Senior Threat Hunter Analyst

Revolutional

Kansas City (MO)

Hybrid

USD 125,000 - 150,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Medical insurance
Dental insurance
Vision insurance
401(k) match
Flexible schedules
Telework

Job summary

Revolutional is seeking a Senior Threat Hunter Analyst to proactively hunt undetected adversary activity across enterprise networks, combining malware analysis, incident response support, and IOC production. You will work with the Cyber Threat Intelligence team to maintain feeds, author finished intelligence products, and contribute to after-action reports with measurable defensive improvements.

The role requires 5+ years in threat hunting or security operations, active Top Secret clearance, and

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience).
  • 5+ years of threat hunting, security operations, or related field required.
  • Active Top Secret clearance required.

Responsibilities

  • Proactively hunt for undetected cyber threats across enterprise networks using network flow, PCAP, log data, endpoint telemetry, and SIEM data; operate ahead of automated detection capabilities.
  • Conduct Computer Network Defense (CND) triage: assess alerts and anomalies, determine threat validity, and prioritize findings for response.
  • Provide analysis support to incident response operations; contribute host and network analysis, malware triage, and attacker TTP reconstruction during active incidents.
  • Perform malware analysis on samples collected during hunts and incidents; identify behavioral indicators, persistence mechanisms, and IOCs for operationalization.
  • Maintain and update threat indicator feeds in coordination with the Cyber Threat Intelligence team; ensure hunt operations are informed by current intelligence.
  • Author IOC reports from open‑source intelligence portals; package findings into finished products suitable for both technical teams and program leadership.
  • Prepare after‑action reports and lessons‑learned documentation following significant hunts and incidents; identify detection gaps and recommend improvements.
  • Produce security event and metric reports for program management; communicate hunt findings, detection trends, and program health in clear, data‑supported terms.
  • Develop and maintain reusable hunt tactics, SIEM queries, and detection logic that improve the program’s long‑term detection capability.
  • Stay current on adversary TTPs, malware families, threat actor trends, and emerging attack techniques relevant to the federal enterprise environment

Skills

Threat hunting
Malware analysis
CND triage
IOC reports
Incident response
OSINT
Threat intel
SIEM
TTP mapping
Python scripting

Education

Bachelor's degree

Tools

SIEM
Malware analysis tools

Job description

Revolutional delivers advanced technology solutions and mission support to federal agencies across civilian, health, and national security environments. We apply modern capabilities, including AI/ML, cloud, cybersecurity, and IT modernization to solve complex challenges, enable faster and more secure operations, and drive measurable mission outcomes.

We are redefining how federal technology gets built and delivered by operating with a product mindset, prioritizing speed, ownership, and execution over bureaucracy.

Senior Threat Hunter Analyst

Location: Washington, DC, Ft. Collins, CO, or Kansas City, MO (remote optional, local preferred)

Terms: Full‑time

Salary: $125‑$150k DOE

Clearance: Active Top Secret required

Travel: 0‑10%

Project Description

This position supports a large‑scale federal security operations program delivering 24/7/365 continuous monitoring, intrusion detection, threat hunting, incident response, and threat intelligence across a complex enterprise network environment. The threat hunting function operates at the leading edge of the program’s defensive posture — finding what automated tools miss before it becomes a confirmed incident.

The core challenge: proactively hunting adversary activity across a large, high‑complexity enterprise network, supporting active incident response, and producing intelligence products that sharpen the program’s detection and response capabilities over time.

Position Description

As a Senior Threat Hunter Analyst at Revolutional, you operate ahead of the threat — proactively hunting for undetected adversary activity across enterprise networks before it surfaces through automated detection. You are a technically deep practitioner who combines hunting tradecraft with malware analysis capability, incident response support, and the discipline to produce IOC reports, after‑action reviews, and security metric reporting that make the program measurably better over time.

You work in close coordination with the Cyber Threat Intelligence team, maintaining threat indicator feeds that keep your hunts current and your findings actionable. You conduct CND triage, support active incidents with analysis, and author finished intelligence products from open‑source portals. Your output reaches both technical peers and program management.

