Cybersecurity Analyst, Threat Hunter
Role details
Job location
Tech stack
Job description
Digital Global Connectors (DGC) is seeking an experienced Cybersecurity Analyst - Tier 3 (Threat Hunter) to support a Federal information security program. The Tier 3 Threat Hunter is responsible for proactively identifying advanced threats, uncovering malicious activity that has evaded traditional security controls, and improving the organization's overall cyber defense capabilities through advanced threat hunting, behavioral analytics, and detection engineering.
This position conducts hypothesis-driven threat hunting, analyzes attacker tactics, techniques, and procedures (TTPs), develops advanced detection methodologies, and collaborates with Security Operations Center (SOC) personnel, Incident Responders, Threat Intelligence Analysts, Security Engineers, and ISSOs to strengthen enterprise security operations and reduce organizational cyber risk.
The successful candidate will possess extensive experience detecting sophisticated cyber threats, performing advanced threat hunting, and applying intelligence-driven methodologies to identify adversary activity across enterprise environments., Threat Hunting Operations
- Conduct proactive threat hunting across enterprise networks, endpoints, cloud environments, and information systems.
- Develop hypothesis-driven hunting campaigns based on threat intelligence, emerging attack trends, and organizational risk.
- Identify indicators of compromise (IOCs), indicators of attack (IOAs), and anomalous system behavior.
- Detect malicious activity that bypasses traditional security controls.
- Validate findings and coordinate response activities with Incident Response personnel.
- Continuously improve threat hunting methodologies and operational effectiveness.
Advanced Threat Analysis
- Analyze attacker tactics, techniques, and procedures (TTPs).
- Correlate data across multiple security platforms to identify sophisticated attack campaigns.
- Evaluate suspicious user activity, authentication anomalies, privilege escalation, persistence mechanisms, and lateral movement.
- Identify advanced persistent threats (APTs), insider threats, and emerging attack patterns.
- Develop recommendations to improve organizational cyber resilience.
Detection Engineering
- Design, develop, and optimize advanced detection logic.
- Create and refine SIEM detection rules, behavioral analytics, correlation searches, and custom alerts.
- Reduce false positives while improving detection fidelity.
- Develop threat detection use cases aligned with known adversary techniques.
- Validate detection effectiveness through testing and simulation.
- Support continuous improvement of enterprise detection capabilities.
Threat Intelligence Integration
- Incorporate internal and external threat intelligence into hunting operations.
- Analyze intelligence reports to identify threats relevant to the enterprise.
- Map adversary behaviors to organizational assets and risks.
- Correlate threat intelligence with enterprise telemetry.
- Collaborate with Threat Intelligence Analysts to operationalize intelligence.
- Recommend defensive measures based on intelligence findings.
Security Tool Operations
Utilize enterprise security technologies including:
- Microsoft Sentinel
- Splunk Enterprise Security
- Microsoft Defender XDR
- Microsoft Defender for Endpoint
- Microsoft Defender for Identity
- Microsoft Defender for Cloud
- CrowdStrike Falcon
- Palo Alto Cortex XDR
- Microsoft Defender for Office 365
- Velociraptor
- Sysmon
- Security Information and Event Management (SIEM)
- Endpoint Detection and Response (EDR)
- Extended Detection and Response (XDR)
- User and Entity Behavior Analytics (UEBA)
Develop and optimize detection capabilities utilizing these technologies.
Threat Hunting Automation
- Develop scripts and automation to improve threat hunting efficiency.
- Automate repetitive investigative tasks where appropriate.
- Create reusable hunting playbooks and workflows.
- Improve data collection and enrichment processes.
- Support Security Orchestration, Automation, and Response (SOAR) initiatives.
- Recommend automation opportunities across cybersecurity operations.
Incident Support
- Support Tier 2 Incident Responders during complex cybersecurity investigations.
- Assist in identifying attack scope, persistence mechanisms, and attacker objectives.
- Provide advanced technical expertise during incident response activities.
- Recommend containment, eradication, and recovery strategies.
