Senior Threat Hunter Analyst
Indexed description
We are redefining how federal technology gets built and delivered by operating with a product mindset, prioritizing speed, ownership, and execution over bureaucracy.
Senior Threat Hunter Analyst
Location: Washington, DC, Ft. Collins, CO, or Kansas City, MO (remote optional, local preferred)
Terms: Full-time
Salary: $125-$150k DOE
Clearance: Active Top Secret required
Travel: 0-10%
Project Description
This position supports a large-scale federal security operations program delivering 24/7/365 continuous monitoring, intrusion detection, threat hunting, incident response, and threat intelligence across a complex enterprise network environment. The threat hunting function operates at the leading edge of the program’s defensive posture — finding what automated tools miss before it becomes a confirmed incident.
The core challenge: proactively hunting adversary activity across a large, high-complexity enterprise network, supporting active incident response, and producing intelligence products that sharpen the program’s detection and response capabilities over time.
Position Description
As a Senior Threat Hunter Analyst at Revolutional, you operate ahead of the threat — proactively hunting for undetected adversary activity across enterprise networks before it surfaces through automated detection. You are a technically deep practitioner who combines hunting tradecraft with malware analysis capability, incident response support, and the discipline to produce IOC reports, after-action reviews, and security metric reporting that make the program measurably better over time.
You work in close coordination with the Cyber Threat Intelligence team, maintaining threat indicator feeds that keep your hunts current and your findings actionable. You conduct CND triage, support active incidents with analysis, and author finished intelligence products from open-source portals. Your output reaches both technical peers and program management.
What You Will Own
- Proactive threat hunting across enterprise network environments for undetected adversary activity
- Malware analysis in support of hunt findings and incident response
- CND triage and analysis support for active incident response operations
- Threat indicator feed maintenance in coordination with the Cyber Threat Intelligence team
- IOC report authorship from open-source intelligence portals
- After-action and lessons-learned documentation for significant hunts and incidents
- Security event and metric reporting for program management
- Proactively hunt for undetected cyber threats across enterprise network environments using network flow, PCAP, log data, endpoint telemetry, and SIEM data; operate ahead of automated detection capabilities
- Conduct Computer Network Defense (CND) triage: assess alerts and anomalies, determine threat validity, and prioritize findings for response or further investigation
- Provide analysis support to incident response operations; contribute host and network analysis, malware triage, and attacker TTP reconstruction during active incidents
- Perform malware analysis on samples collected during hunts and incidents; identify behavioral indicators, persistence mechanisms, and IOCs for operationalization
- Maintain and update threat indicator feeds in coordination with the Cyber Threat Intelligence team; ensure hunt operations are informed by current intelligence
- Author IOC reports from open-source intelligence portals; package findings into finished products suitable for both technical teams and program leadership
- Prepare after-action reports and lessons-learned documentation following significant hunts and incidents; identify detection gaps and recommend improvements
- Produce security event and metric reports for program management; communicate hunt findings, detection trends, and program health in clear, data-supported terms
- Develop and maintain reusable hunt tactics, SIEM queries, and detection logic that improve the program’s long-term detection capability
- Stay current on adversary TTPs, malware families, threat actor trends, and emerging attack techniques relevant to the federal enterprise environment
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience)
- 5 or more years of experience in threat hunting, security operations, or a closely related technical discipline
- Active Top Secret clearance required
- Demonstrated experience proactively hunting for adversary activity across enterprise networks using hypothesis-driven and intelligence-driven hunt methodologies
- Hands-on IDS/IPS experience: signature review, alert triage, anomaly identification, and tuning to reduce noise and improve detection fidelity
- Proficiency with SIEM platforms: search language, query development, correlation rule creation, dashboard operations, and metric reporting
- Malware analysis experience including behavioral analysis, static review, IOC extraction, and identification of adversary tooling and techniques
- Experience conducting CND triage and supporting incident response with technical analysis under operational tempo
- Experience authoring IOC reports and finished intelligence products from open-source intelligence (OSINT) portals
- Experience preparing after-action reports and lessons-learned documentation that drive concrete defensive improvements
- Familiarity with MITRE ATT&CK framework applied to hunt hypothesis development and TTP mapping
- Current knowledge of adversary TTPs, threat actor trends, and the evolving federal cybersecurity threat landscape
- Proactive and analytically driven — you hunt because you assume the adversary is already in, and you don’t stop until the evidence tells you otherwise
- Technically fluent across hunting, malware analysis, and incident response — you shift between disciplines fluidly as the mission demands
- Strong written communicator: your IOC reports, after-actions, and metric reports are clear, accurate, and written for the audience
- Collaborative partner to threat intelligence and incident response teams — your findings feed the broader program, not just your own queue
One Or More Of The Following Is Strongly Preferred
- GCIH (GIAC Certified Incident Handler), GCIA (GIAC Certified Intrusion Analyst), GCTI (GIAC Cyber Threat Intelligence), GREM (GIAC Reverse Engineering Malware), CySA+, or equivalent
- Experience threat hunting in a federal civilian, defense, or intelligence SOC environment
- Proficiency scripting in Python or equivalent for hunt automation and IOC enrichment workflows
- Experience with threat intelligence platforms (TIPs) and integrating CTI data into active hunt operations
- Background in advanced malware reverse engineering or exploit analysis
- Familiarity with cloud-native hunting across commercial or GovCloud environments
___________________________________________________________________________________________________________
Here At Revolutional We Are Pleased To Have Been Repeatedly Recognized For Our Outstanding Work Culture, The Innovative Work We Do, And The Employees On Our Team Who Make a Difference Each Day. Some Of These Recognitions Include
- Recognized as a Top 20 "Best Place to Work in Virginia"
- Recipient of Department of Labor's HireVets Gold Medallion
- Great Place to Work Certification for five years running
- A Virginia Chamber of Commerce Fantastic 50 company
- A Northern Virginia Technology Council Tech 100 company
- Inc. 5000 list of fastest growing companies for eleven years
- Two-time SBA SBIR Tibbett's Award winner
- Virginia Values Veterans (V3) Certification
- Traditional and HSA- eligible medical insurance plans
- 100% employer-paid dental and vision insurance options
- 100% employer-sponsored STD, LTD, and life insurance
- 5% 401(k) company matching
- Flexible-schedules and teleworking options
- Paid holidays and PTO Accrual Plans
- Paid Parental Leave
- Professional development and career growth opportunities
- Team and company-wide events, recognition, and appreciation-- and so much more!
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search