5 часов назад
Senior Threat Hunter Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Threat Hunter Analyst (Cybersecurity): Proactively hunting undetected adversary activity across complex federal enterprise networks with an accent on malware analysis, CND triage, incident response support, and threat intelligence. Focus on developing SIEM queries and detection logic, reconstructing attacker TTPs, producing IOC and after-action reports, and improving continuous monitoring capabilities.
Location: Fort Collins, Colorado; Kansas City, Missouri; or Washington, DC, United States
Company
builds and delivers federal technology with a product mindset focused on speed, ownership, and execution.
What you will do
- Proactively hunt for undetected adversary activity across complex enterprise networks using network flow, PCAP, logs, endpoint telemetry, and SIEM data.
- Conduct Computer Network Defense triage, assess alerts and anomalies, and prioritize findings for investigation or response.
- Support active incident response through host and network analysis, malware triage, and attacker TTP reconstruction.
- Perform malware analysis, extract IOCs, and maintain threat indicator feeds with the Cyber Threat Intelligence team.
- Author IOC reports, finished intelligence products, after-action reviews, lessons-learned documentation, and security metrics for technical and program audiences.
- Develop reusable hunt tactics, SIEM queries, and detection logic while tracking emerging adversary TTPs and malware families.
Requirements
- Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent experience.
- At least five years of experience in threat hunting, security operations, or a closely related technical discipline.
- Active Top Secret clearance required.
- Hands-on experience with IDS/IPS, SIEM platforms, malware analysis, CND triage, and incident response support.
- Experience producing IOC reports, OSINT-based intelligence products, after-action reports, and lessons-learned documentation.
- Familiarity with the MITRE ATT&CK framework and current federal cybersecurity threats.
Nice to have
- GCIH, GCIA, GCTI, GREM, CySA+, or an equivalent certification.
- Experience in a federal civilian, defense, or intelligence SOC environment.
- Python scripting for hunt automation and IOC enrichment.
- Experience with threat intelligence platforms, advanced malware reverse engineering, exploit analysis, or cloud-native hunting.
Culture & Benefits
- Flexible schedules and teleworking options.
- Medical insurance, including HSA-eligible plans, plus employer-paid dental and vision options.
- Employer-sponsored short-term disability, long-term disability, and life insurance.
- 5% 401(k) company matching, paid holidays, PTO accrual, and paid parental leave.
- Professional development, career growth opportunities, and team and company-wide recognition events.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →