> Markdown version of [/jobs/ext/2198051-threat-hunter-analyst](https://www.wearedevelopers.com/jobs/ext/2198051-threat-hunter-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Threat Hunter Analyst - **Company:** Revolutional, LLC - **Location:** Fort Collins, CO, United States (Remote available) - **Experience:** Expert - **Salary:** $125,000.0 - $150,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Network Analysis, Cloud Computing, Cyber Security, Computer Telephony Integration, Data Security, Internet Security, Intrusion Detection and Prevention, Intrusion Detection Systems, Python (Programming Language), Network Security, Pcap, Open Source Technology, Open Source Intelligence, Reverse Engineering, Security Information and Event Management, Inversion of Control, Mitre Att&ck, Malware, Cyber Threat Analysis, Information Technology, Cybercrime - **Published:** August 23, 2026 - **Apply:** https://www.careerbuilder.com/job-details/senior-threat-hunter-analyst-fort-collins-co--56f6d408-bca5-40aa-898e-bc5314f9e0ee ## About the Role * Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience) * 5 or more years of experience in threat hunting, security operations, or a closely related technical discipline * Active Top Secret clearance required Technical & Domain Capabilities * Demonstrated experience proactively hunting for adversary activity across enterprise networks using hypothesis-driven and intelligence-driven hunt methodologies * Hands-on IDS/IPS experience: signature review, alert triage, anomaly identification, and tuning to reduce noise and improve detection fidelity * Proficiency with SIEM platforms: search language, query development, correlation rule creation, dashboard operations, and metric reporting * Malware analysis experience including behavioral analysis, static review, IOC extraction, and identification of adversary tooling and techniques * Experience conducting CND triage and supporting incident response with technical analysis under operational tempo * Experience authoring IOC reports and finished intelligence products from open-source intelligence (OSINT) portals * Experience preparing after-action reports and lessons-learned documentation that drive concrete defensive improvements * Familiarity with MITRE ATT&CK framework applied to hunt hypothesis development and TTP mapping * Current knowledge of adversary TTPs, threat actor trends, and the evolving federal cybersecurity threat landscape Core Strengths * Proactive and analytically driven - you hunt because you assume the adversary is already in, and you don't stop until the evidence tells you otherwise * Technically fluent across hunting, malware analysis, and incident response - you shift between disciplines fluidly as the mission demands * Strong written communicator: your IOC reports, after-actions, and metric reports are clear, accurate, and written for the audience * Collaborative partner to threat intelligence and incident response teams - your findings feed the broader program, not just your own queue Certifications One or more of the following is strongly preferred: * GCIH (GIAC Certified Incident Handler), GCIA (GIAC Certified Intrusion Analyst), GCTI (GIAC Cyber Threat Intelligence), GREM (GIAC Reverse Engineering Malware), CySA+, or equivalent Nice to Have (Differentiators) * Experience threat hunting in a federal civilian, defense, or intelligence SOC environment * Proficiency scripting in Python or equivalent for hunt automation and IOC enrichment workflows * Experience with threat intelligence platforms (TIPs) and integrating CTI data into active hunt operations * Background in advanced malware reverse engineering or exploit analysis * Familiarity with cloud-native hunting across commercial or GovCloud environments #DICE #LinkedIn, Affirmative Action, Analysis Skills, Artificial Intelligence (AI), Cloud Computing, Computer Network Defense (CND), Computer Science, Computer Security, Computer Telephony Integration (CTI), Concrete, Cyber Threat Hunting, Defense Intelligence, Documentation, Establish Priorities, Federal Government, Health Insurance, Hunting, Incident Response, Information/Data Security (InfoSec), Internet Security, Intrusion Detection Systems, Intrusion Prevention Systems, Inversion of Control (IoC), Leadership, Machine Tool, Malware, Malware Analysis, Metrics, Network Performance/Analysis, OSINT (Open Source Intelligence), Open Source, Operational Audit, Operational Measurement, Operations Security (OPSEC), Process Improvement, Project/Program Management, Reporting Dashboards, Reporting Skills, Reverse Engineering, Security Attacks, Security Information and Event Management (SIEM), Small Business, Team Player, Technical Analysis, Technical Delivery, Telemetry, Trend Analysis, Writing Skills ## Description This position supports a large-scale federal security operations program delivering 24/7/365 continuous monitoring, intrusion detection, threat hunting, incident response, and threat intelligence across a complex enterprise network environment. The threat hunting function operates at the leading edge of the program's defensive posture - finding what automated tools miss before it becomes a confirmed incident. The core challenge: proactively hunting adversary activity across a large, high-complexity enterprise network, supporting active incident response, and producing intelligence products that sharpen the program's detection and response capabilities over time., As a Senior Threat Hunter Analyst at Revolutional, you operate ahead of the threat - proactively hunting for undetected adversary activity across enterprise networks before it surfaces through automated detection. You are a technically deep practitioner who combines hunting tradecraft with malware analysis capability, incident response support, and the discipline to produce IOC reports, after-action reviews, and security metric reporting that make the program measurably better over time. You work in close coordination with the Cyber Threat Intelligence team, maintaining threat indicator feeds that keep your hunts current and your findings actionable. You conduct CND triage, support active incidents with analysis, and author finished intelligence products from open-source portals. Your output reaches both technical peers and program management. What You Will Own * Proactive threat hunting across enterprise network environments for undetected adversary activity * Malware analysis in support of hunt findings and incident response * CND triage and analysis support for active incident response operations * Threat indicator feed maintenance in coordination with the Cyber Threat Intelligence team * IOC report authorship from open-source intelligence portals * After-action and lessons-learned documentation for significant hunts and incidents * Security event and metric reporting for program management Responsibilities * Proactively hunt for undetected cyber threats across enterprise network environments using network flow, PCAP, log data, endpoint telemetry, and SIEM data; operate ahead of automated detection capabilities * Conduct Computer Network Defense (CND) triage: assess alerts and anomalies, determine threat validity, and prioritize findings for response or further investigation * Provide analysis support to incident response operations; contribute host and network analysis, malware triage, and attacker TTP reconstruction during active incidents * Perform malware analysis on samples collected during hunts and incidents; identify behavioral indicators, persistence mechanisms, and IOCs for operationalization * Maintain and update threat indicator feeds in coordination with the Cyber Threat Intelligence team; ensure hunt operations are informed by current intelligence * Author IOC reports from open-source intelligence portals; package findings into finished products suitable for both technical teams and program leadership * Prepare after-action reports and lessons-learned documentation following significant hunts and incidents; identify detection gaps and recommend improvements * Produce security event and metric reports for program management; communicate hunt findings, detection trends, and program health in clear, data-supported terms * Develop and maintain reusable hunt tactics, SIEM queries, and detection logic that improve the program's long-term detection capability * Stay current on adversary TTPs, malware families, threat actor trends, and emerging attack techniques relevant to the federal enterprise environment ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)