Senior Threat Hunter (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Threat Hunter (Cybersecurity): Detecting and analyzing advanced persistent threats (APT) within government networks with an accent on data manipulation, query generation, and threat intelligence frameworks. Focus on developing reusable hunt tactics, analyzing complex malware, and integrating data from multiple SIEM and EDR sources.
Location: Remote (Active Secret security clearance required)
Salary: $60,000 - $180,000 USD
Company
IT services provider specializing in delivering cybersecurity, cloud migration, and data analytics solutions to the US Federal Government.
What you will do
- Conduct proactive threat hunting to identify Advanced Persistent Threats (APT) using network flow, PCAP, and logs.
- Generate complex queries and reports to interpret data from multiple security tool sources.
- Develop reusable hunt tactics, techniques, and algorithms to analyze data structures.
- Analyze complex malware and identify common encoding techniques such as XOR, Base64, and Unicode.
- Create and maintain standard operating procedures and technical documentation.
- Brief technical findings to various audiences, including executive-level leadership.
Requirements
- Active Secret security clearance.
- 5+ years of experience in data hunting, manipulation, and presentation.
- Proficiency with MITRE ATT&CK and D3FEND frameworks.
- Experience with SIEM search languages and EDR solutions.
- Ability to write scripts using Python, R, SQL, PIG, or HIVE.
- Bachelor's Degree or 4+ years of additional relevant experience.
Nice to have
- Professional certifications: CISSP, CCSP, SSCP, GCIH, GNFA, or GCIA.
Culture & Benefits
- Competitive compensation package.
- Strong commitment to hiring veterans, transitioning service members, and military spouses.
- Remote work flexibility.
- Opportunity to support mission-critical Federal Government agencies.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →