Back to jobs
New

Threat Hunter/Purple Team Operator

Remote

Threat Hunter / Purple Team Operator

SIXGEN's mission is to deliver agile, mission-ready cybersecurity solutions that empower government and critical infrastructure organizations to stay ahead of advanced cyber threats. We combine innovation, deep expertise, and leading technical capabilities to uncover vulnerabilities, protect vital systems, and strengthen operational resilience.

POSITION OVERVIEW

  • Position: Mid-Level Threat Hunter / Purple Team Operator
  • Job Type: Full Time
  • Location: Remote with travel to customers and test locations as required
  • Clearance Requirement: Active Top Secret with SCI eligibility

WHAT YOU'LL DO

SIXGEN is seeking a mid-level Threat Hunter / Purple Team Operator to  identify threats that evade existing detection methods, develop and test hunting hypotheses, and feed findings back into detection engineering. This role will combine remote threat hunting and on-site purple team coordination in direct support of red team engagements to secure systems, strengthen the defenders, and build and validate detection methods that can catch offensive traffic in real time.

This role requires comfort working independently through remote hunts as well as the ability to translate adversary tradecraft into defensive guidance.

Responsibilities include:

  • Conduct hypothesis-driven and intelligence-led threat hunts across endpoints, networks, and cloud telemetry for several weeks prior to each red team engagement.
  • Analyze logs, alerts, and historical data for indicators of compromise (IOCs), anomalous behavior, and adversary TTPs mapped to the MITRE ATT&CK from partner-provided sources (EDR, SIEM, authentication/identify logs).
  • Document hunt coverage and methodology, findings, detection recommendations, and any confirmed or suspected compromise, escalating immediately if active adversary activity is found.
  • Deliver a threat hunt summary and determine if the customer environment is clear prior to red team assessments.
  • Partner with blue teams during the purple portion of the engagement to assist in detecting, tuning, and validating controls against red team TTPs in real-time.
  • Brief technical and non-technical stakeholders on hunt result and purple team detection outcomes.
  • Serve as a Trusted Agent during the red team assessment and maintain strict confidentiality and operational security with insight into both red and blue team activity.

Technology proficiency includes:

  • SIEM platforms (e.g., Splunk, Microsoft Sentinel, Elastic).
  • EDR/XDR tooling (e.g. CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne, Carbon Black).
  • Network detection and traffic analysis tools (e.g. Zeek, Suricata, full packet capture).
  • Log aggregation and correlation across endpoint, network, cloud, and identity sources (e.g., Azure AD/Entra ID, AWS CloudTrail, Microsoft 365).
  • MITRE ATT&CK framework for mapping hunts and detections to adversary TTPs.
  • Query and scripting languages for hunting and automation (e.g. KQL, SPL, Python).
  • Familiarity with common red team tooling and tradecraft (e.g., Cobalt Strike, Havoc, and other C2 traffic patterns) to help recognize and detect it.

WHAT YOU BRING

Required qualifications:

  • 3 – 5+ years of experience in threat hunting, SOC/detection engineering, incident response, or a closely related defensive security role.
  • Hand-on experience working with a major SIEM and EDR platform.
  • Working knowledge of the MITRE ATT&CK framework and how to map observed activity to adversary TTPs.
  • Understanding of common adversary tradecraft and red team testing methodology to help close detection gaps.
  • Strong written and verbal communication skills with the ability to produce clear, customer-facing findings and an “all clear” determination.
  • Comfortable operating independently in remote, customer-facing roles.
  • U.S. citizenship, with eligibility to obtain and maintain a U.S. government security clearance.

Preferred qualifications:

  • Industry certifications such as GCFA, GCIH, GNFA, GCTI, CySA+, or equivalent.
  • Prior experience performing threat hunting and/or purple team role working directly alongside a red team.
  • Scripting and automation experience to streamline hunting workflows (e.g., Python, PowerShell).
  • Prior experience working with multiple partner organizations or client environments.
  • Active TS/SCI clearance.

COMPENSATION AND BENEFITS

SIXGEN offers competitive compensation based on the responsibilities of the role and the candidate's experience, qualifications, specialized expertise, and security-clearance status. The final compensation package will be discussed during the hiring process.

SIXGEN offers benefits for full-time employees, including:

  • Employer-paid health insurance premiums, including medical, dental, and vision coverage, for employees and their families
  • Employer-paid short- and long-term disability insurance and basic life and AD&D insurance
  • 401(k) plan with a 4% employer contribution
  • Professional-development reimbursement options for training, certifications, and education
  • Flexible and remote-work policies for most positions
  • Flexible paid time off and holiday schedule

For more information, please contact Human Strategist Amy Maxwell at amy.maxwell@sixgen.io.

OUR COMMITMENT

SIXGEN is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, age, marital status, ancestry, protected veteran status, or any other characteristic protected by applicable law.

We are committed to fostering an inclusive culture that values diversity in our people and reflects the communities and customers we serve. We strive to attract and retain a diverse talent pool and to create an environment where everyone is empowered to do their best work.

 

Create a Job Alert

Interested in building your career at SixGen, Inc.? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...

U.S. Standard Demographic Questions

We are committed to building an inclusive culture of belonging that embraces the diversity of our people and represents the communities in which we work and the customers we serve. We know the happiest and highest performing teams include people with diverse perspectives and ways of solving problems. We strive to attract and retain talent from all backgrounds and create workplaces where everyone feels empowered to bring their full, authentic selves to work.   

We invite applicants to share their demographic background. If you choose to complete this survey, your responses may be used to identify areas of improvement in our hiring process.

Select...
Select...
Select...
Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in SixGen, Inc.’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...