> Markdown version of [/jobs/ext/457317-cyber-threat-hunt-lead](https://www.wearedevelopers.com/jobs/ext/457317-cyber-threat-hunt-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Threat Hunt Lead - **Company:** Gunnison Consulting Group Inc - **Location:** Washington, DC, United States - **Experience:** Expert - **Salary:** $150,000.0 - $165,000.0 - **Contract:** Permanent contract - **Skills:** Agile Methodology, Big Data, Intrusion Detection and Prevention, Python (Programming Language), Windows PowerShell, Phishing, Security Information and Event Management, Software Vulnerability Management, Data Logging, Scripting, Cloud Platform System, Cyber Threat Analysis, Information Technology - **Published:** June 6, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=18bbb85523929a0b ## About the Role Do you have experience in Tooling?, Do you have a Bachelor's degree?, * Bachelor's degree in Computer Science, Information Technology, or a related discipline * Minimum of 5 years of experience in incident response within a large-scale SOC environment (5,000+ endpoints), including at least 3 years focused on proactive threat hunting or adversary emulation * At least 3 years of hands-on experience developing and testing hypotheses, querying large datasets, and identifying advanced persistent threat (APT) behaviors * Minimum of 2 years of experience using scripting languages such as Python and PowerShell to create tools and automate analysis * Certification required: OSCP or GXPN Clearance Requirement: Ability to obtain and maintain a Public Trust. The salary range for this position depends upon multiple factors including location, the individual's knowledge, skills, competencies, and experience, and contract-specific budget constraints and organizational requirements. ## Description * Oversee and direct proactive threat hunting efforts to detect sophisticated adversaries, insider threats, and anomalous activity that evade traditional detection controls * Design and execute hypothesis-driven hunts using adversary tactics, intelligence reporting, behavioral analytics, and available telemetry * Manage and coordinate hunt operations within Agile sprint cycles, ensuring completion of assigned objectives and deliverables * Develop formal threat hunt plans outlining objectives, assumptions, data sources, methodologies, and investigative procedures * Analyze telemetry from endpoints, networks, cloud environments, identity systems, SIEM platforms, and EDR tools to identify indicators of compromise and attack patterns * Escalate suspected or confirmed threats in accordance with federal customer incident response procedures * Coordinate with incident response and triage teams to support investigations and containment efforts * Identify gaps in detection, logging, or telemetry and work with detection engineering teams to improve visibility * Integrate threat intelligence into hunting operations and collaborate with intelligence teams to monitor emerging threats * Conduct advanced analysis of threat actors, malware campaigns, phishing activity, and suspicious infrastructure * Produce detailed hunt reports documenting methodologies, findings, indicators, and recommended improvements * Deliver executive-level summaries highlighting threats, operational impacts, and emerging risks * Provide real-time analytical support during high-priority incidents * Utilize enterprise security tools such as SIEM, SOAR, endpoint security platforms, and vulnerability management systems * Develop and maintain standard operating procedures, playbooks, and methodologies aligned with federal cybersecurity standards * Brief stakeholders and leadership on threat activity and operational findings * Provide mentorship and oversight to junior analysts and hunting personnel * Contribute to continuous improvement initiatives related to threat detection, telemetry, and operational efficiency ## Related Videos - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Alibaba Big Data and Machine Learning Technology](https://www.wearedevelopers.com/videos/37-alibaba-big-data-and-machine-learning-technology) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [PySpark - Combining Machine Learning & Big Data](https://www.wearedevelopers.com/videos/44-pyspark-combining-machine-learning-big-data) - [Forecasting Cyber Attacks with Glassdoor Reviews - Lianne Potter](https://www.wearedevelopers.com/videos/2143-forecasting-cyber-attacks-with-glassdoor-reviews-lianne-potter) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Top 6 Hackathons for Developers in 2023](https://www.wearedevelopers.com/magazine/263-top-6-hackathons-for-developers-in-2023) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Should senior developers refuse interview coding challenges?](https://www.wearedevelopers.com/magazine/29-should-senior-developers-refuse-interview-coding-challenges) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf)