> Markdown version of [/jobs/ext/2695598-cyber-threat-hunter](https://www.wearedevelopers.com/jobs/ext/2695598-cyber-threat-hunter). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Threat Hunter - **Company:** CYBER MANAGEMENT INTERNATIONAL CORPORATION - **Location:** Beltsville, MD, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Data Analysis, Cloud Computing Security, Cyber Security, Information Systems, Computer Networks, Computer Forensics, Linux, Networking Hardware, Network Security, Log Files, Reverse Engineering, Scripting, Computer Network Operations, Mitre Att&ck, Cyber Threat Analysis, Cybercrime, Cyber Warfare - **Published:** September 3, 2026 - **Apply:** https://www.wayup.com/i-j-Cyber-Threat-Hunter-Cyber-Management-International-Corp-152083533481713/ ## About the Role + US Citizenship required and an active TOP SECRET clearance. + BS degree and 12 to 15 years', experience or MS degree with 10 to 13 years', experience or a high school diploma/equivalent with minimum 16 years', experience. + Possess CISSP or similar cybersecurity certification. + 8+ years of directly relevant experience in cyber forensic and network investigations using leading edge technologies and industry standard forensic tools. + Experience with reconstructing a malicious attack or activity. + In depth knowledge and experience of identifying different classes and characterization of attacks and attack stages. Qualifications: Preferred Requirements + Knowledge of cybersecurity frameworks and standards + Ability to track incidents using MITRE ATT&CK and Cyber Kill Chain methodology. + Knowledge of cloud security + Knowledge of current IT security best practices + Knowledge of system administration, networking, and operating system hardening techniques + Mixed operating systems experience: (Linux, Windows) + Scripting/coding experience ## Description Cyber Management International Corporation is actively recruiting a highly motivated Cyber Threat Hunter looking for challenging, exciting work in support of the U.S. Department of State (DOS) Consular Affairs Enterprise Infrastructure Operations (CAEIO) Program, for the Bureau of Consular Affairs (CA). The Cyber Threat Hunter will be working closely with other CAEIO team members, application/system owners, and Government Leadership to ensure Consular Affairs mission success. This organization provides services that analyze and produce enhanced cyber security and threat intelligence information to include threats and potential threats to the customer's information and information systems; provides timely and relevant technical analysis to assist with mitigating cyber threats confronting the Department; supports evaluation, implementation, and operations of tools/technologies used in advanced analysis. Functional Duties The Cyber Threat Hunter and Researcher will support the customer's overall cyber threat analysis efforts. Performs advanced analysis of adversary tradecraft, malicious code, and Advance Persistent Threat capabilities. Analyzes computer, communication, network security events and exploits to determine security vulnerabilities and recommend remedial actions. Conducts forensic, malicious code, and packet-level analyses to develop comprehensive technical reports stepping through complete reverse engineering of incidents. Recommends countermeasures based on the identified techniques, tactics, procedures, and behavior patterns used by adversaries. This role is also responsible for developing alert criteria to improve incident response capabilities; as well as contributing to the development, writing, and reviewing of SOPs. Responsibilities + Conducts research and data correlation using a variety of enterprise data sources with specific emphasis on network operations and cyber warfare tactics, techniques, and procedures. + Analyzes network events to determine the impact on current operations and conduct research to determine adversary capability and intent. + Analyzes identified malicious network and system log activity to determine weaknesses exploited, exploitation methods, effects on systems and information. + Collects and analyzes network device integrity data for signs of tampering or compromise. + Prepares assessments and cyber threat profiles of current events based on the sophisticated collection, research, and analysis of information. + Conducts data analysis in support of directed assessments, anomaly investigations, long term trending and system check out. + Develops and maintains analytical procedures to meet changing requirements and customer inquiries. + Serves as the cyber technical liaison to stakeholders, explaining investigation details. + Tracks and documents incident response activities and provides updates to leadership through executive summaries and in-depth technical reports. + Create, discuss and explain Cyber investigative documentation. + Resolve highly complex malware and intrusion issues using computer host analysis, forensics, and reverse engineering. + Characterize and analyze network traffic, identify anomalous activity / potential threats, and analyze anomalies in network traffic using metadata. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [The Software Bug All Stars - and what we can learn from them](https://www.wearedevelopers.com/videos/423-the-software-bug-all-stars-and-what-we-can-learn-from-them) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Supply Chain Security and the Real World: Lessons From Incidents](https://www.wearedevelopers.com/videos/1656-supply-chain-security-and-the-real-world-lessons-from-incidents) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents)