Cyber Threat Hunter

ASM
Albany, NY, United States
12 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Compensation
$94,100.0 - $150,000.0
Working hours
Regular working hours
Job source

Tech stack

CompTIA Security+ Cyber Security Data Flow Control Intrusion Detection and Prevention Python (Programming Language) Log Analysis Packet Analyzer Windows PowerShell Comptia Pentest+ CE Reverse Engineering Data Streaming Malware
+5 more
Cyber Threat Analysis Information Technology Cybercrime Cyber Warfare Vulnerability Analysis

Job description

The Cyber Threat Hunter proactively protects enterprise environments from advanced cyber threats by analyzing network, endpoint, and log data to identify malicious activity that may evade conventional security controls. This role establishes normal traffic and data-flow baselines, detects anomalies, develops threat hypotheses, and investigates adversary tactics, techniques, and procedures to strengthen cyber defense and incident response operations. This role directly supports a proactive SOC model by contributing to detection engineering, monitoring enhancements, automation development and continuous gap analysis to identify and mitigate emerging threats before they materialize., + Conduct proactive threat hunting across networks, endpoints, and security datasets to identify, isolate, and help eradicate advanced threats before they impact operations.

  • Analyze logs from multiple sources, including packet captures, correlation engines, parsed security data, and endpoint telemetry, to detect suspicious behavior and validate threat activity.

  • Establish and maintain baseline patterns for normal traffic, system activity, and data flows to improve anomaly detection and investigative accuracy.

  • Collaborate closely with SOC analysts and detection engineers to recommend new alerts, analytics, and monitoring logic based on threat hunting findings, emerging trends, and identified visibility gaps.

  • Develop automation scripts and workflows (using SOAR platforms, Python, PowerShell, or similar tools) to streamline threat hunting activities, automate repetitive analytical tasks, and reduce detection and response time.

  • Research and track adversary tactics, techniques, and procedures (TTPs), developing technical hypotheses and investigative leads based on threat intelligence and observed behaviors.

  • Support incident response activities by creating incident documentation, follow-up actions, reporting criteria, and recommendations that improve overall response maturity and operational resilience.

  • Examine and characterize malware and cyber threats, including viruses, worms, bots, rootkits, and Trojan horses, to determine threat nature, scope, and potential impact., Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM’s overall compensation and benefits package for employees.

Requirements

  • Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or a related field, or equivalent relevant experience.

  • 4 years of experience in cybersecurity or a closely related technical security role.

  • Demonstrated ability to perform system administrator-level analysis across multiple platforms and operating systems in support of cyber investigations.

  • Strong analytical and problem-solving skills with the ability to identify, track, and assess adversary TTPs and suspicious activity.

  • Knowledge of intrusion detection methodologies, evidence preservation practices, and cyber defense and information security policies, procedures, and regulations.

  • Ability to support work in a U.S.-only staffing environment and satisfy any client-required background investigation or security requirements.

Preferred Qualifications

  • Relevant cybersecurity certifications such as GCDA, GNFA, CompTIA PenTest+ (Removed CISSP), CISM, or CompTIA CySA+.

  • Experience with reverse engineering, malware analysis, vulnerability research, and threat analysis in enterprise or government environments.

  • Familiarity with U.S. Army Corps of Engineers (USACE) IT policies and operational security requirements.

  • Experience preparing technical reports, incident summaries, and threat findings for stakeholders and operational leadership.

Job Specific Skills

  • Threat hunting and anomaly detection.

  • Log correlation and security event analysis.

  • Packet capture analysis and data parsing., The physical requirements described in ā€œKnowledge, Skills and Abilitiesā€ above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, ā€œlight office duties’ or ā€œlifting up to 50 poundsā€ or ā€œsome travelā€ required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions.

About the company

ASM Research, An Accenture Federal Services Company (Albany, NY)

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.juju.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

5:11 min

Deploying manual Seccomp profiles to block malware

Dimitrij Klesev +1 Ā· LIVE

11:18 min

Addressing audience questions on security and microservice architectures

Reinhard Kugler Ā· LIVE

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa Ā· LIVE

1:27 min

Differences between autonomous AI agents and traditional malware

Michele Zuccala Michele Zuccala +4 Ā· WWC Europe 2026

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady Ā· WWC Europe 2026

Videos

See all

Related articles

See all