Senior Threat Hunter

SOSi

Washington (District of Columbia)

On-site

USD 90,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

SOSi is seeking a Senior Threat Hunter in Washington, D.C. This role involves conducting threat hunting operations and analyzing data to identify malicious activities. The ideal candidate should have at least five years of experience in data hunting and a bachelor's degree. Required certifications include CISSP and others relevant to cybersecurity. The position may require work in deployed locations, as well as evenings and weekends to meet program needs.

Qualifications

  • Five or more years of experience in data hunting, manipulation, and presentation.
  • Management or team lead experience is required.
  • Experience analyzing TCP/IP, IDS data, PCAP, logs, and sensor data.
  • Certification such as CISSP (Associate), CCSP, or equivalent required.

Responsibilities

  • Conduct proactive threat hunting to identify malicious activity.
  • Analyze data from logs and EDR tools to detect threats.
  • Support detection and response to cyber threats.

Skills

Data hunting
Threat analysis
Scripting/query languages
Malware analysis
Experience with EDR tools

Education

Bachelor’s Degree

Tools

EDR tools
TCP/IP
IDS data
PCAP analysis
R
Python
SQL

Job description

Founded in 1989, SOSi is among the largest private, founder-owned technology and services integrators in the defense and government services industry. We deliver tailored solutions, tested leadership, and trusted results to enable national security missions worldwide.

Job Description

Overview

SOSi is seeking a Senior Threat Hunter to support proactive cyber defense activities in alignment with our customer. This role is responsible for conducting threat hunting operations, analyzing data from multiple sources to identify malicious activity, supporting detection and response efforts, and applying advanced analytical techniques to improve cyber defense operations.

Responsibilities

  • Conduct proactive threat hunting to identify malicious activity, indicators of compromise, and anomalous behavior across the enterprise
  • Analyze data from logs, sensors, endpoint detection and response (EDR) tools, and full packet capture (PCAP) sources to detect threats
  • Apply threat hunting methodologies using MITRE ATT&CK and MITRE D3FEND frameworks
  • Support detection, analysis, and response to cyber threats in coordination with SOC and incident response teams
  • Perform analysis of TCP/IP traffic, intrusion detection system (IDS) data, malware activity, and adversary tactics, techniques, and procedures (TTPs)
  • Use scripting and query tools to support threat analysis, data hunting, and development of analytical outputs
  • Support development of threat hunting products, reporting, and recommendations to improve cyber defense detection and monitoring
Qualifications
  • Experience:
    • Five (5) or more years of experience in data hunting, manipulation, and presentation
    • Management or team lead experience
    • Experience with MITRE ATT&CK and MITRE D3FEND
    • Experience analyzing TCP/IP, IDS data, PCAP, logs, and sensor data
    • Experience supporting malware analysis
    • Experience with Endpoint Detection and Response (EDR) tools
    • Experience with scripting or query languages including R, Python, PIG, HIVE, or SQL
  • Education:
    • Bachelor’s Degree
    • (Bachelor’s Degree may be substituted with additional 4+ years of experience as approved by Government)
  • Certifications:
    One of:
    • CISSP (Associate)
    • CCSP
    • SSCP
    • GCIH
    • GNFA
    • GCIA
  • Plus one DoD 8570 CSSP certification in:
  • CSSP Analyst
  • CSSP Infrastructure Support
  • Clearance/Suitability: Secret (active), Top Secret, SCI Eligible
Additional Information
  • Normal office conditions with potential to perform duties in deployed locations.
  • Core hours of operation are Monday through Friday, 0600 – 1700.
  • May be requested to work evenings and weekends to meet program and contract needs.

Working at SOSi

All interested individuals will receive consideration and will not be discriminated against for any reason.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Threat Hunter
Senior Threat Hunter

SOS International LLC • United States

On-site
USD 130,000 - 180,000
Senior Threat Hunter - Proactive Cyber Defense Lead, Secret
Senior Threat Hunter - Proactive Cyber Defense Lead, Secret

SOS International LLC • United States

On-site
USD 130,000 - 180,000
Senior Cyber Defense Analyst
Senior Cyber Defense Analyst

SOS International LLC • United States

On-site
USD 110,000 - 149,000
Lead Cyber Defense Incident Responder On-site - TS/SCI
Lead Cyber Defense Incident Responder On-site - TS/SCI

S2i2, Inc • Arlington (VA)

On-site
USD 175,000 - 180,000
Professional certifications support
Leadership development
Regular company updates
+3
Lead Cyber Defense Incident ResponderOn-site - TS/SCI
Lead Cyber Defense Incident ResponderOn-site - TS/SCI

S2i2, Inc • Arlington (VA)

On-site
USD 175,000 - 180,000
Certification support
Accessible leadership
Regular company updates
+3
Threat Hunt Analyst
Threat Hunt Analyst

Phase2 Technology • Colorado

On-site
USD 120,000 - 150,000
SOC Watch Officer
SOC Watch Officer

SOS International • Chandler (AZ)

On-site
USD 80,000 - 120,000
Cybersecurity Task Lead
Cybersecurity Task Lead

SOS International LLC • Linthicum (MD)

On-site
USD 120,000 - 249,000
Cybersecurity Task Lead
Cybersecurity Task Lead

SOSi • Linthicum (MD)

On-site
USD 119,803 - 248,822
Threat Hunt Analyst
Threat Hunt Analyst

Booz Allen Hamilton • Lakewood (CO)

On-site
USD 99,000 - 225,000
Comprehensive health benefits
Paid leave
Professional development
+1