis-driven and intelligence-led threat hunts across endpoints, networks, and cloud telemetry for several weeks prior to each red team engagement.
  • Analyze logs, alerts, and historical data for indicators of compromise (IOCs), anomalous behavior, and adversary TTPs mapped to the MITRE ATT&CK from partner-provided sources (EDR, SIEM, authentication/identify logs).
  • Document hunt coverage and methodology, findings, detection recommendations, and any confirmed or suspected compromise, escalating immediately if active adversary activity is found.
  • Deliver a threat hunt summary and determine if the customer environment is clear prior to red team assessments.
  • Partner with blue teams during the purple portion of the engagement to assist in detecting, tuning, and validating controls against red team TTPs in real-time.
  • Brief technical and non-technical stakeholders on hunt result and purple team detection outcomes.
  • Serve as a Trusted Agent during the red team assessment and maintain strict confidentiality and operational security with insight into both red and blue team activity.

Technology proficiency includes:

  • SIEM platforms (e.g., Splunk, Microsoft Sentinel, Elastic).
  • EDR/XDR tooling (e.g. CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne, Carbon Black).
  • Network detection and traffic analysis tools (e.g. Zeek, Suricata, full packet capture).
  • Log aggregation and correlation across endpoint, network, cloud, and identity sources (e.g., Azure AD/Entra ID, AWS CloudTrail, Microsoft 365).
  • MITRE ATT&CK framework for mapping hunts and detections to adversary TTPs.
  • Query and scripting languages for hunting and automation (e.g. KQL, SPL, Python).
  • Familiarity with common red team tooling and tradecraft (e.g., Cobalt Strike, Havoc, and other C2 traffic patterns) to help recognize and detect it.

WHAT YOU BRING

Required qualifications:

  • 3 – 5+ years of experience in threat hunting, SOC/detection engineering, incident response, or a closely related defensive security role.
  • Hand-on experience working with a major SIEM and EDR platform.
  • Working knowledge of the MITRE ATT&CK framework and how to map observed activity to adversary TTPs.
  • Understanding of common adversary tradecraft and red team testing methodology to help close detection gaps.
  • Strong written and verbal communication skills with the ability to produce clear, customer-facing findings and an “all clear” determination.
  • Comfortable operating independently in remote, customer-facing roles.
  • U.S. citizenship, with eligibility to obtain and maintain a U.S. government security clearance.

Preferred qualifications:

  • Industry certifications such as GCFA, GCIH, GNFA, GCTI, CySA+, or equivalent.
  • Prior experience performing threat hunting and/or purple team role working directly alongside a red team.
  • Scripting and automation experience to streamline hunting workflows (e.g., Python, PowerShell).
  • Prior experience working with multiple partner organizations or client environments.
  • Active TS/SCI clearance.

COMPENSATION AND BENEFITS

SIXGEN offers competitive compensation based on the responsibilities of the role and the candidate's experience, qualifications, specialized expertise, and security-clearance status. The final compensation package will be discussed during the hiring process.

SIXGEN offers benefits for full-time employees, including:

  • Employer-paid health insurance premiums, including medical, dental, and vision coverage, for employees and their families
  • Employer-paid short- and long-term disability insurance and basic life and AD&D insurance
  • 401(k) plan with a 4% employer contribution
  • Professional-development reimbursement options for training, certifications, and education
  • Flexible and remote-work policies for most positions
  • Flexible paid time off and holiday schedule

For more information, please contact Human Strategist Amy Maxwell at [email protected].

OUR COMMITMENT

SIXGEN is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, age, marital status, ancestry, protected veteran status, or any other characteristic protected by applicable law.

We are committed to fostering an inclusive culture that values diversity in our people and reflects the communities and customers we serve. We strive to attract and retain a diverse talent pool and to create an environment where everyone is empowered to do their best work.

 

Skills

PythonAWSAzureCybersecuritySIEMSOCSplunk