Cybersecurity Threat Hunter II
Invictus Inc.
Alexandria, VA, United States
4 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.clearancejobs.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Working hours
Regular working hours
Job source
Tech stack
Identity and Access Management
Network Security
Security Information and Event Management
Mitre Att&ck
Cyber Threat Analysis
Cybercrime
Cyber Warfare
Job description
- Independently conduct hypothesis-driven threat hunts across available enterprise telemetry to identify malicious or anomalous activity not detected by automated controls
- Proactively analyze security telemetry to identify indicators of compromise, anomalous behavior, and adversary activity that has not met an incident threshold or has evaded automated security controls
- Assess and correlate data from multiple sources, including network, endpoint, identity, SIEM, threat intelligence, vulnerability, and other available security data
- Document hunt activity, findings, evidence, and recommended follow-on actions in authorized systems and initiate or support incident-response processes when malicious activity is identified
- Provide relevant findings and trends for SOC operational reporting, significant-activity reporting, and defensive awareness
- Develop hunt hypotheses based on threat intelligence, adversary TTPs, environmental observations, emerging threats, and known detection gaps
- Use MITRE ATT&CK and other threat-informed methodologies to characterize observed behavior and guide analytical pivots
- Identify patterns, relationships, and potential adversary activity across users, hosts, network segments, and time periods
- Recommend new or improved detections, data collection, enrichment, and defensive controls based on hunt outcomes
Requirements
Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph, * Bachelor’s degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree
- Minimum four (4) years of relevant experience in addition to education level
- Hands-on experience with threat hunting, security analysis, incident investigation, threat intelligence analysis, or comparable proactive cyber defense work
- Working knowledge of adversary TTPs, MITRE ATT&CK, network and endpoint telemetry, and analytical search techniques
- Experience using SIEM, network-security monitoring, endpoint telemetry, or other large-scale security data sources
- Must possess current DoD 8570 IAT II or IAM II certification
- Experience working in a DoD or IC environment
- Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.clearancejobs.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
LM
Luis Minvielle
over 2 years ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
almost 2 years ago
DC
Daniel Cranney
The Overflow: Security and Privacy
6 months ago
DC
Daniel Cranney
Understanding and Mitigating Common Web Vulnerabilities
over 1 year ago
DC
Daniel Cranney
Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF
5 months ago
BB
Benedikt Bischof
Walking Into The Era of Supply Chain Risks
about 4 years ago