Threat Hunt Analyst

Phase2 Technology

Colorado

On-site

USD 120,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Phase2 Technology in Colorado is looking for a Threat Hunt Analyst to proactively identify and disrupt advanced threats targeting critical infrastructure. This role is pivotal for supporting federal missions and involves leading threat hunting operations.

The ideal candidate must have 8+ years in cybersecurity, be proficient in tools such as SIEM or EDR, and possess a Top Secret clearance. A Bachelor's degree and GIAC or CISSP certification are required.

Qualifications

  • 8+ years of experience supporting cyber operations in various roles.
  • Experience conducting proactive, hypothesis-driven threat hunts.
  • Ability to analyze endpoint and network data for malicious behavior.

Responsibilities

  • Lead sophisticated threat hunting operations.
  • Translate cyber threat intelligence into actionable hunt hypotheses.
  • Collaborate with engineers and subject matter experts.

Skills

Cyber operations expertise
Incident response
Threat hunting
Detection engineering
Analytical skills
Knowledge of TTPs
Communication skills

Education

Bachelor's degree
GIAC Certification or CISSP

Tools

SIEM tools
EDR platforms
Log analytics tools
Python
PowerShell

Job description

Threat Hunt Analyst

Join a high-impact, mission-driven team operating at the forefront of cyber defense for critical infrastructure. As a Threat Hunter, you will be part of a small, agile group entrusted with proactively identifying and disrupting advanced threats targeting some of the nation's most essential systems.

This role goes beyond traditional detection and response. You will lead and execute sophisticated threat hunting operations, transforming emerging intelligence into actionable hunt missions, engineering novel collection capabilities, and uncovering adversary activity that evades conventional security controls. Working at the intersection of cyber threat intelligence, detection engineering, and operational technology (OT), you will help defend complex, real-world environments where the stakes are tangible and immediate.

You will collaborate closely with system owners, engineers, and OT subject matter experts to design and deploy innovative approaches to visibility and analysis, often in environments where telemetry is limited and adversaries are highly adaptive. Your work will directly support federal missions, contributing to the resilience and security of critical infrastructure sectors.

This is a role for a technically deep, creatively minded operator who thrives in ambiguity, enjoys building new capabilities from the ground up, and is motivated by meaningful, national-level impact.

You Have
  • 8+ years of experience supporting cyber operations in incident response, threat hunting, detection engineering, offensive operations, or cybersecurity and information assurance
  • Experience conducting proactive, hypothesis-driven threat hunts in enterprise or industrial environments
  • Experience mapping activity to frameworks such as MITRE ATT&CK
  • Experience with a query and analysis platform such as SIEM or EDR, or log analytics tools
  • Experience analyzing endpoint, network, and log data to identify malicious or anomalous behavior
  • Knowledge of adversary tactics, techniques, and procedures (TTPs)
  • Ability to translate cyber threat intelligence into actionable hunt hypotheses, operational plans, and detection analytics, design, test, and iterate on data collection strategies in constrained or complex environments, and clearly document findings and brief technical and non-technical audiences
  • Top Secret clearance
  • Bachelor's degree
  • GIAC Certification such as GCFA, GCIH, or GCIA, or CISSP Certification
Nice If You Have
  • Experience working with industrial control systems (ICS), SCADA environments, or other OT networks
  • Experience with the development of custom detection content, signatures, or behavioral analytics beyond out-of-the-box tooling
  • Experience with scripting or programming such as Python or PowerShell, to automate analysis or build custom tooling
  • Experience with the U.S. Intelligence Community and using intelligence to support cyber defensive operations
  • Experience conducting threat hunting in cloud or hybrid environments such as AWS, Azure, or containerized infrastructure
  • Experience with threat emulation or purple teaming
  • Knowledge of OT protocols such as Modbus or DNP3, and visibility challenges unique to industrial environments
  • Knowledge of memory forensics, malware analysis, or reverse engineering
  • Possession of strong written and verbal communication skills
Clearance

Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; Top Secret clearance is required.

Commitment to Non-Discrimination

All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Threat Hunt Analyst
Threat Hunt Analyst

Booz Allen Hamilton • Lakewood (CO)

On-site
USD 99,000 - 225,000
Comprehensive health benefits
Paid leave
Professional development
+1
Threat Hunt Lead
Threat Hunt Lead

Agile Defense, LLC • Reston (VA)

Hybrid
USD 165,000 - 200,000
Threat Hunt Lead
Threat Hunt Lead

Agile Defense • Reston (VA)

Hybrid
USD 165,000 - 200,000
Threat Hunting Engineer
Threat Hunting Engineer

RK Management Consultants, Inc. • Milwaukee (WI)

On-site
USD 70,000 - 90,000
Cyber Hunt Team Leader
Cyber Hunt Team Leader

ECS • Richmond (VA)

Hybrid
USD 140,000 - 160,000
Threat Hunter/Detection Engineer - Tier 3
Threat Hunter/Detection Engineer - Tier 3

Evans & Chambers Technology • Fort Meade (MD)

On-site
USD 130,000 - 150,000
Threat Hunter/Detection Engineer - Tier 3
Threat Hunter/Detection Engineer - Tier 3

Evans & Chambers • Fort Meade (MD)

On-site
USD 130,000 - 150,000
Threat Hunter
Threat Hunter

Jobtailor • Colorado

On-site
USD 120,000 - 160,000
Threat Hunter
Threat Hunter

Ascent360 • Tampa (FL)

On-site
USD 80,000 - 120,000
Senior Threat Hunter Analyst
Senior Threat Hunter Analyst

Revolutional • Kansas City (MO)

Hybrid
USD 125,000 - 150,000
Medical insurance
Dental insurance
Vision insurance
+3