I'm a threat hunter and cybersecurity data scientist and have always felt a dissociation with the vast majority of others in the same field and my coworkers since I started leaning more into the DS/ML side of things, even though I use those capabilities to perform advanced proactive and predictive hunt and analysis.
From what I've seen, there has been a strong desire to bring folks with similar skills into the broader cybersecurity landscape, so I know the appetite for hiring is there but I haven't seen many jobs that specifically ask for this. On top of that, I'm not sure that there is a widely-accepted term to describe that kind of position that blends typical hunt operations, threat intel, hunting, detection engineering, automation, analysis, and DS/ML.
Splunk put out a packet about a year ago about threat hunting with PEAK and it outlines hypothesis-driven, baseline, and model-assisted threat hunting pathways and it perfectly describes what I do and what I'm most passionate about. There just doesn't seem to be jobs that are open to accommodating the role expansion, even if there's justification and interest in cultivating, acquiring, and retaining someone with those skills.
I'd love to hear from anyone that is currently in that kind of role and would be interested in hearing a little more (industry, typical responsibilities, opinions on integration into established security operations, etc).