Skip to content

Open nowPosted 17 hours ago

Senior Phishing Tradecraft Researcher

Huntress36 open roles

Where
United States of America
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Phishing Tradecraft ResearcherHuntress · United States of America
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Huntress's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market. Huntress postings stay open a median of 25 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.8%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.2%30 days
This job: posted 17 hours ago

Huntress median: 25 days open

The posting

What We Do:

Cybercrime is growing, and more businesses are getting hit by threats that used to target only the biggest organizations. That pushes defenders like us to operate at the highest level, and it deepens our need for good people who want to make a meaningful impact.

Founded in 2015 by former NSA cyber operators, Huntress is a remote-first team working to make enterprise-grade cybersecurity accessible to businesses of all sizes. We work closely with security teams and service providers protecting complex environments, often without the time or headcount to handle it all. That’s why we build our technology in-house and back it with a 24/7 human-led Security Operations Center (SOC). As a result, our platform is never disconnected from the experts who manage it, ensuring our customers' protection.

Huntress now secures more than 5M endpoints and 16M identities worldwide. Those numbers keep growing because more businesses rely on us to help carry the load and operate with more confidence. Every day, you can see that commitment in how we stand with our customers and how we show up for each other.

Reports to: Manager, Product Research Location: Remote US

Compensation Range: $170,000.00 to $185,000.00 base plus bonus and equity

What You’ll Do:

Do you like getting into the weeds on all things technical, psychological, and educational, and have a desire to know how things work? Then this is the position for you. We are looking for that Swiss Army Knife that brings broad experience to each challenge presented. The Huntress Product team has the unique honor of waking up every morning knowing we’re going to make hackers regret targeting our partners and customers. As a Senior Product Researcher for our Security Awareness Training product, we’re looking for someone who wants to pour all of their creativity into building and implementing simple solutions that are disproportionately effective at countering these constantly evolving threats. One should have experience managing, deploying, and securing SMB environments utilizing a wide variety of security software, best practices, and automation tools. Familiarity with product management, incident response, social engineering, psychology, education, and managed service provider tools is an additional way to differentiate yourself.

Responsibilities:

  • Operate a proven industry-leading Security Awareness Training phishing program.
  • Be the security expert designing and building phishing scenario emails & landing pages that simulate real cyber attacks for thousands of SAT learners. Every simulation is paired with coaching that shows learners the social engineering tells, how the learner can develop skills to identify social engineering tradecraft, the indicators, like hovering a link before clicking or receiving an unexpected email. Craft a growing library of common indicators and write new ones when a scenario calls for it.
  • Comfortable scripting and coding to build proofs-of-concept and tooling with a keen eye for creating pixel-perfect simulated phishing emails & landing pages using HTML, CSS, JavaScript, & React. Take pride in delivering simulations impossible to distinguish from real tradecraft. The details are the job.
  • Identify emerging social engineering tradecraft from attack patterns, email metadata, and web expertise. Today ClickFix attacks and variants dominate the threat landscape, but relentless hunger to get ahead of attacker tradecraft will mean translating the shifts in attacker tactics that matter into what the program teaches. Evolve deliverables with the tradecraft.
  • Automate by default, evolving + expanding phishing content generation as an AI-powered system using Claude Code.
  • Expand the program into new regions, more languages, more tailored content, and new kinds of learning experiences with the guidance of the Product Manager and Principal Product Researcher.
  • Triage reported phishing emails, internal and external security incidents surfacing threat insights and trend analysis in the Huntress Threat Report, threat advisories, social media engagements, webinars & conference talks, resulting in strategic security awareness outreach campaigns.
  • Align with the Principal Researcher to deliver unified Security Awareness Training and phishing program outcomes.
  • Proven organizational and project management skills, with a keen attention to detail and sense of urgency to deliver an exceptional product under tight deadline pressures.
  • Eagerness to engage, report, and be accountable to executive stakeholders.
  • Passion to translate your expertise in technical & nontechnical ways to deliver impactful security outcomes that protect the 99%.

What You Bring To The Team:

  • Proficiency with HTML, CSS, Javascript & React, Angular, or Vue
  • Proficiency with Claude Code, Codex, or Cursor with impressive projects to prove it
  • Experience in manually building phishing simulation deliverables like emails and landing pages, simulating phishing attacks, then analyzing & reporting simulation results
  • Experience triaging reported phishing emails, security incidents, and identifying trends + patterns
  • Experience in analyzing, tracking, and defending against phishing attacks
  • Experience identifying emerging tradecraft
  • Social engineering experience, coursework, training, certifications
  • Experience innovating training content
  • Experience with eLearning design and development
  • Experience developing marketing content for social media, YouTube, blogs & reports
  • Spanish language skills desired, but not required

What We Offer:

  • 100% remote work environment - since our founding in 2015
  • Generous paid time off policy, including vacation, sick time, and paid holidays
  • 12 weeks of paid parental leave
  • Highly competitive and comprehensive medical, dental, and vision benefits plans
  • 401(k) with a 5% contribution regardless of employee contribution
  • Life and Disability insurance plans
  • Stock options for all full-time employees
  • One-time $500 reimbursement for building/upgrading home office
  • Annual allowance for education and professional development assistance
  • $75 USD/month digital reimbursement
  • Access to the BetterUp platform for coaching, personal, and professional growth

Huntress is committed to creating a culture of inclusivity where every single member of our team is valued, has a voice, and is empowered to come to work every day just as they are.

We do not discriminate based on race, ethnicity, color, ancestry, national origin, religion, sex, sexual orientation, gender identity, disability, veteran status, genetic information, marital status, or any other legally protected status.

We do discriminate against hackers who try to exploit businesses of all sizes.

Accommodations:

If you require reasonable accommodation to complete this application, interview, or pre-employment testing or participate in the employee selection process, please direct your inquiries to [email protected]. Please note that non-accommodation requests to this inbox will not receive a response.

Huntress uses artificial intelligence tools to assist in reviewing and evaluating job applications, including resume screening, skills assessment, and candidate matching and comparisons. These AI tools support our human recruiters in the initial review process, but do not make final hiring decisions without human involvement. By submitting your application, you acknowledge this use of AI in our recruitment process. Please review our Candidate Privacy Notice for more details on our practices and your data privacy rights.

#BI-Remote

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Huntress's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Huntress's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Huntress's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.