Senior Threat Hunter

Revolutional, LLC

Washington

On-site

USD 135,000 - 175,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Medical insurance
Dental & vision
401(k) plan
Teleworking options
Paid holidays
Parental leave
Professional development

Job summary

Revolutional is seeking a Senior Threat Hunter in the Washington, DC area to proactively hunt for threats that automated tools miss. You will analyze network data, develop reusable hunting techniques, and lead hunt operations to improve detection across enterprise environments.

You will write scripts, build SIEM queries, and brief findings to technical peers and executives. A strong data skillset and leadership experience are required for this role.

Qualifications

  • Bachelor’s degree in CS/InfoSec or 4+ years of related experience.
  • 5+ years of data hunting, manipulation, and presentation in a security operations or threat intelligence context.
  • Experience in a management or team lead capacity; managing projects and tasks.
  • Active Secret clearance; Top Secret/SCI eligibility.
  • Proficiency with SIEM platforms: search language, query development, alert tuning, dashboard creation, and report building.
  • Scripting proficiency in Python, R, SQL, or equivalent languages for data analysis.

Responsibilities

  • Proactively hunt for APTs, adversary TTPs, and indicators across network data (flow, PCAP, logs, endpoint telemetry).
  • Develop, execute, and document reusable hunt tactics that can be scaled across the security program.
  • Build and maintain SIEM queries, alerts, dashboards, and reports to support hunt operations.
  • Write scripts to automate data collection, manipulation, and analysis workflows.
  • Develop algorithms to analyze complex data structures and identify anomalous patterns.

Skills

Threat hunting
APTs tracking
Data analysis
Scripting (Python, R, SQL)
MITRE ATT&CK
EDR experience
Communication skills
Leadership

Education

Bachelor’s degree in CS/InfoSec

Tools

SIEM platforms
EDR tools
PCAP analysis

Job description

Revolutional delivers advanced technology solutions and mission support to federal agencies across civilian, health, and national security environments. We apply modern capabilities, including AI/ML, cloud, cybersecurity, and IT modernization to solve complex challenges, enable faster and more secure operations, and drive measurable mission outcomes.

We are redefining how federal technology gets built and delivered by operating with a product mindset, prioritizing speed, ownership, and execution over bureaucracy.

Title: Senior Threat Hunter

Location: Washington, DC or Chandler, AZ

Terms: Full-time

Salary: $135-$175k DOE

Clearance: Secret eligibility

Travel: 0-20%

Position Description

As a Senior Threat Hunter at Revolutional, you go looking for threats that automated tools miss. You proactively hunt for Advanced Persistent Threats and adversary activity across enterprise network environments — using network flow, PCAP, logs, sensors, and endpoint data — before they manifest as confirmed incidents. You are technically deep, analytically rigorous, and creative enough to find what others overlook.

You bring serious data skills: you write scripts, build algorithms, develop SIEM queries, and manipulate large data sets to surface patterns and anomalies. You also lead. You manage hunt operations against tight deadlines, develop reusable hunt tactics that raise the team’s capabilities, and brief findings clearly to technical peers and executive audiences alike.

