The ProblemAs Flock scales its safety network across deployed hardware devices, cloud platforms, and core applications, identifying complex cybersecurity threats requires proactive threat hunting and continuous detection validation. Protecting sensitive infrastructure demands an experienced engineer who can architect targeted adversary pursuit campaigns, optimize threat visibility, and bridge offensive testing with incident response. You will design and execute our adversary pursuit function, mature our threat hunting capabilities, and sharpen our incident detection posture across the entire technology stack.
What You'll Own- Lead end-to-end threat hunting campaigns across cloud environments, IoT hardware systems, and corporate applications to detect advanced persistent threats and visibility gaps.
- Partner with the Offensive Security team to validate custom detection rules and translate findings into high-fidelity detections mapped to the MITRE ATT&CK framework.
- Design and execute technical exercise scenarios and tabletop exercises that test incident response readiness against real-world cyber risks.
- Serve as a technical escalation point for deep-dive root cause analysis on complex incidents and mentor junior engineers to elevate team technical capabilities.
- Integrate security automation platforms and intelligent workflows to streamline threat analysis and accelerate operational response capabilities.
What This Role is Not- This isn't a routine SOC analyst or Tier 1 triage job, you will focus on proactive threat hunting, deep adversary pursuit, and advanced detection engineering.
- This is not a purely offensive red-teaming role, you will collaborate with offensive security to validate detections and improve overall defense and response posture.
- This isn't a hands-off strategic management position, you will execute technical threat hunts, analyze suspicious binaries, and write detection logic directly.
What You Bring- Demonstrated experience in digital forensics, incident response, and threat hunting across cloud platforms, enterprise infrastructure, and operational or IoT environments.
- Hands-on expertise using enterprise security tooling, developing custom scripts, and authoring high-fidelity detection rules in Splunk SPL, YARA, or Sigma.
- Practical capability in security automation integrations, malware analysis, or sandboxing technologies to accelerate threat investigation workflows.
- Strong cross-functional technical communication skills to collaborate with Engineering, Product, and Infrastructure teams on architecture improvements.
- Deep understanding of cyber threat intelligence frameworks, MITRE ATT&CK mapping, and technical threat modeling.
CompensationIn this role, you'll receive a starting salary between $140,000 and $175,000 as well as Flock Stock Options. Base salary is determined by job-related experience, education/training, as well as market indicators. Your recruiter will discuss this in depth with you during our first chat.
Some problems get solved faster in the same room, so we prioritize candidates in Atlanta and Boston. Hub-based roles mean real in-person time with your coworkers. Remote roles exist, and when a posting is open to remote work, it says so.