Principal Threat Hunting and Emulation Engineer - Infosec

Elastic Elastic · Enterprise · United States · InfoSec

This Principal Threat Hunting and Emulation Engineer role at Elastic focuses on proactively defending the company's products and services by leading structured, hypothesis-driven threat hunts and adversary emulation exercises. The role involves partnering with various security teams, leveraging AI/ML for analysis, and translating findings into durable detections and hardened defenses. The engineer will also contribute to the security community through knowledge sharing.

What you'd actually do

  1. Lead structured, hypothesis-driven threat hunting operations across Elastic’s cloud, SaaS, endpoint, and CI/CD environments using frameworks such as PEAK, TaHiTI, or equivalent.
  2. Develop and maintain a threat hunting program at scale. Defining hunt hypotheses based on threat intelligence, ATT&CK mappings, and environmental risk profiles.
  3. Design and execute adversary emulation exercises and purple team engagements to validate detection pipelines, identify coverage gaps, and simulate real-world threat actor TTPs.
  4. Build and maintain a threat emulation library of reusable attack simulations, leveraging tools such as Atomic Red Team, Caldera, Scythe, or custom-developed tooling.
  5. Leverage AI and machine learning capabilities to accelerate hypothesis generation, anomaly detection, and the analysis of large, complex datasets during hunts.

Skills

Required

  • 8 years of experience in information security with a focus on threat hunting, detection engineering, incident response, or red/purple team operations with the Elastic Stack.
  • Demonstrated experience in conducting structured and hypothesis-driven threat hunts in complex enterprise or cloud-native environments.
  • Familiarity with threat hunting frameworks such as PEAK, TaHiTI, or Sqrrl, and the ability to apply them operationally and at scale.
  • Experience designing and executing adversary emulation exercises or purple team engagements, including scoping, execution, and post-exercise reporting.
  • Working knowledge of adversary TTPs through frameworks such as MITRE ATT&CK, and the ability to map real-world threat intelligence to hunt hypotheses.
  • Experience using AI-assisted tooling or large language models to support threat hunting workflows, such as hypothesis generation, log summarization, or anomaly triage.
  • Scripting or coding ability to automate repetitive hunt tasks or build custom tooling.
  • A curious, research-driven mindset.
  • Strong written communication skills with an ability to document technical findings clearly for both technical and executive audiences.
  • Eligible to work in Department of Defense (DoD) Impact Level 4 or above cloud service environments.

Nice to have

  • Background in both detection engineering and incident response
  • Experience threat hunting in cloud environments (AWS, GCP, Azure)
  • Familiarity with CI/CD and developer supply chain threat hunting (GitHub Actions, code pipeline integrity, dependency confusion, etc.)
  • Contributions to open-source threat hunting or detection engineering projects, or public threat research publications.

What the JD emphasized

  • proactively defending
  • structured, hypothesis-driven hunts
  • adversary emulation exercises
  • AI-assisted analysis
  • real-world adversary emulation
  • structured and hypothesis-driven threat hunts
  • forward-thinking threat hunting
  • adversary emulation exercises or purple team engagements
  • AI-assisted tooling or large language models

Other signals

  • AI-assisted analysis
  • AI and machine learning capabilities
  • AI-assisted tooling or large language models