> Markdown version of [/jobs/ext/578873-cybersecurity-threat-hunter](https://www.wearedevelopers.com/jobs/ext/578873-cybersecurity-threat-hunter). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Threat Hunter - **Company:** University of Maryland University College - **Location:** Adelphi, MD, United States - **Experience:** Expert - **Salary:** $120,000.0 - $135,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Microsoft Azure, Bash Shell, Cloud Computing, Cyber Security, Information Systems, Query Languages, Linux, Python (Programming Language), Packet Analyzer, Network Protocols, Windows PowerShell, Phishing, Reverse Engineering, Security Information and Event Management, Scripting, Mitre Att&ck, Malware, Cyber Threat Analysis, Information Technology, Cybercrime - **Published:** June 18, 2026 - **Apply:** https://careers.umgc.edu/job/cybersecurity-threat-hunter-it-and-project-management-adelphi-md-10025804/ ## About the Role * Strong knowledge of threat actor tactics, techniques, and procedures (TTPs) and experience using frameworks such as MITRE ATT&CK. * Proficiency with EDR tools, SIEM platforms, and threat intelligence platforms. * Ability to develop detection logic using scripting or query languages (e.g., PowerShell, Bash, Python). * Experience with log and packet analysis, endpoint forensics, and malware reverse engineering. * In-depth understanding of operating system internals (Windows, Linux), network protocols, and cloud infrastructure (AWS, Azure). * Strong analytical and problem-solving skills, with the ability to work independently and collaboratively. * Excellent verbal and written communication skills; capable of conveying technical findings to technical and non-technical audiences. Required Qualifications: Education: * Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or a related field (or equivalent experience). Experience: * Minimum of 6-8 years of relevant cybersecurity experience, with at least 5 years focused on threat hunting, threat intelligence, or incident response. Preferred Qualifications: Certifications: * GIAC Cyber Threat Intelligence (GCTI) * GIAC Certified Incident Handler (GCIH) * GIAC Advanced Threat Hunting (GATH) * Certified Threat Intelligence Analyst (CTIA) * OSCP or similar offensive security certifications ## Description We are seeking a highly skilled and proactive Cybersecurity Threat Hunter to join our Information Security team. In this role, you will be responsible for proactively identifying advanced threats and developing detection strategies to protect enterprise assets. You will apply your deep expertise in adversary tactics, techniques, and procedures (TTPs), threat intelligence, and endpoint/network telemetry to hunt, investigate, and mitigate complex threats in our hybrid multi-cloud environment., * Lead proactive threat hunting activities across endpoints, network, and cloud environments to detect anomalous behaviors and emerging threats. * Analyze large security logs to identify patterns of malicious activity and Indicators of Compromise (IOCs) using our SIEM and EDR platforms, augmenting analysis with threat intelligence feeds. * Develop and refine hypotheses for hunting campaigns based on current threat landscape and adversary TTPs (e.g., MITRE ATT&CK). * Collaborate with the bigger Information Security team and other cross-functional teams to triage, escalate, and respond to identified threats. * Design and implement custom detection logic and rules to improve threat detection efficacy within SIEM tool. * Perform analysis on phishing emails, malicious files, and other threat artifacts when required. * Develop documentation, hunting playbooks, and knowledge transfer materials for junior analysts and other stakeholders. * Produce relevant valuable reports following threat assessments highlighting recommendations to improve security. * Provide expert-level consultation on threat hunting methodologies and cyber adversary techniques. * Maintain awareness of the latest security threats, vulnerabilities, and attack techniques through continuous research. * Mentor and guide tier 1 engineers, fostering skill development and knowledge sharing. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Getting under the skin: The Social Engineering techniques](https://www.wearedevelopers.com/videos/38-getting-under-the-skin-the-social-engineering-techniques) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf)