Cyber Threat Hunter
Indexed description
Work you'll do
As a Threat Hunter, for the Cyber Defense & Resilience offering, you will be responsible for...
- Conducting proactive threat hunts across endpoint, network, cloud, and log data to identify malicious activity, anomalous behavior, and indicators of compromise
- Analyzing security telemetry, alerts, and artifacts to investigate threats and support detection, containment, and remediation activities
- Developing hunt hypotheses based on threat intelligence, adversary tactics, techniques, and procedures, and documented attack patterns
- Partnering security operations, incident response, and engineering teams to improve detections, close visibility gaps, and strengthen defensive capabilities
- Documenting hunt methodologies, findings, and recommendations, and communicating results to technical stakeholders and team leadership
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
Qualifications
Required:
- Bachelor's degree in computer science, Cybersecurity, Information Technology, Engineering, or a degree in related technical field
- 3+ years of experience in threat hunting, security operations, detection engineering, or incident response
- 3+ years of experience with security information and event management platforms, endpoint detection and response platforms, and network analysis tools
- 2+ years of experience doing the following:
- Analyzing endpoint, network, cloud, and log telemetry to identify suspicious or malicious activity
- Mapping adversary behavior to MITRE ATT&CK and documenting hunt findings and recommendations
- Ability to travel 20%, on average, based on the work you do and the clients and industries/sectors you serve.
- Active Secret clearance or higher
- One or more certifications such as Certified Information Systems Security Professional, GIAC Certified Incident Handler, or GIAC Certified Forensic Analyst
- Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.
- 1+ years of experience supporting government or public sector cybersecurity environments
- 2+ years of experience creating or tuning detection logic, analytic rules, or hunt queries
- 2+ years of experience with the following:
- Digital forensics or malware analysis
- Cloud security monitoring in Amazon Web Services or Microsoft Azure environments
- Using Python, PowerShell, or Structured Query Language for analysis or automation
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search