Senior Threat Hunter

SOS International LLC

Washington (District of Columbia)

On-site

USD 140,000 - 180,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

SOSi is seeking a Senior Threat Hunter to support proactive cyber defense activities for our client. You will conduct threat hunting across enterprise data, identifying indicators of compromise and anomalous behavior, and collaborate with SOC and incident response teams.

Responsibilities include analyzing logs, EDR, PCAP sources, applying MITRE ATT&CK and D3FEND strategies, and developing analytics outputs to improve detection and response capabilities while mentoring junior staff.

Qualifications

  • Five or more years of data hunting, manipulation, and presentation experience.
  • Experience with MITRE ATT&CK and MITRE D3FEND frameworks.
  • Bachelor’s degree or equivalent experience.
  • Ability to analyze TCP/IP, IDS data, PCAP, logs, and sensor data.
  • Experience with scripting or query languages (R, Python, PIG, HIVE, SQL).

Responsibilities

  • Conduct proactive threat hunting to identify malicious activity and IOC across the enterprise.
  • Analyze data from logs, EDR tools, and PCAP sources to detect threats.
  • Apply MITRE ATT&CK and D3FEND methodologies in operations.
  • Support detection, analysis, and response with SOC and IR teams.
  • Analyze TCP/IP traffic and malware TTPs; produce analytical outputs.
  • Use scripting to support data hunting and product development.

Skills

Threat hunting
Team leadership
MITRE ATT&CK experience
MITRE D3FEND experience
Data analysis
Scripting / query languages

Education

Bachelor’s Degree

Tools

EDR tools
SQL
Python
R
PIG
HIVE

Job description

Washington, DC, USA

Full-time

Clearance Requirement: Secret

Company Description

Founded in 1989, SOSi is among the largest private, founder-owned technology and services integrators in the defense and government services industry. We deliver tailored solutions, tested leadership, and trusted results to enable national security missions worldwide.

Job Description

***** This position is contingent upon contract award *****

Overview

SOSi is seeking a Senior Threat Hunter to support proactive cyber defense activities in alignment with our customer. This role is responsible for conducting threat hunting operations, analyzing data from multiple sources to identify malicious activity, supporting detection and response efforts, and applying advanced analytical techniques to improve cyber defense operations.

Responsibilities
  • Conduct proactive threat hunting to identify malicious activity, indicators of compromise, and anomalous behavior across the enterprise

  • Analyze data from logs, sensors, endpoint detection and response (EDR) tools, and full packet capture (PCAP) sources to detect threats

  • Apply threat hunting methodologies using MITRE ATT&CK and MITRE D3FEND frameworks

  • Support detection, analysis, and response to cyber threats in coordination with SOC and incident response teams

  • Perform analysis of TCP/IP traffic, intrusion detection system (IDS) data, malware activity, and adversary tactics, techniques, and procedures (TTPs)

  • Use scripting and query tools to support threat analysis, data hunting, and development of analytical outputs

  • Support development of threat hunting products, reporting, and recommendations to improve cyber defense detection and monitoring

Qualifications
  • Experience:

  • Five (5) or more years of experience in data hunting, manipulation, and presentation
  • Management or team lead experience
  • Experience with MITRE ATT&CK and MITRE D3FEND
  • Experience analyzing TCP/IP, IDS data, PCAP, logs, and sensor data
  • Experience supporting malware analysis
  • Experience with Endpoint Detection and Response (EDR) tools
  • Experience with scripting or query languages including R, Python, PIG, HIVE, or SQL
  • Education:

  • Bachelor’s Degree
  • (Bachelor’s Degree may be substituted with additional 4+ years of experience as approved by Government)
  • Certifications: One of:

  • GCIH
  • GNFA
  • GCIA
  • Plus one DoD 8570 CSSP certification in:
  • CISSP (Associate)
  • CCSP
  • SSCP>
  • Clearance/Suitability : Secret (active), Top Secret, SCI Eligible

Additional Information
Work Environment
  • Normal office conditions with potential to perform duties in deployed locations.
  • Core hours of operation are Monday through Friday, 0600 – 1700.
  • May be requested to work evenings and weekends to meet program and contract needs.
Working at SOSi

All interested individuals will receive consideration and will not be discriminated against for any reason.

SOSi is an equal employment opportunity employer and affirmative action employer. All interested individuals will receive consideration and will not be discriminated against on the basis of race, color, religion, sex, national origin, disability, age, sexual orientation, gender identity, genetic information, or protected veteran status. SOSi takes affirmative action in support of its policy to advance diversity and inclusion of individuals who are minorities, women, protected veterans, and individuals with disabilities.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Intelligence Analyst III
Cyber Intelligence Analyst III

SOS International LLC • Washington

Hybrid
USD 110,000 - 150,000
Cyber Intelligence Analyst III
Cyber Intelligence Analyst III

SmartRecruiters, Inc. • Washington, Northern (KY)

Hybrid
USD 120,000 - 160,000
Occasional remote work
Cybersecurity Task Lead
Cybersecurity Task Lead

SOS International LLC • Linthicum (MD)

Hybrid
USD 120,000 - 249,000
Hybrid work model
Data Scientist III
Data Scientist III

SOS International LLC • Washington

On-site
USD 120,000 - 160,000
Emerging & Disruptive Technology Analyst (Senior)
Emerging & Disruptive Technology Analyst (Senior)

SOS International LLC • Fort Belvoir (VA)

On-site
USD 102,000 - 213,000
Senior Cybersecurity Threat Hunter III
Senior Cybersecurity Threat Hunter III

Invictus International • Alexandria (VA)

On-site
USD 120,000 - 180,000
Senior Cybersecurity Threat Hunter III
Senior Cybersecurity Threat Hunter III

Invictus International Consulting, LLC • Colorado Springs (CO)

On-site
USD 158,000 - 193,000
Senior Threat Hunter
Senior Threat Hunter

Peraton • Chandler (AZ)

On-site
USD 104,000 - 166,000
Penetration Tester III
Penetration Tester III

SOS International LLC • Washington

On-site
USD 120,000 - 180,000
Senior Program Manager
Senior Program Manager

SOS International LLC • Washington

On-site
USD 140,000 - 190,000