Responsibilities
  • Proactively hunt for APTs, adversary TTPs, and indicators of compromise across network flow, PCAP, logs, endpoint telemetry, and sensor data
  • Develop, execute, and document reusable hunt tactics, techniques, and procedures that can be operationalized across the security program
  • Build and maintain SIEM queries, alerts, dashboards, and reports to support hunt operations and improve detection coverage
  • Write scripts in Python, R, SQL, PIG, HIVE, or equivalent languages to automate data collection, manipulation, and analysis workflows
  • Develop algorithms to analyze complex data structures and identify anomalous patterns indicative of adversary activity
  • Apply MITRE ATT&CK and D3FEND frameworks to structure hunt hypotheses, map adversary behavior, and recommend defensive improvements
  • Conduct complex malware analysis to understand adversary tools, identify encoding techniques (XOR, Base64, ASCII, Unicode, URL encoding, Uuencode), and extract actionable IOCs
  • Leverage EDR solutions to investigate endpoint activity, identify suspicious behavior, and support hunt and incident response workflows
  • Interpret and fuse data from multiple tool sources into coherent hunt findings and threat assessments
  • Produce clear, well-structured hunt reports and briefings for audiences ranging from technical analysts to executive leadership
  • Develop, update, and maintain standard operating procedures and technical documentation for hunt operations
  • Manage hunt projects and tasks against tight deadlines; provide team leadership and mentorship as needed
  • Stay current on adversary tactics, trends, and emerging threat vectors relevant to the federal enterprise environment
Baseline Requirements
  • Bachelor’s degree in Computer Science, Information Security, or related field; may be substituted with 4 or more additional years of qualifying experience
  • 5 or more years of experience in data hunting, manipulation, and presentation in a security operations or threat intelligence context
  • Experience in a management or team lead capacity, managing projects and tasks against tight deadlines
  • Active Secret clearance; Top Secret/SCI eligibility required
Technical & Domain Capabilities
  • Demonstrated experience hunting for APTs and adversary activity using network flow, PCAP, log data, and security sensor telemetry
  • Proficiency with SIEM platforms: search language, query development, alert tuning, dashboard creation, and report building
  • Scripting proficiency in one or more of: Python, R, SQL, PIG, HIVE, or equivalent languages for data analysis and workflow automation
  • Skill in developing algorithms and conducting structured queries to analyze complex data structures at scale
  • Knowledge of MITRE ATT&CK and D3FEND frameworks and their practical application to hunt operations and defensive recommendations
  • Solid understanding of the TCP/IP networking stack and network intrusion detection technologies
  • Experience with complex malware analysis and identification of common encoding techniques including XOR, Base64, ASCII, Unicode, URL encoding, and Uuencode
  • Hands-on experience with EDR solutions for endpoint visibility and threat investigation
  • Experience creating reusable hunt tactics and techniques that can be operationalized across a security program
  • Current knowledge of cyber adversary tactics, trends, and the evolving federal threat landscape
Core Strengths
  • Proactive and intellectually curious — you hunt because you assume the adversary is already in, and you don’t stop until you’ve proved otherwise
  • Strong analytical and data skills; you find signal in noise and can explain what you found and why it matters
  • Effective communicator across audiences — from technical write-ups to executive briefings, your findings land clearly
  • Disciplined operator who builds repeatable processes, documents work thoroughly, and raises the capability of the team around you
Certifications

One certification from each of the following groups is required:

Group 1 — Security Specialty (one required)
  • CISSP Associate, CCSP, SSCP, GCIH, GNFA (GIAC Network Forensic Analyst), or GCIA (GIAC Certified Intrusion Analyst)
Group 2 — DoD 8570 CSSP (one required)
  • Any certification qualifying under the DoD 8570 CSSP Analyst, Infrastructure Support, or Incident Responder categories, or other similar certifications as approved
Nice to Have (Differentiators)
  • Advanced threat hunting certifications: GCTI (GIAC Cyber Threat Intelligence), GREM (GIAC Reverse Engineering Malware), or GCFE/GCFA (GIAC forensics)
  • Experience building or maturing a threat hunting program from the ground up in a federal environment
  • Familiarity with threat intelligence platforms (TIPs) and integrating CTI data into hunt workflows
  • Experience with cloud-native hunting across commercial or GovCloud environments
  • Background in red team or adversary emulation that informs hunt hypothesis development
  • Active TS/SCI clearance

#DICE #LinkedIn

Here at Revolutional we are pleased to have been repeatedly recognized for our outstanding work culture, the innovative work we do, and the employees on our team who make a difference each day. Some of these recognitions include:

