- Location
- Colorado Springs, CO
- Type
- Full-time
- Department
- IT
- Education
- Bachelor
- Clearance
- Required
- Source
- ApplicantPro
Description
Title: Cybersecurity Threat Hunter II
Location: Colorado Springs, CO
Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph
Job Details:
- Independently conduct hypothesis-driven threat hunts across available enterprise telemetry to identify malicious or anomalous activity not detected by automated controls
- Proactively analyze security telemetry to identify indicators of compromise, anomalous behavior, and adversary activity that has not met an incident threshold or has evaded automated security controls
- Assess and correlate data from multiple sources, including network, endpoint, identity, SIEM, threat intelligence, vulnerability, and other available security data
- Document hunt activity, findings, evidence, and recommended follow-on actions in authorized systems and initiate or support incident-response processes when malicious activity is identified
- Provide relevant findings and trends for SOC operational reporting, significant-activity reporting, and defensive awareness
- Develop hunt hypotheses based on threat intelligence, adversary TTPs, environmental observations, emerging threats, and known detection gaps
- Use MITRE ATT&CK and other threat-informed methodologies to characterize observed behavior and guide analytical pivots
- Identify patterns, relationships, and potential adversary activity across users, hosts, network segments, and time periods
- Recommend new or improved detections, data collection, enrichment, and defensive controls based on hunt outcomes
Requirements:
- Bachelor's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree
- Minimum four (4) years of relevant experience in addition to education level
- Hands-on experience with threat hunting, security analysis, incident investigation, threat intelligence analysis, or comparable proactive cyber defense work
- Working knowledge of adversary TTPs, MITRE ATT&CK, network and endpoint telemetry, and analytical search techniques
- Experience using SIEM, network-security monitoring, endpoint telemetry, or other large-scale security data sources
- Must possess current DoD 8570 IAT II or IAM II certification
- Experience working in a DoD or IC environment
- Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph
Equal Opportunity Employer/Veteran/Disabled
Skills
CybersecuritySIEMSOC