Senior Cybersecurity Threat Hunter
Enterprise Solutions and Management (ESM) is a rapidly growing government contractor that provides strategic IT services that meet mission needs for Defense and Federal customers. We are hiring a Cybersecurity Threat Hunter to support an enterprise-level program within a federal environment.
Job Description and Responsibilities
Proactively identifies and investigates cyber threats that may be operating undetected within the network, using a threat-informed approach that assumes an adversary may already have access to the environment. Analyzes raw log, network, and security data to identify unusual activity and potential malicious behavior, while collaborating with Threat Detection and Incident Response teams to develop and pursue hunting leads. Correlates enterprise activity and emerging trends with current threat intelligence to identify potential threats, vulnerabilities, and areas requiring mitigation. Leads the analysis and response to advanced persistent threats (APTs) and other compromises discovered during threat hunting activities. Develops and implements threat hunting strategies, tools, and automation to improve the organization's ability to detect sophisticated adversaries, and provides incident response support for critical security incidents.
Required Knowledge, Skills and Abilities (KSA)
- Knowledge of threat hunting methodologies and the ability to proactively identify anomalous activity, advanced threats, and indicators of compromise within an enterprise network.
- Skill in analyzing and correlating raw log, network, security, and threat intelligence data to identify malicious activity, vulnerabilities, and emerging threats.
- Ability to investigate and respond to critical security incidents, including advanced persistent threats (APTs) and network compromises, and develop effective mitigation strategies.
- Ability to develop threat hunting strategies, tools, and automated capabilities that improve the detection and analysis of sophisticated cyber adversaries.
- Knowledge of security challenges across multiple operating systems and the MITRE ATT&CK framework.
- Ability to analyze large datasets and identify trends, anomalies, and potential threats.
- Experience with security tools and scripting languages, including Splunk, Python, and PowerShell.
- Ability to translate threat intelligence and data into actionable insights and clear threat hunting documentation.
Desired KSA
- Be a positive, self-motivated, and proactive person with the ability to adapt to change and tolerate stressful situations
- Candidate must communicate effectively with team members, team lead, management, and government customers
- Must have the ability and desire to research and develop creative solutions to unique problems with minimal supervision
Minimum Training, Education, and Certifications
- Five (5) years of technical experience in one of the following areas: Threat Intelligence, Cybersecurity Incident Response, Penetration Testing, Reverse Engineering, Digital Forensic
- Three (3) years of experience analyzing attacker techniques at all levels of attack.
- Must maintain CSSP Analyst certification by having one of the following or equivalent - (CEH, CFR, GCIA, GCISP)
Minimum Clearance
- Top Secret
Physical Requirements
- Required to stand, walk and sit; communicate verbally both in person and by telephone; use hands to finger, handle or feel objects or controls; reach with hands and arms. Regularly required to stoop, kneel, bend, crouch and lift up to 25 pounds. Specific vision abilities required by this job include close vision, distance vision, depth perception, color vision and the ability to adjust focus.
- Physical demands associated with this position include extensive walking (including stairs) throughout offices and between buildings. May require use of public transportation, personal or Government vehicle to drive to local and/or remote office locations.
Additional Requirements
- Other duties as assigned
ESM provides equal employment opportunity to all individuals regardless of race, color, creed, religion, gender, age, sexual orientation, national origin or ancestry, disability, genetic information, veteran status, gender identification or any other characteristic protected by state, federal or local law.
Required Skills
Required Languages
🇬🇧 English