Cyber Hunt Team Leader

ECS

Richmond (VA)

Hybrid

USD 140,000 - 160,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

ECS Federal LLC is seeking a Cyber Hunt Team Leader to direct proactive threat hunting, advanced analytics, and incident response for a large federal IT enterprise. You will guide a skilled team, coordinate with SOC, CTI, and agency partners, and develop detection strategies and intelligence to reduce risk.

The role requires 10+ years in cybersecurity, active clearance, and senior-level leadership. Remote work within proximity to the NCR is supported, with a competitive salary and federal-facing

Qualifications

  • 10+ years of cybersecurity experience with threat hunting and incident response.
  • Active Public Trust 6c or ability to obtain and maintain one.
  • US Citizenship is required.
  • At least one of CISSP, GCIH, GCFA, or CEH.
  • Experience leading threat-hunting teams within an SOC environment.
  • Hands-on experience with EDR/NDR, SIEM, MITRE ATT&CK, and threat emulation.
  • Strong OS, networking knowledge and TTPs; excellent written/verbal skills for federal docs.

Responsibilities

  • Lead proactive threat hunting missions and analytics to identify and neutralize threats.
  • Serve as incident response lead and project/technical lead for the Hunt Team.
  • Coordinate with SOC, CTI, and government partners to mitigate APTs.
  • Develop IoCs, detection logic, and threat-hunting playbooks.
  • Support Purple Team exercises and threat emulation to validate defenses.
  • Oversee network analysis capabilities for incident response and hunting.
  • Lead responses to critical network intrusions across the federal enterprise.
  • Provide program management and roadmaps for new tech to enhance hunt capabilities.
  • Present findings and risk intel to senior government officials.

Skills

Threat hunting
Incident response
Adversary tracking
Security operations leadership
Communication

Education

Bachelor's degree in Cybersecurity/IT/CS or related field

Tools

EDR/NDR platforms
SIEM tools
MITRE ATT&CK framework
Threat emulation methodologies

Job description

Cyber Hunt Team Leader

Location: National Capital Region (NCR) – remote work possible within close proximity.

Salary Range: $140,000 - $160,000.

The Cyber Hunt Team Leader will lead proactive threat hunting missions, advanced analytics, and incident response across a large federal IT enterprise. This role will direct a skilled team to uncover advanced threats, collaborate with SOC analysts, CTI teams, and agency stakeholders, and develop detection strategies, threat emulation exercises, and actionable intelligence that reduces risk across the organization.

Position Responsibilities
  • Lead proactive threat hunting missions and advanced analytics to identify and neutralize threats before they impact agency operations.
  • Serve as an incident response lead, proactive/persistent hunt lead, and project/technical lead for the Hunt Team.
  • Coordinate with SOC, CTI, and other business partners and government teams to identify and mitigate advanced persistent threats (APTs).
  • Develop threat hypotheses, detection logic, and a comprehensive knowledge base of Indicators of Compromise (IoCs).
  • Support Purple Team exercises and threat emulation activities to validate and improve the agency's defensive posture.
  • Oversee and coordinate analysis and development of capabilities related to network analysis and network device integrity for incident response and proactive threat hunting.
  • Lead teams in responding to critical network intrusions across the federal enterprise.
  • Provide leadership and program management for large-scale hunt operations, identifying technical roadmaps for the use of new and emerging technologies to maximize hunt capabilities across network, endpoint, and cloud-based environments.
  • Develop and continuously improve threat hunting methodologies, playbooks, and standard operating procedures.
  • Serve as a trusted liaison between hunt team personnel and agency stakeholders, facilitating clear communication and timely issue resolution.
  • Present findings, risk recommendations, and threat intelligence to senior government officials in a clear, actionable format.
Required Skills
  • U.S. Citizenship required.
  • 10+ years of cybersecurity experience, with demonstrated expertise in threat hunting, incident response, and adversary tracking.
  • Remote but within close proximity to the NCR.
  • Active Public Trust 6c clearance, or the ability to obtain and maintain one.
  • At least one of the following certifications: CISSP, GCIH, GCFA, or CEH.
  • Hands‑on experience with EDR/NDR platforms, SIEM tools, MITRE ATT&CK framework, and threat emulation methodologies.
  • Strong understanding of operating systems, networking, and adversary tactics, techniques, and procedures (TTPs).
  • Experience leading threat hunting teams within a Security Operations Center (SOC) environment.
  • Proven ability to develop threat hypotheses and translate complex technical findings into clear, actionable intelligence for both technical teams and executive audiences.
  • Excellent written and verbal communication skills, with a track record of producing high‑quality federal security documentation.
Desired Skills
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field or equivalent professional experience.
  • One of the following certifications:
    • Certified Information Security Manager (CISM)
    • GIAC Cyber Threat Intelligence (GCTI)
    • GIAC Cloud Threat Detection (GCTD)
    • MITRE ATT&CK Defender (MAD)
  • Familiarity with federal cybersecurity frameworks including NIST RMF, NIST SP 800-53, and FedRAMP compliance requirements.
  • Experience supporting continuous monitoring programs and coordinating with SOC teams on POA&M remediation tracking.
  • Prior experience working on large‑scale federal civilian agency programs with complex, multi‑stakeholder environments.
  • Experience conducting or supporting industrial control systems (ICS)/operational technology (OT) and cloud‑based threat hunting operations.
  • Familiarity with cyber threat intelligence platforms and the structured analysis of threat actor campaigns.
  • Ability to provide strategic guidance that enhances and optimizes an agency's overall cybersecurity posture.
  • Experience with DevSecOps pipelines, vulnerability management tools, and cloud‑native security technologies.

ECS Federal LLC is an equal‑opportunity employer and does not discriminate or allow discrimination on the basis of any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Cyber Threat Hunting Team (Remote/NCR)
Lead Cyber Threat Hunting Team (Remote/NCR)

ECS • Richmond (VA)

Hybrid
USD 140,000 - 160,000
Senior Cybersecurity Threat Hunter III
Senior Cybersecurity Threat Hunter III

Invictus International Consulting, LLC • Colorado Springs (CO)

On-site
USD 158,000 - 193,000
Senior Cybersecurity Threat Hunter III
Senior Cybersecurity Threat Hunter III

Invictus International • Alexandria (VA)

On-site
USD 120,000 - 180,000
Threat Hunt Lead
Threat Hunt Lead

Agile Defense • Reston (VA)

On-site
USD 165,000 - 200,000
Cyber Hunt Specialist
Cyber Hunt Specialist

Strategic Data Systems, Inc. • Dahlgren (VA)

On-site
USD 110,000 - 150,000
Cyber Threat Hunter
Cyber Threat Hunter

Koitecc Solutions • Washington

Hybrid
USD 107,000 - 196,000
Health and Wellness programs
Income protection
Paid leave
+1
Cybersecurity Threat Analyst Subject Matter Expert IV
Cybersecurity Threat Analyst Subject Matter Expert IV

Invictus International Consulting, LLC • Alexandria (VA)

On-site
USD 171,000 - 209,000
Detection Engineer/Threat Hunter
Detection Engineer/Threat Hunter

Partner Forces • Arlington (VA)

On-site
USD 120,000 - 160,000
SK Cyber Hunt Analyst
SK Cyber Hunt Analyst

Probity Inc. • McLean (VA)

On-site
USD 85,000 - 120,000
External Job Posting Title Threat Hunter / Public Trust
External Job Posting Title Threat Hunter / Public Trust

Peraton • Warrenton (VA)

On-site
USD 86,000 - 138,000