Cyber Threat Hunter (Mid-Level)

Posted 15 Days Ago
Be an Early Applicant
Washington, DC
Mid level
Software
The Role
In this role, the Cyber Threat Hunter will monitor and investigate network intrusions, conduct malware analysis, and support forensic investigations. The hunter will analyze security alerts, develop hypotheses, and implement automated detection measures, while participating in Agile Scrum processes and documenting incidents.
Summary Generated by Built In

cFocus Software seeks a Cyber Threat Hunter (Mid-Level) to join our program supporting USDOT in Washington, DC. This position has remote capabilities. This position requires an active Public Trust clearance and must meet 8570 requirements.
Qualifications:

  • Bachelor’s Degree or equivalent experience in a computer, engineering, or science field.
  • Active Public Trust clearance.
  • 8570 Compliant (Security+ CE)
  • Hold active certifications such as GCIA or GCIH or GSEC or GMON, and Splunk Core Power User.
  • 5+ years of relevant experience.

Duties:

  • Identifies, deters, monitors, and investigates computer and network intrusions.
  • Provide computer forensic support to high technology investigations in the form of evidence seizure, computer forensic analysis, and data recovery.
  • Monitor and assess complex security devices for patterns and anomalies from raw events (DNS, DHCP, AD, SE logs), tag events for Tier 1 & 2 monitoring.
  • Conduct malware analysis in out-of-band environment (static and dynamic), including complex malware.
  • Accept and respond to government technical requests through the AOUSC ITSM ticket (e.g., HEAT or Service Now), for threat hunt support.
  • Threat hunt targets include cloud-based and non-cloud-based applications such as: Microsoft Azure, Microsoft O365, Microsoft Active Directory, and Cloud Access Security Brokers (i.e., Zscaler).
  • Review and analyze risk-based Security information and event management (SIEM) alerts when developing hunt hypotheses.
  • Review open-source intelligence about threat actors when developing hunt hypotheses.
  • Plan, conduct, and document iterative, hypothesis based, tactics, techniques, and procedures (TTP) hunts utilizing the agile scrum project management methodology.
  • At the conclusion of each hunt, propose, discuss, and document custom searches for automated detection of threat actor activity based on the hunt hypothesis.
  • Configure, deploy, and troubleshoot Endpoint Detection and Response agents (e.g., Crowdstrike and Sysmon).
  • Collect and analyze data from compromised systems using EDR agents and custom scripts provided by the AOUSC.
  • Track and document cyber defense incidents from initial detection through final resolution.
  • Interface with IT contacts at court or vendor to install or diagnose problems with EDR agents.
  • Participate in government led after action reviews of incidents.
  • Triage malware events to identify the root cause of specific activity.
  • Attend daily Agile Scrum standups and report progress on assigned Jira stories.

Top Skills

Crowdstrike
Gcia
Gcih
Gmon
Gsec
Microsoft Active Directory
Azure
Microsoft O365
Security+
Splunk
Sysmon
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Largo, MD
25 Employees
On-site Workplace
Year Founded: 2006

What We Do

Established in 2006, cFocus Software automates FedRAMP compliance and develops government chatbots for the Azure Government Cloud, Office 365, and SharePoint.

cFocus Software is the exclusive vendor of ATO (Authority To Operate) as a Service™, which automates FedRAMP compliance for the Azure Government Cloud and Office 365.

Contact Us for a demo of ATO as a Service™ or a FREE government chatbot proof of concept project today!

Similar Jobs

Leidos Logo Leidos

Cyber Threat Hunt Lead

Information Technology • Software
Washington, DC, USA
27104 Employees
105K-189K Annually
12 Locations
12000 Employees
130K-216K Annually

Bank of America Logo Bank of America

Senior Threat Hunter

Big Data • Fintech • Mobile • Payments • Financial Services • Data Privacy
3 Locations
208000 Employees
143K-193K Annually
Washington, DC, USA
25 Employees

Similar Companies Hiring

HERE Technologies Thumbnail
Software • Logistics • Internet of Things • Information Technology • Computer Vision • Automotive • Artificial Intelligence
Amsterdam, NL
6000 Employees
True Anomaly Thumbnail
Software • Machine Learning • Hardware • Defense • Artificial Intelligence • Aerospace
Colorado Springs, CO
131 Employees
Caliola Engineering Thumbnail
Software • Machine Learning • Hardware • Defense • Data Privacy • App development • Aerospace
Colorado Springs, CO
52 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account