19 часов назад
Threat Hunt Lead (CBP) (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Threat Hunt Lead (CBP) (Cybersecurity): Leading structured threat hunts for federal law enforcement systems with an accent on hypothesis-driven investigation, detection engineering, and evidence preservation. Focus on testing MITRE ATT&CK-based hypotheses, converting findings into production detections, and handing actionable evidence to incident response and digital forensics.
Location: Ashburn, Virginia, United States; hybrid workplace
Active CBP BI and EOD or another qualifying clearance can shorten the start date. Candidates without an existing clearance may begin CBP BI processing, which can take months.
A $10,000 signing bonus is available after 90 days under standard terms for candidates who already hold an active CBP BI and EOD.
Company
provides cybersecurity and technology services supporting federal government missions.
What you will do
- Lead structured, hypothesis-driven threat hunts for a program supporting continuous U.S. Customs and Border Protection operations.
- Investigate activity that automated SOC detections may miss and confirm or rule out hypotheses using available environmental data.
- Convert confirmed hunt findings into production detection logic and tune detections as conditions change.
- Preserve evidence and context for actionable handoff to incident response and digital forensics leads.
- Translate threat intelligence and federal law enforcement threats into targeted hunting priorities.
Requirements
- Experience leading or performing structured threat hunting using a framework such as MITRE ATT&CK.
- Experience turning a threat-hunting finding into a production detection.
- Experience defending government or law enforcement data and environments.
- Ability to work with incomplete or ambiguous signals and assess which hypotheses are worth pursuing.
- Active CBP BI, a fitness determination at another DHS component, or an active DoD clearance is preferred.
Nice to have
- GCFA, GNFA, or an equivalent certification.
Culture & Benefits
- Health and life insurance options.
- Paid time off and holiday pay.
- Short-term and long-term disability coverage.
- Retirement benefits and learning and development opportunities.
- Values centered on helpfulness, honesty, humility, continuous improvement, and mission-driven execution.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
CrowdStrike
7 дней назад
Threat Hunter, FedCloud (Remote)
85 000 - 120 000$
1 день назад
Security Operations Lead (AI)
180 000 - 210 000$
22 часа назад
Cyber Security Analyst Leads (Cyber Threat Hunting)
6 дней назад
Security Operations Lead (Cybersecurity)
1 день назад
Manager, Incident Response (Cybersecurity)
132 410 - 165 510$
5 дней назад
Threat Detection Analyst (Expert)
70 000 - 140 000$