Skip to content

Open nowPosted 7 hours agoWe saw it 87 min after it went up

Threat Hunter/Purple Team Operator

SixGen, Inc.22 open roles

Where
Remote
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowThreat Hunter/Purple Team OperatorSixGen, Inc. · Remote
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on SixGen, Inc.'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.3% of postings close within 7 days. Measured by our own scanner across the market. SixGen, Inc. postings stay open a median of 33 days.

Share of postings closed within
  1. 1.9%1 day
  2. 3.9%3 days
  3. 8.3%7 days
  4. 15.3%14 days
  5. 34.1%30 days
This job: posted 7 hours ago

SixGen, Inc. median: 33 days open

The posting

Threat Hunter / Purple Team Operator

SIXGEN's mission is to deliver agile, mission-ready cybersecurity solutions that empower government and critical infrastructure organizations to stay ahead of advanced cyber threats. We combine innovation, deep expertise, and leading technical capabilities to uncover vulnerabilities, protect vital systems, and strengthen operational resilience.

POSITION OVERVIEW

  • Position: Mid-Level Threat Hunter / Purple Team Operator
  • Job Type: Full Time
  • Location: Remote with travel to customers and test locations as required
  • Clearance Requirement: Active Top Secret with SCI eligibility

WHAT YOU'LL DO

SIXGEN is seeking a mid-level Threat Hunter / Purple Team Operator to identify threats that evade existing detection methods, develop and test hunting hypotheses, and feed findings back into detection engineering. This role will combine remote threat hunting and on-site purple team coordination in direct support of red team engagements to secure systems, strengthen the defenders, and build and validate detection methods that can catch offensive traffic in real time.

This role requires comfort working independently through remote hunts as well as the ability to translate adversary tradecraft into defensive guidance.

Responsibilities include:

  • Conduct hypothesis-driven and intelligence-led threat hunts across endpoints, networks, and cloud telemetry for several weeks prior to each red team engagement.
  • Analyze logs, alerts, and historical data for indicators of compromise (IOCs), anomalous behavior, and adversary TTPs mapped to the MITRE ATT&CK from partner-provided sources (EDR, SIEM, authentication/identify logs).
  • Document hunt coverage and methodology, findings, detection recommendations, and any confirmed or suspected compromise, escalating immediately if active adversary activity is found.
  • Deliver a threat hunt summary and determine if the customer environment is clear prior to red team assessments.
  • Partner with blue teams during the purple portion of the engagement to assist in detecting, tuning, and validating controls against red team TTPs in real-time.
  • Brief technical and non-technical stakeholders on hunt result and purple team detection outcomes.
  • Serve as a Trusted Agent during the red team assessment and maintain strict confidentiality and operational security with insight into both red and blue team activity.

Technology proficiency includes:

  • SIEM platforms (e.g., Splunk, Microsoft Sentinel, Elastic).
  • EDR/XDR tooling (e.g. CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne, Carbon Black).
  • Network detection and traffic analysis tools (e.g. Zeek, Suricata, full packet capture).
  • Log aggregation and correlation across endpoint, network, cloud, and identity sources (e.g., Azure AD/Entra ID, AWS CloudTrail, Microsoft 365).
  • MITRE ATT&CK framework for mapping hunts and detections to adversary TTPs.
  • Query and scripting languages for hunting and automation (e.g. KQL, SPL, Python).
  • Familiarity with common red team tooling and tradecraft (e.g., Cobalt Strike, Havoc, and other C2 traffic patterns) to help recognize and detect it.

WHAT YOU BRING

Required qualifications:

  • 3 – 5+ years of experience in threat hunting, SOC/detection engineering, incident response, or a closely related defensive security role.
  • Hand-on experience working with a major SIEM and EDR platform.
  • Working knowledge of the MITRE ATT&CK framework and how to map observed activity to adversary TTPs.
  • Understanding of common adversary tradecraft and red team testing methodology to help close detection gaps.
  • Strong written and verbal communication skills with the ability to produce clear, customer-facing findings and an “all clear” determination.
  • Comfortable operating independently in remote, customer-facing roles.
  • U.S. citizenship, with eligibility to obtain and maintain a U.S. government security clearance.

Preferred qualifications:

  • Industry certifications such as GCFA, GCIH, GNFA, GCTI, CySA+, or equivalent.
  • Prior experience performing threat hunting and/or purple team role working directly alongside a red team.
  • Scripting and automation experience to streamline hunting workflows (e.g., Python, PowerShell).
  • Prior experience working with multiple partner organizations or client environments.
  • Active TS/SCI clearance.

COMPENSATION AND BENEFITS

SIXGEN offers competitive compensation based on the responsibilities of the role and the candidate's experience, qualifications, specialized expertise, and security-clearance status. The final compensation package will be discussed during the hiring process.

SIXGEN offers benefits for full-time employees, including:

  • Employer-paid health insurance premiums, including medical, dental, and vision coverage, for employees and their families
  • Employer-paid short- and long-term disability insurance and basic life and AD&D insurance
  • 401(k) plan with a 4% employer contribution
  • Professional-development reimbursement options for training, certifications, and education
  • Flexible and remote-work policies for most positions
  • Flexible paid time off and holiday schedule

For more information, please contact Human Strategist Amy Maxwell at [email protected].

OUR COMMITMENT

SIXGEN is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, age, marital status, ancestry, protected veteran status, or any other characteristic protected by applicable law.

We are committed to fostering an inclusive culture that values diversity in our people and reflects the communities and customers we serve. We strive to attract and retain a diverse talent pool and to create an environment where everyone is empowered to do their best work.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against SixGen, Inc.'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on SixGen, Inc.'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    SixGen, Inc.'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.