- Validate remediation activities following incident resolution.
Reporting and Documentation
Develop and maintain:
- Threat Hunting Reports
- Threat Assessments
- Detection Use Cases
- Threat Intelligence Summaries
- Hunting Playbooks
- Executive Briefings
- Adversary Profiles
- Hunting Metrics
- Lessons Learned
- Standard Operating Procedures
Ensure documentation accurately reflects technical findings and supports operational decision-making.
Collaboration
- Coordinate with Tier 1 SOC Analysts, Tier 2 Incident Responders, Threat Intelligence Analysts, Security Engineers, Digital Forensics Analysts, ISSOs, and Government stakeholders.
- Participate in cyber defense working groups and operational planning sessions.
- Mentor junior analysts in threat hunting methodologies.
- Present technical findings to both technical and executive audiences.
- Support enterprise cybersecurity exercises and adversary simulations.
Continuous Improvement
- Monitor emerging cyber threats, adversary tradecraft, and evolving attack techniques.
- Evaluate new threat hunting technologies and methodologies.
- Recommend enhancements to enterprise detection and monitoring capabilities.
- Participate in purple team exercises and detection validation activities.
- Maintain professional certifications and technical expertise in advanced cyber defense operations.
Requirements
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, Digital Forensics, or a related discipline.
- Minimum six (6) years of experience supporting cybersecurity operations, threat hunting, cyber defense, or incident response.
- Experience conducting proactive threat hunting within enterprise environments.
- Experience utilizing SIEM, EDR, XDR, and behavioral analytics platforms.
- Strong understanding of attacker tactics, techniques, and procedures (TTPs).
- Experience analyzing Windows, Linux, cloud, and network security telemetry.
- Experience with scripting languages such as PowerShell or Python.
- Strong analytical, investigative, communication, and documentation skills.
- U.S. Citizenship required.
- Ability to obtain and maintain a Tier 2 Public Trust.
Preferred Qualifications
- Master's degree in Cybersecurity, Computer Science, Information Assurance, or a related discipline.
- Experience supporting a Federal civilian agency.
- Experience utilizing the MITRE ATT&CK Framework for threat hunting and detection engineering.
- Experience supporting Microsoft Azure, Microsoft 365, or AWS security operations.
- GIAC Cyber Threat Intelligence (GCTI)
- GIAC Certified Intrusion Analyst (GCIA)
- GIAC Certified Incident Handler (GCIH)
- CompTIA CySA+
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- Certified Information Systems Security Professional (CISSP) (preferred)
Knowledge, Skills, and Abilities
- Threat Hunting
- Detection Engineering
- Threat Intelligence
- Adversary Emulation
- MITRE ATT&CK Framework
- Microsoft Sentinel
- Splunk Enterprise Security
- Microsoft Defender XDR
- Microsoft Defender for Endpoint
- Microsoft Defender for Identity
- Microsoft Defender for Cloud
- Security Information and Event Management (SIEM)
- Endpoint Detection and Response (EDR)
- Extended Detection and Response (XDR)
- User and Entity Behavior Analytics (UEBA)
- Windows Security
- Linux Security
- Cloud Security
- Network Security
- Threat Analytics
- Malware Identification
- Behavioral Analysis
- PowerShell
- Python
- Log Analysis
- Kusto Query Language (KQL)
- Microsoft Office Suite
- ServiceNow
- Jira
Security Requirements
- Ability to successfully obtain and maintain a Tier 2 Public Trust investigation.
- Compliance with all applicable Federal security, privacy, ethics, and information assurance training requirements before receiving system access.
- Ability to support advanced cyber defense operations, incident response activities, scheduled maintenance windows, continuity of operations (COOP), and surge support as required.
- Must maintain strict confidentiality while handling sensitive threat intelligence, investigative findings, enterprise telemetry, and Federal information systems.
- Ability to independently identify sophisticated cyber threats, develop advanced detection methodologies, and collaborate with Government stakeholders and cybersecurity teams to strengthen enterprise defensive capabilities through proactive threat hunting and continuous operational improvement.