  • Recognized as a Top 20 “Best Place to Work in Virginia”
  • Recipient of Department of Labor’s HireVets Gold Medallion
  • Great Place to Work Certification for five years running
  • A Virginia Chamber of Commerce Fantastic 50 company
  • A Northern Virginia Technology Council Tech 100 company
  • Inc. 5000 list of fastest growing companies for eleven years
  • Two-time SBA SBIR Tibbett’s Award winner
  • Virginia Values Veterans (V3) Certification

We recognize that every bit of our success is the result of our teams of hard-working, motivated, and innovative professionals who are proud to call themselves part of the Revolutional family! In addition to competitive compensation, a family-focused culture, and a dynamic, productive work environment, we offer all full-time employees a variety of benefits including, but not limited to

  • Traditional and HSA- eligible medical insurance plans
  • 100% employer-paid dental and vision insurance options
  • 100% employer-sponsored STD, LTD, and life insurance
  • 5% 401(k) company matching
  • Flexible-schedules and teleworking options
  • Paid holidays and PTO Accrual Plans
  • Paid Parental Leave
  • Professional development and career growth opportunities
  • Team and company-wide events, recognition, and appreciation– and so much more!

Revolutional is an Equal Opportunity Employer providing equal employment opportunity to all employees and applicants for employment without regard to race, color, religion, national origin, age, gender, gender identity, sexual orientation, disability, or genetics. Revolutional_does and will take affirmative action to employ and advance in employment individuals with disabilities and protected veterans. To perform the above job successfully, an individual must possess the knowledge, skills, and abilities listed; meet the education and work experience required; and must be able to perform each essential duty and responsibility satisfactorily. Other duties in addition to those listed may be assigned as necessary to meet business needs. Reasonable accommodation will be made to enable an applicant with a disability to successfully apply for and/or perform the essential duties of the job. If you are in need of an accommodation, please contact HR@revolutional.com._

“Know Your Rights: Workplace Discrimination is Illegal” Poster | U.S. Equal Employment Opportunity Commission

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Threat Hunter
Senior Threat Hunter

Revolutional • Washington

On-site
USD 135,000 - 175,000
Medical insurance
Dental and vision insurance
401(k) matching
+2
Senior Threat Hunter Analyst
Senior Threat Hunter Analyst

Revolutional, LLC • United States

Hybrid
USD 125,000 - 150,000
Medical insurance
Dental & vision insurance
401(k) matching
+2
Cyber Intelligence Analyst
Cyber Intelligence Analyst

Revolutional, LLC • United States

Hybrid
USD 90,000 - 130,000
Senior Threat Hunt Analyst
Senior Threat Hunt Analyst

Revolutional, LLC • Washington

On-site
USD 120,000 - 190,000
Health insurance
Dental & vision insurance
401(k) with match
+2
Senior Threat Hunter Analyst
Senior Threat Hunter Analyst

Revolutional • Kansas City (MO)

Hybrid
USD 125,000 - 150,000
Medical insurance
Dental insurance
Vision insurance
+3
Cybersecurity Analyst - Tier 2
Cybersecurity Analyst - Tier 2

Revolutional • Martinsburg (WV)

On-site
USD 85,000 - 130,000
Traditional and HSA- eligible medical
100% employer-paid dental and vision
5% 401(k) company matching
+5
Lead Cyber Threat Intelligence Analyst
Lead Cyber Threat Intelligence Analyst

Revolutional • Suitland (MD)

On-site
USD 130,000 - 180,000
Medical insurance
Dental and vision insurance
401(k) matching
+2
Senior Advisor, Infrastructure & IT Operations (Top Secret)
Senior Advisor, Infrastructure & IT Operations (Top Secret)

Revolutional • Washington

On-site
USD 190,000 - 225,000
Traditional and HSA- eligible medical
100% employer-paid dental and vision
100% employer-sponsored STD, LTD, and
+6
Lead Test Engineer
Lead Test Engineer

Harmonia Holdings Group, LLC • McLean (VA)

Hybrid
USD 140,000 - 180,000
Program Manager
Program Manager

Revolutional, LLC • United States

Hybrid
USD 165,000 - 220,000