Cybersecurity Threat Hunters are elite security analysts who proactively search for malicious activity that has evaded automated detection systems like firewalls and antivirus software. Rather than waiting for alerts, they form hypotheses about how attackers might infiltrate a network, then dig through logs, endpoint data, and network traffic to uncover subtle indicators of compromise. This role requires deep knowledge of attacker tactics, techniques, and procedures (TTPs), often informed by frameworks like MITRE ATT&CK.
| Entry level | $78,000 |
| Median | $118,000 |
| Senior | $155,000 |
| Top 10% | $190,000 |
| Job growth | +32% |
| Professionals in the USA | 0.1 million |
| Typical hours/week | 45 hrs |
| Remote work share | 60% |
| Annual job openings | 16,000/yr |
| Demand | Very High |
AI is transforming threat hunting by automating data correlation, anomaly detection, and initial triage, allowing hunters to focus on complex investigations. However, sophisticated attackers also use AI, creating an escalating arms race that requires human strategic oversight and creativity. The role is shifting from manual log analysis toward AI-augmented hypothesis-driven hunting.
Automation exposure: Routine log aggregation, pattern matching, basic alert triage, and known signature detection are increasingly automated by AI/ML tools and SOAR platforms.
The human edge: Creative hypothesis generation, understanding attacker psychology and novel TTPs, contextual business risk judgment, and adapting to unprecedented zero-day attack patterns that lack historical training data.
Figures are estimates for exploration — verify current data with BLS.gov.