Proactively analyze security telemetry to identify indicators of compromise, anomalous behavior, and adversary activity that has not met an incident threshold or has evaded automated security controls. Document hunt activity, findings, evidence, and recommended follow-on actions in authorized systems and initiate or support incident-response processes when malicious activity is identified.
Numbers & Facts
Location
Alexandria, VA
Description
Title: Senior Cybersecurity Threat Hunter III
Location: Alexandria, VA
Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph
Job Details:
Lead complex, hypothesis-driven threat hunts across multiple enterprise data sources and enclaves to identify sophisticated or previously undetected adversary activity
Proactively analyze security telemetry to identify indicators of compromise, anomalous behavior, and adversary activity that has not met an incident threshold or has evaded automated security controls
Assess and correlate data from multiple sources, including network, endpoint, identity, SIEM, threat intelligence, vulnerability, and other available security data
Document hunt activity, findings, evidence, and recommended follow-on actions in authorized systems and initiate or support incident-response processes when malicious activity is identified
Provide relevant findings and trends for SOC operational reporting, significant-activity reporting, and defensive awareness
Develop and prioritize hunt campaigns based on threat intelligence, mission risk, adversary TTPs, detection coverage, incident lessons learned, and environmental changes
Perform advanced behavioral analysis and identify patterns indicative of persistence, credential abuse, lateral movement, command and control, collection, or other adversary activity
Serve as an escalation point for junior threat analysts and provide technical guidance on hunt methodology, analytical pivots, and evidence validation
Translate successful hunt findings into actionable requirements for detection engineering, watch operations, security engineering, and incident response
Develop reusable hunt playbooks, queries, analytic methods, documentation standards, and training materials
Mentor junior personnel and support exercises, knowledge sharing, and assessment of threat-analysis proficiency
Requirements:
Bachelor's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree
Minimum six (6) years of relevant experience in addition to education level