Senior OT Threat Hunter
Quick Summary
Lead independent, hypothesis‑driven threat hunting operations across customer ICS/OT environments, investigating suspicious network behaviors to identify adversaries, anomalies, and misconfigurations.
5+ years of experience in threat hunting, security monitoring, or incident response within ICS/OT environments. Strong understanding of networking concepts (e.g., TCP/IP, firewalls, DNS,
Dragos is on a relentless mission to defend industrial organizations that provide us with the necessities of modern civilization; running water, functioning electricity, and safe industrial working environments. As the market leader in ICS/OT Cybersecurity, we are dedicated to arming our customers with best-in-class technology, threat intelligence, and services to protect their systems as effectively and efficiently as possible. We’re a remote-first culture with operations in North America, Europe, the Middle East, and APAC. We’re looking for mission-oriented teammates who embody our core values of authenticity, transparency, and trust. Are you ready to make a difference? Come join a mission that can save the world!
About the Role:
As a Senior OT Threat Hunter on the OT Watch team, you will play a key role in delivering Dragos’ proactive threat hunting service, focused on identifying adversary activity within customer OT environments using the Dragos Platform. Leveraging deep visibility into OT networks and your industrial domain expertise, you will uncover sophisticated threats and help drive continuous improvements to the threat hunting program. You will independently lead hunt operations, serve as an escalation point for the team, and collaborate closely with Intelligence, Services, Product, and Engineering partners to enhance detections and overall capabilities. You will also act as a trusted advisor to customers during critical security events, providing clear, actionable guidance grounded in technical analysis.
Responsibilities:
- Lead independent, hypothesis‑driven threat hunting operations across customer ICS/OT environments, investigating suspicious network behaviors to identify adversaries, anomalies, and misconfigurations.
- Serve as the primary escalation point for high‑severity events detected in the Dragos Platform, guiding OT Hunters and Security Analysts through triage, analysis, and response.
- Communicate critical findings directly to customers, providing clear, actionable remediation guidance and confidently addressing technical questions during security events.
- Tune and optimize Dragos Platform configurations and distributed hunt profiles to improve detection fidelity, reduce noise, and validate detection triggers based on operational findings.
- Develop and refine original hunt hypotheses, content, and workflows, and provide structured feedback to Detection Engineering and Intelligence teams to enhance detections, IOCs, and threat intelligence outputs.
- Contribute to operational reporting and incident summaries, support custom reporting needs, and mentor junior team members to promote technical rigor, knowledge sharing, and continuous improvement across the team.
Qualifications:
- 5+ years of experience in threat hunting, security monitoring, or incident response within ICS/OT environments.
- Strong understanding of networking concepts (e.g., TCP/IP, firewalls, DNS, packet analysis) and OT-specific protocols (e.g., Modbus, DNP3, Ethernet/IP).
- Experience with PCAP analysis, IDS/IPS, SIEM platforms, or other network traffic analysis tools in an OT context.
- Deep familiarity with adversary tactics, techniques, and procedures (TTPs) relevant to OT environments, including MITRE ATT&CK for ICS.
- Familiarity with threat intelligence workflows, including consumption and feedback loops with intelligence and detection engineering teams.
- Proven ability to communicate complex security findings to clients and internal stakeholders, both verbally and in writing.
- Experience acting as a technical escalation point or senior contributor in a security operations or threat hunting context.
- Ability to work independently and lead efforts in a remote, distributed team environment.
Compensation:
- Salary: 150,000 AUD
- Competitive Equity Package
- Comprehensive Benefits Plan
#LI-JF1 #LI-REMOTE
Dragos is an Equal Opportunity Employer and considers applicants for employment without regard to race, color, religion, sex, orientation, national origin, age, disability, genetics, or any other basis forbidden under federal, state, or local laws. All new hires must pass a background check as a condition of employment.
Listing Details
- Posted
- April 2, 2026
- First seen
- April 2, 2026
- Last seen
- April 26, 2026
Posting Health
- Days active
- 23
- Repost count
- 0
- Trust Level
- 23%
- Scored at
- April 26, 2026
Signal breakdown
Please let Dragos know you found this job on Jobera.
4 other jobs at Dragos
View all →Explore open roles at Dragos.
Similar Threat Hunter jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.