What You Will Own
  • Proactive threat hunting across enterprise network environments for undetected adversary activity
  • Malware analysis in support of hunt findings and incident response
  • CND triage and analysis support for active incident response operations
  • Threat indicator feed maintenance in coordination with the Cyber Threat Intelligence team
  • IOC report authorship from open‑source intelligence portals
  • After‑action and lessons‑learned documentation for significant hunts and incidents
  • Security event and metric reporting for program management
Responsibilities
  • Proactively hunt for undetected cyber threats across enterprise network environments using network flow, PCAP, log data, endpoint telemetry, and SIEM data; operate ahead of automated detection capabilities
  • Conduct Computer Network Defense (CND) triage: assess alerts and anomalies, determine threat validity, and prioritize findings for response or further investigation
  • Provide analysis support to incident response operations; contribute host and network analysis, malware triage, and attacker TTP reconstruction during active incidents
  • Perform malware analysis on samples collected during hunts and incidents; identify behavioral indicators, persistence mechanisms, and IOCs for operationalization
  • Maintain and update threat indicator feeds in coordination with the Cyber Threat Intelligence team; ensure hunt operations are informed by current intelligence
  • Author IOC reports from open‑source intelligence portals; package findings into finished products suitable for both technical teams and program leadership
  • Prepare after‑action reports and lessons‑learned documentation following significant hunts and incidents; identify detection gaps and recommend improvements
  • Produce security event and metric reports for program management; communicate hunt findings, detection trends, and program health in clear, data‑supported terms
  • Develop and maintain reusable hunt tactics, SIEM queries, and detection logic that improve the program’s long‑term detection capability
  • Stay current on adversary TTPs, malware families, threat actor trends, and emerging attack techniques relevant to the federal enterprise environment
What You Bring (Requirements)
Baseline Requirements
  • Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience)
  • 5 or more years of experience in threat hunting, security operations, or a closely related technical discipline
  • Active Top Secret clearance required
Technical & Domain Capabilities
  • Demonstrated experience proactively hunting for adversary activity across enterprise networks using hypothesis‑driven and intelligence‑driven hunt methodologies
  • Hands‑on IDS/IPS experience: signature review, alert triage, anomaly identification, and tuning to reduce noise and improve detection fidelity
  • Proficiency with SIEM platforms: search language, query development, correlation rule creation, dashboard operations, and metric reporting
  • Malware analysis experience including behavioral analysis, static review, IOC extraction, and identification of adversary tooling and techniques
  • Experience conducting CND triage and supporting incident response with technical analysis under operational tempo
  • Experience authoring IOC reports and finished intelligence products from open‑source intelligence (OSINT) portals
  • Experience preparing after‑action reports and lessons‑learned documentation that drive concrete defensive improvements
  • Familiarity with MITRE ATT&CK framework applied to hunt hypothesis development and TTP mapping
  • Current knowledge of adversary TTPs, threat actor trends, and the evolving federal cybersecurity threat landscape
Core Strengths
  • Proactive and analytically driven — you hunt because you assume the adversary is already in, and you don’t stop until the evidence tells you otherwise
  • Technically fluent across hunting, malware analysis, and incident response — you shift between disciplines fluidly as the mission demands
  • Strong written communicator: your IOC reports, after‑actions, and metric reports are clear, accurate, and written for the audience
  • Collaborative partner to threat intelligence and incident response teams — your findings feed the broader program, not just your own queue
Preferred Certifications
  • GCIH (GIAC Certified Incident Handler), GCIA (GIAC Certified Intrusion Analyst), GCTI (GIAC Cyber Threat Intelligence), GREM (GIAC Reverse Engineering Malware), CySA+, or equivalent
Nice to Have (Differentiators)
  • Experience threat hunting in a federal civilian, defense, or intelligence SOC environment
  • Proficiency scripting in Python or equivalent for hunt automation and IOC enrichment workflows
  • Experience with threat intelligence platforms (TIPs) and integrating CTI data into active hunt operations
  • Background in advanced malware reverse engineering or exploit analysis
  • Familiarity with cloud‑native hunting across commercial or GovCloud environments
Benefits
  • Traditional and HSA‑eligible medical insurance plans
  • 100% employer‑paid dental and vision insurance options
  • 100% employer‑sponsored STD, LTD, and life insurance
  • 5% 401(k) company matching
  • Flexible‑schedules and teleworking options
  • Paid holidays and PTO Accrual Plans
  • Paid Parental LeaveProfessional development and career growth opportunities
  • Team and company‑wide events, recognition, and appreciation

To perform the above job successfully, an individual must possess the knowledge, skills, and abilities listed; meet the education and work experience required; and must be able to perform each essential duty and responsibility satisfactorily. Other duties in addition to those listed may be assigned as necessary to meet business needs. Reasonable accommodation will be made to enable an applicant with a disability to successfully apply for and/or perform the essential duties of the job. If you are in need of an accommodation, please contact HR@revolutional.com.

Revolutional is an Equal Opportunity Employer providing equal employment opportunity to all employees and applicants for employment without regard to race, color, religion, national origin, age, gender, gender identity, sexual orientation, disability, or genetics. Revolutional does and will take affirmative action to employ and advance in employment individuals with disabilities and protected veterans.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Threat Hunter
Senior Threat Hunter

Revolutional • Washington

On-site
USD 135,000 - 175,000
Medical insurance
Dental and vision insurance
401(k) matching
+2
Lead Cyber Threat Intelligence Analyst
Lead Cyber Threat Intelligence Analyst

Revolutional • Suitland (MD)

On-site
USD 130,000 - 180,000
Medical insurance
Dental and vision insurance
401(k) matching
+2
Senior Forensic Analyst
Senior Forensic Analyst

Revolutional • Kansas City (MO)

Hybrid
USD 130,000 - 170,000
Flexible schedules
Telework options
Paid holidays & PTO
Lead Cyber Defense Forensics Analyst
Lead Cyber Defense Forensics Analyst

Revolutional • Suitland (MD)

On-site
USD 110,000 - 150,000
Medical insurance
Dental and vision insurance
STD, LTD, and life insurance
+6
SOC Operations Manager
SOC Operations Manager

Revolutional • Kansas City (MO)

Hybrid
USD 150,000 - 190,000
Medical insurance
Dental & Vision
STD/LTD/Life insurance
+6
Program Manager
Program Manager

Revolutional • Kansas City (MO)

Hybrid
USD 165,000 - 220,000
Medical insurance
Dental and vision insurance
401(k) 5% match
+3
Security Operations Center (SOC) Chief
Security Operations Center (SOC) Chief

Revolutional • Suitland (MD)

On-site
USD 175,000 - 235,000
Medical insurance
Dental insurance
Vision insurance
+6
Lead Penetration Tester
Lead Penetration Tester

Revolutional • Kansas City (MO)

On-site
USD 110,000 - 150,000
Medical insurance
Dental/vision insurance
STD/LTD/Life insurance
+5
SOC Watch Officer
SOC Watch Officer

Revolutional • Chandler (AZ)

On-site
USD 130,000 - 160,000
Medical insurance
Dental & vision insurance
401(k) matching
+1
Cybersecurity Analyst - Tier 2
Cybersecurity Analyst - Tier 2

Revolutional • Martinsburg (WV)

On-site
USD 85,000 - 130,000
Traditional and HSA- eligible medical
100% employer-paid dental and vision
5% 401(k) company matching
+5