SixGen, Inc.
Threat Hunter/Purple Team Operator
- Confirmed live in the last 24 hours
- No salary listed
- Mid level
- Remote
- 3+ yrs exp
- Added today
About this role
Threat Hunter / Purple Team Operator
SIXGEN's mission is to deliver agile, mission-ready cybersecurity solutions that empower government and critical infrastructure organizations to stay ahead of advanced cyber threats. We combine innovation, deep expertise, and leading technical capabilities to uncover vulnerabilities, protect vital systems, and strengthen operational resilience.
POSITION OVERVIEW
- Position: Mid-Level Threat Hunter / Purple Team Operator
- Job Type: Full Time
- Location: Remote with travel to customers and test locations as required
- Clearance Requirement: Active Top Secret with SCI eligibility
WHAT YOU'LL DO
SIXGEN is seeking a mid-level Threat Hunter / Purple Team Operator to identify threats that evade existing detection methods, develop and test hunting hypotheses, and feed findings back into detection engineering. This role will combine remote threat hunting and on-site purple team coordination in direct support of red team engagements to secure systems, strengthen the defenders, and build and validate detection methods that can catch offensive traffic in real time.
This role requires comfort working independently through remote hunts as well as the ability to translate adversary tradecraft into defensive guidance.
Responsibilities include
- Conduct hypothesis-driven and intelligence-led threat hunts across endpoints, networks, and cloud telemetry for several weeks prior to each red team engagement.
- Analyze logs, alerts, and historical data for indicators of compromise (IOCs), anomalous behavior, and adversary TTPs mapped to the MITRE ATT&CK from partner-provided sources (EDR, SIEM, authentication/identify logs).
- Document hunt coverage and methodology, findings, detection recommendations, and any confirmed or suspected compromise, escalating immediately if active adversary activity is found.
- Deliver a threat hunt summary and determine if the customer environment is clear prior to red team assessments.
- Partner with blue teams during the purple portion of the engagement to assist in detecting, tuning, and validating controls against red team TTPs in real-time.
- Brief technical and non-technical stakeholders on hunt result and purple team detection outcomes.
- Serve as a Trusted Agent during the red team assessment and maintain strict confidentiality and operational security with insight into both red and blue team activity.
Technology proficiency includes
- SIEM platforms (e.g., Splunk, Microsoft Sentinel, Elastic).
- EDR/XDR tooling (e.g. CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne, Carbon Black).
- Network detection and traffic analysis tools (e.g. Zeek, Suricata, full packet capture).
- Log aggregation and correlation across endpoint, network, cloud, and identity sources (e.g., Azure AD/Entra ID, AWS CloudTrail, Microsoft 365).
- MITRE ATT&CK framework for mapping hunts and detections to adversary TTPs.
- Query and scripting languages for hunting and automation (e.g. KQL, SPL, Python).
- Familiarity with common red team tooling and tradecraft (e.g., Cobalt Strike, Havoc, and other C2 traffic patterns) to help recognize and detect it.
WHAT YOU BRING
Required qualifications
- 3 – 5+ years of experience in threat hunting, SOC/detection engineering, incident response, or a closely related defensive security role.
- Hand-on experience working with a major SIEM and EDR platform.
- Working knowledge of the MITRE ATT&CK framework and how to map observed activity to adversary TTPs.
- Understanding of common adversary tradecraft and red team testing methodology to help close detection gaps.
- Strong written and verbal communication skills with the ability to produce clear, customer-facing findings and an “all clear” determination.
- Comfortable operating independently in remote, customer-facing roles.
- U.S. citizenship, with eligibility to obtain and maintain a U.S. government security clearance.
Preferred qualifications
- Industry certifications such as GCFA, GCIH, GNFA, GCTI, CySA+, or equivalent.
- Prior experience performing threat hunting and/or purple team role working directly alongside a red team.
- Scripting and automation experience to streamline hunting workflows (e.g., Python, PowerShell).
- Prior experience working with multiple partner organizations or client environments.
- Active TS/SCI clearance.
COMPENSATION AND BENEFITS
SIXGEN offers competitive compensation based on the responsibilities of the role and the candidate's experience, qualifications, specialized expertise, and security-clearance status. The final compensation package will be discussed during the hiring process.
SIXGEN offers benefits for full-time employees, including
- Employer-paid health insurance premiums, including medical, dental, and vision coverage, for employees and their families
- Employer-paid short- and long-term disability insurance and basic life and AD&D insurance
- 401(k) plan with a 4% employer contribution
- Professional-development reimbursement options for training, certifications, and education
- Flexible and remote-work policies for most positions
- Flexible paid time off and holiday schedule
For more information, please contact Human Strategist Amy Maxwell at [email protected].
OUR COMMITMENT
SIXGEN is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, age, marital status, ancestry, protected veteran status, or any other characteristic protected by applicable law.
We are committed to fostering an inclusive culture that values diversity in our people and reflects the communities and customers we serve. We strive to attract and retain a diverse talent pool and to create an environment where everyone is empowered to do their best work.
Written by SixGen, Inc.. Original job post
Skills mentioned
- Agile
- AWS
- Azure
- Python
- Splunk
- TypeScript
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
SixGen, Inc.
SixGen, Inc. provides cybersecurity and intelligence solutions, including network access technologies, vulnerability management, security analytics, and mobile application security tools. The company is hiring for specialized security roles including IT field specialists, vulnerability management engineers, security analysts, mobile reverse engineers, and mobile exploit developers.
- Industry
- Technology & Software
Likely interview questions
- Describe your experience conducting hypothesis-driven threat hunts, and what tools you've utilized for these hunts.
- How do you leverage the MITRE ATT&CK framework to map observed activity and inform your threat hunting approach?