> Markdown version of [/jobs/ext/2787968-senior-cybersecurity-threat-hunter-iii](https://www.wearedevelopers.com/jobs/ext/2787968-senior-cybersecurity-threat-hunter-iii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cybersecurity Threat Hunter III - **Company:** Invictus Inc. - **Location:** Colorado Springs, CO, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Software Documentation, Identity and Access Management, Security Information and Event Management, Mitre Att&ck, Cyber Threat Analysis, Cybercrime - **Published:** September 8, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/18225445?backUrl=%2Fcareer%2F18225445%2FSenior-Cybersecurity-Threat-Hunter-Iii-Colorado-Colorado-Springs ## About the Role Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph, * Bachelor's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree * Minimum six (6) years of relevant experience in addition to education level * Significant hands-on experience conducting threat hunting, advanced cyber analysis, or adversary-focused investigations * Strong knowledge of MITRE ATT&CK, adversary TTPs, threat intelligence application, and network/host/identity security telemetry * Experience developing hunt hypotheses and converting analytical findings into detection or defensive improvements * Experience mentoring analysts or leading complex analytical efforts * Must possess current DoD 8570 IAT II or IAM II certification * Experience working in a DoD or IC environment * Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph ## Description * Lead complex, hypothesis-driven threat hunts across multiple enterprise data sources and enclaves to identify sophisticated or previously undetected adversary activity * Proactively analyze security telemetry to identify indicators of compromise, anomalous behavior, and adversary activity that has not met an incident threshold or has evaded automated security controls * Assess and correlate data from multiple sources, including network, endpoint, identity, SIEM, threat intelligence, vulnerability, and other available security data * Document hunt activity, findings, evidence, and recommended follow-on actions in authorized systems and initiate or support incident-response processes when malicious activity is identified * Provide relevant findings and trends for SOC operational reporting, significant-activity reporting, and defensive awareness * Develop and prioritize hunt campaigns based on threat intelligence, mission risk, adversary TTPs, detection coverage, incident lessons learned, and environmental changes * Perform advanced behavioral analysis and identify patterns indicative of persistence, credential abuse, lateral movement, command and control, collection, or other adversary activity * Serve as an escalation point for junior threat analysts and provide technical guidance on hunt methodology, analytical pivots, and evidence validation * Translate successful hunt findings into actionable requirements for detection engineering, watch operations, security engineering, and incident response * Develop reusable hunt playbooks, queries, analytic methods, documentation standards, and training materials * Mentor junior personnel and support exercises, knowledge sharing, and assessment of threat-analysis proficiency ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Forecasting Cyber Attacks with Glassdoor Reviews - Lianne Potter](https://www.wearedevelopers.com/videos/2143-forecasting-cyber-attacks-with-glassdoor-reviews-lianne-potter) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf) - [Top 6 Hackathons for Developers in 2023](https://www.wearedevelopers.com/magazine/263-top-6-hackathons-for-developers-in-2023)