Cybersecurity Threat Hunter II

Invictus International

Colorado Springs (CO)

On-site

USD 120,000 - 170,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Invictus International in Colorado Springs seeks a Threat Hunter to independently conduct hypothesis-driven hunts across enterprise telemetry and identify malicious activity not detected by automated controls. You will proactively analyze security telemetry to uncover indicators of compromise and adversary activity that evade thresholds.

The role requires correlating data from network, endpoint, identity, SIEM, threat intelligence, and other sources; documenting findings; and supporting incident

Qualifications

  • Hands-on experience with threat hunting, security analysis, incident investigation, threat intelligence analysis, or comparable proactive cyber defense work.

Responsibilities

  • Independently conduct hypothesis-driven threat hunts across available enterprise telemetry to identify malicious or anomalous activity not detected by automated controls.
  • Proactively analyze security telemetry to identify indicators of compromise, anomalous behavior, and adversary activity that has not met an incident threshold or has evaded automated security controls.
  • Assess and correlate data from multiple sources, including network, endpoint, identity, SIEM, threat intelligence, vulnerability, and other available security data.
  • Document hunt activity, findings, evidence, and recommended follow-on actions in authorized systems and initiate or support incident-response processes when malicious activity is identified.
  • Provide relevant findings and trends for SOC operational reporting, significant-activity reporting, and defensive awareness.
  • Develop hunt hypotheses based on threat intelligence, adversary TTPs, environmental observations, emerging threats, and known detection gaps.
  • Use MITRE ATT&CK and other threat-informed methodologies to characterize observed behavior and guide analytical pivots.
  • Identify patterns, relationships, and potential adversary activity across users, hosts, network segments, and time periods.
  • Recommend new or improved detections, data collection, enrichment, and defensive controls based on hunt outcomes.

Skills

Threat hunting
Security analysis
Incident investigation
Threat intelligence analysis
MITRE ATT&CK
Adversary TTPs
SIEM
Network telemetry
Endpoint telemetry
Certification (DoD 8570 IAM II/IAT II)

Education

Bachelor's degree in a technical discipline

Tools

SIEM
Network-security monitoring
Endpoint telemetry

Job description

Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph

  • Independently conduct hypothesis-driven threat hunts across available enterprise telemetry to identify malicious or anomalous activity not detected by automated controls
  • Proactively analyze security telemetry to identify indicators of compromise, anomalous behavior, and adversary activity that has not met an incident threshold or has evaded automated security controls
  • Assess and correlate data from multiple sources, including network, endpoint, identity, SIEM, threat intelligence, vulnerability, and other available security data
  • Document hunt activity, findings, evidence, and recommended follow-on actions in authorized systems and initiate or support incident-response processes when malicious activity is identified
  • Provide relevant findings and trends for SOC operational reporting, significant-activity reporting, and defensive awareness
  • Develop hunt hypotheses based on threat intelligence, adversary TTPs, environmental observations, emerging threats, and known detection gaps
  • Use MITRE ATT&CK and other threat-informed methodologies to characterize observed behavior and guide analytical pivots
  • Identify patterns, relationships, and potential adversary activity across users, hosts, network segments, and time periods
  • Recommend new or improved detections, data collection, enrichment, and defensive controls based on hunt outcomes
Requirements
  • Bachelor's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree
  • Minimum four (4) years of relevant experience in addition to education level
  • Hands-on experience with threat hunting, security analysis, incident investigation, threat intelligence analysis, or comparable proactive cyber defense work
  • Working knowledge of adversary TTPs, MITRE ATT&CK, network and endpoint telemetry, and analytical search techniques
  • Experience using SIEM, network-security monitoring, endpoint telemetry, or other large-scale security data sources
  • Must possess current DoD 8570 IAT II or IAM II certification
  • Experience working in a DoD or IC environment
  • Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph

Equal Opportunity Employer/Veteran/Disabled

Helping all candidates find great careers is our goal. The information you provide here is secure and confidential.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Threat Hunter II
Cybersecurity Threat Hunter II

Invictus International • Alexandria (VA)

On-site
USD 120,000 - 160,000
Senior Cybersecurity Threat Hunter III
Senior Cybersecurity Threat Hunter III

Invictus International • Alexandria (VA)

On-site
USD 120,000 - 180,000
Cybersecurity Threat Analyst
Cybersecurity Threat Analyst

Invictus International • Alexandria (VA)

On-site
USD 110,000 - 170,000
Cybersecurity Threat Analyst
Cybersecurity Threat Analyst

Invictus International • Colorado Springs (CO)

On-site
USD 90,000 - 140,000
Senior Cybersecurity Threat Hunter III
Senior Cybersecurity Threat Hunter III

Invictus International • Colorado Springs (CO)

On-site
USD 130,000 - 190,000
Senior Cybersecurity Threat Hunter III
Senior Cybersecurity Threat Hunter III

Invictus International Consulting, LLC. • Alexandria (VA)

On-site
USD 120,000 - 180,000
Equal Opportunity Employer
Senior Cybersecurity Threat Hunter III
Senior Cybersecurity Threat Hunter III

Invictus International Consulting, LLC. • Colorado Springs (CO)

On-site
USD 120,000 - 170,000
Cybersecurity Threat Analyst Subject Matter Expert IV
Cybersecurity Threat Analyst Subject Matter Expert IV

Invictus International Consulting, LLC. • Alexandria (VA)

On-site
USD 140,000 - 190,000
Cybersecurity Threat Analyst Subject Matter Expert IV
Cybersecurity Threat Analyst Subject Matter Expert IV

Invictus International • Alexandria (VA)

On-site
USD 150,000 - 190,000
Cybersecurity Threat Analyst Subject Matter Expert IV
Cybersecurity Threat Analyst Subject Matter Expert IV

Invictus International Consulting, LLC. • Colorado Springs (CO)

On-site
USD 130,000 - 190,000