Cyber Security Analyst Leads – Cyber Threat Hunting

FIS Management Services LLC

Jacksonville (FL)

On-site

USD 110,000 - 150,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

FIS Management Services LLC seeks a Cyber Security Analyst Lead – Cyber Threat Hunting in Jacksonville, FL to act as a technical lead within the CT H program. You will drive proactive hunts, leverage EDR/SIEM, and translate threat intel into detections to reduce dwell time.

You will collaborate with SOC, pen-testing teams, and detection engineering to operationalize hunts into durable detections and scalable workflows, including scripting in PowerShell, Python, and Bash.

Qualifications

  • Bachelor’s degree or foreign equivalent in Computer Science, Cyber Security, Digital Forensics, or related field with seven years of experience.
  • Experience investigating endpoint-based threats using enterprise EDR and analyzing behavioral detections.
  • Experience developing and tuning detections in SIEM platforms across enterprise environments.
  • Experience supporting cybersecurity incident response activities (triage, containment, remediation).
  • Familiarity with Python, PowerShell and Bash to automate workflows and investigations.
  • Experience consuming threat intelligence including IOCs and adversary TTPs; Masters +5 years accepted.

Responsibilities

  • Lead proactive threat hunts across endpoints, network, identity and cloud telemetry.
  • Execute complex investigations using enterprise EDR and SIEM; scope, contain, and support remediation.
  • Translate threat intel into high-fidelity detections and durable response playbooks.
  • Automate hunting workflows and scale investigations using scripting.

Skills

Scripting (Python)
Scripting (PowerShell)
Scripting (Bash)
Threat hunting
Incident response

Education

Bachelor’s degree in Computer Science / Cyber Security / Digital Forensics or related field
Master’s degree in listed fields with 5 years of experience

Tools

EDR
SIEM
Threat intelligence platforms

Job description

Responsibilities

FIS Management Services, LLC seeks Cyber Security Analyst Leads – Cyber Threat Hunting in Jacksonville, FL to serve as a technical lead within FIS Cyber Threat Hunting (CTH) program, driving proactive, hypothesis-based threat hunts across endpoint, network, identity and cloud telemetry to uncover stealthy adversary activity leading to reductions in attack dwell time in the FIS environment. Execute complex investigations using enterprise level EDR and SIEM platforms, correlate multi-source evidence and rapidly scope, contain and support remediation for incidents including malware, credential compromise and unauthorized access while clearly documenting hunt outcomes and investigative conclusions. Translate threat intelligence and adversary TTPs into high-fidelity behavioral analytics mapped to frameworks such as MITRE ATT&CK, and partner with the Security Operations Center, Penetration Testing Teams and Detection Engineering stakeholders to operationalize successful hunts into durable detections and improved response playbooks. Automate and scale hunting and investigative workflows through scripting languages (PowerShell/BASH), enrichment and data analysis to improve speed, consistency and signal quality. Lead threat hunting efforts in newly acquired or integrating M&A environments, where rapidly assess unfamiliar architectures, establish baselines, and identify inherited risk and latent compromise. Hunt for pre- and post-acquisition adversary activity while informing integration and risk-reduction strategies.

Qualifications
  • Bachelor’s degree or foreign equivalent in Computer Science, Cyber Security, Digital Forensics, or related field and seven (7) years of progressively responsible experience in the job offered or a related occupation.
  • Investigating endpoint-based security threats using enterprise Endpoint Detection and Response (EDR) solutions, including analysis of behavioral detections, process execution trees, command-line activity, and persistence mechanisms to identify and contain malicious activity.
  • Developing, tuning, and investigating security detections using SIEM platforms in an enterprise environment, including analysis of authentication logs, endpoint telemetry, network events, and cloud audit logs.
  • Supporting cybersecurity incident response activities, including triage, scoping, containment, and remediation of incidents including malware infections, credential compromise, and unauthorized access.
  • Utilizing scripting languages including Python, PowerShell, and Bash to automate security workflows, analyze security data, enrich security alerts, or support incident investigations.
  • Consuming and applying threat intelligence, including indicators of compromise (IOCs), adversary tactics and techniques, and opensource intelligence, to enhance security detections and investigations.
  • In the alternative, the employer will accept a Master’s degree in the above listed fields and five (5) years of experience in the above listed skills.
  • Telecommuting and/or working from home may be permissible pursuant to company policies.
EEOC Statement

FIS is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, marital status, genetic information, national origin, disability, veteran status, and other protected characteristics. The EEO is the Law poster is available here supplement document available here For positions located in the US, the following conditions apply. If you are made a conditional offer of employment, you will be required to undergo a drug test. ADA Disclaimer: In developing this job description care was taken to include all competencies needed to successfully perform in this position. However, for Americans with Disabilities Act (ADA) purposes, the essential functions of the job may or may not have been described for purposes of ADA reasonable accommodation. All reasonable accommodation requests will be reviewed and evaluated on a case-by-case basis.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Analyst Leads – Cyber Threat Hunting
Cyber Security Analyst Leads – Cyber Threat Hunting

FIS • Jacksonville (FL)

On-site
USD 120,000 - 170,000
Cyber Threat Hunting Lead - Detect & Contain Threats
Cyber Threat Hunting Lead - Detect & Contain Threats

FIS • Jacksonville (FL)

On-site
USD 120,000 - 170,000
Lead Cyber Threat Hunter for Proactive Detection & Response
Lead Cyber Threat Hunter for Proactive Detection & Response

FIS Management Services LLC • Jacksonville (FL)

On-site
USD 110,000 - 150,000
Detection Engineer – Threat Hunter
Detection Engineer – Threat Hunter

ECS • Arlington (VA)

Hybrid
USD 170,000 - 190,000
Detection Engineer - Threat Hunter
Detection Engineer - Threat Hunter

ECS Corporate Services • Arlington (VA)

Hybrid
USD 170,000 - 190,000
Top Secret Clearance
Threat Hunter
Threat Hunter

Bank of America • Washington

On-site
USD 130,000 - 170,000
Detection Engineer – Threat Hunter
Detection Engineer – Threat Hunter

Everforth ECS • Arlington (VA)

Hybrid
USD 120,000 - 170,000
Senior Cybersecurity Threat Hunter III
Senior Cybersecurity Threat Hunter III

Invictus International Consulting, LLC. • Colorado Springs (CO)

On-site
USD 120,000 - 170,000
Cyber Threat Hunt (CTH) Lead
Cyber Threat Hunt (CTH) Lead

Accenture Federal Services • Arlington (VA)

On-site
USD 116,000 - 244,000
Health insurance
Collaborative work environment
Hands-on experience and training
Senior Cybersecurity Threat Hunter III
Senior Cybersecurity Threat Hunter III

Invictus International • Colorado Springs (CO)

On-site
USD 130,000 - 190,000