Threat Hunter

Strategic Operational Solutions, Inc

Fort Bragg (CA)

On-site

USD 120,000 - 165,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Strategic Operational Solutions (STOPSO) seeks a Threat Hunter to support USARC's DCOMSS program at Fort Bragg, NC. You will hunt adversaries using hypothesis-driven methods, analyze telemetry, and develop detections to support Blue Team and CTI operations.

Candidate must have DoD cyber qualifications and TS/SCI clearance, with strong experience in SIEM/EDR, CTI, and incident response. On-site duties and potential travel are involved; STOPSO is an Equal Opportunity Employer.

Qualifications

  • 3+ years of documented relevant threat hunting, intrusion analysis, or CTI integration experience.
  • Proficiency with DoD cyber workforce framework qualifications and relevant certifications.
  • Experience with DoD or enterprise IT environments and mission tooling is preferred.

Responsibilities

  • Develop hunt hypotheses from adversary tactics, intelligence, indicators, and telemetry gaps.
  • Search SIEM, EDR, NetFlow, packet data, host telemetry for complex intrusion activity.
  • Analyze findings, distinguish threats from benign activity, and escalate for incident response.
  • Develop and validate correlation rules, signatures, and host-based detections with stakeholders.
  • Document hunt objectives, methods, data sources, evidence, and gaps.
  • Coordinate indicator packages and lessons learned with CTI and Blue Team.
  • Perform other duties as assigned consistent with responsibilities and clearance.

Skills

Threat hunting
Intrusion analysis
MITRE ATT&CK
Cyber threat intelligence
Detection engineering
SIEM
EDR
NetFlow
Packet capture
YARA
Snort
Suricata

Education

DCWF 511 Advanced
DCWF 171 Intermediate
DoDM 8140.03 qualification requirements

Tools

SIEM
EDR
NetFlow
Packet capture
YARA
Snort
Suricata

Job description

Position Summary

Strategic Operational Solutions (STOPSO) is seeking a Threat Hunter to support the U.S. Army Reserve Command (USARC) Defensive Cyberspace Operations Mission Support Services (DCOMSS) program at Fort Bragg, North Carolina. Find adversary activity through hypothesis-driven hunts that combine defensive telemetry and cyber threat intelligence. The Threat Hunter develops findings and detection improvements for Blue Team and CTI operations.

Essential Duties and Responsibilities
  • · Develop hunt hypotheses from adversary tactics, intelligence, indicators, and observed telemetry gaps.
  • · Search SIEM, EDR, NetFlow, packet, host, authentication, and CTI data for complex intrusion activity.
  • · Analyze findings, distinguish benign behavior from threats, and elevate actionable activity for incident response.
  • · Develop and validate correlation rules, signatures, and host-based detections with authorized sensor stakeholders.
  • · Document hunt objectives, methods, data sources, evidence, coverage gaps, and recommended actions.
  • · Coordinate indicator packages and lessons learned with CTI, Blue Team, and exercise personnel.
  • · Perform other duties as assigned consistent with the position's responsibilities, qualifications, clearance, and authorized scope.
Required Qualifications
Education and Experience
  • · Minimum 3 years of documented relevant experience. Relevant threat hunting, intrusion analysis, detection development, SIEM/network analysis, and CTI integration experience.
  • · DoD Cyber Workforce Framework (DCWF) 511, Cyber Defense Analyst, Advanced proficiency, and DCWF 171, Cyber Threat Intelligence Analyst, Intermediate proficiency.
  • · Meet DoDM 8140.03 qualification requirements for every assigned work role and proficiency through an approved education, training, certification, or authorized experience route before independent cyber work. Document work-role appointment and qualification; maintain required residential qualification and continuing learning. A higher-level approved option may qualify the same role at a lower level.
  • · Current matrix-listed certification options for 511 Advanced: CBROPS, CFR, CySA+, GCFA, GCIA, GICSP. The additional 171 Intermediate intelligence qualification must be verified under the Government-approved criteria.
Knowledge, Skills and Abilities
  • · Demonstrated knowledge of Threat hunting, intrusion analysis, MITRE ATT&CK, adversary TTPs, cyber threat intelligence, and detection engineering.
  • · Proficiency with SIEM, EDR, NetFlow, packet capture, YARA, Snort or Suricata, and host telemetry appropriate to assigned duties and approved access.
  • · Ability to produce accurate records, explain findings and decisions, and follow approved procedures and security requirements.
  • · Strong written and verbal communication skills and sound judgment when coordinating with technical staff and Government stakeholders.
  • · Strong organizational skills, confidentiality, and ability to work independently and collaboratively in a mission-focused environment.
Preferred Qualifications
  • · Experience hunting across classified DoD cyber defense environments.
  • · Relevant DoD or enterprise IT experience with mission tooling and operational reporting.
Security Clearance

Active TS/SCI clearance and ability to maintain required SCI indoctrination and assigned system access. U.S. citizenship is required.

Supervisory Responsibilities

No formal supervisory responsibilities; provides technical findings and detection guidance.

Work Environment and Physical Requirements

Work is primarily performed on site in a secure Government facility using computer systems and standard office equipment. The employee must be able to perform sustained computer-based analysis or coordination, communicate effectively, and support operational activities outside standard business hours when assigned. Mission-essential watch roles may include shifts, weekends, and holidays.

Reasonable accommodations may be made to enable qualified individuals with disabilities to perform the essential functions of the position.

Travel

Occasional local, CONUS, or OCONUS travel may be required for authorized mission activities, exercises, assessments, or conferences.

Equal Employment Opportunity

STOPSO is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, veteran status, genetic information, or any other characteristic protected by applicable federal, state, or local law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Threat Hunter
Threat Hunter

Strategic Operational Solutions, Inc • Fort Bragg (NC)

On-site
USD 110,000 - 140,000
Senior Threat Hunter: DoD Cyber Defense & CTI Ops
Senior Threat Hunter: DoD Cyber Defense & CTI Ops

Strategic Operational Solutions, Inc • Fort Bragg (CA)

On-site
USD 120,000 - 165,000
SOC Tier 3 and Incident Response Lead
SOC Tier 3 and Incident Response Lead

Strategic Operational Solutions, Inc • Fort Bragg (NC)

On-site
USD 120,000 - 170,000
Threat Hunter: Hypothesis-Driven Cyber Defense & CTI
Threat Hunter: Hypothesis-Driven Cyber Defense & CTI

Strategic Operational Solutions, Inc • Fort Bragg (NC)

On-site
USD 110,000 - 140,000
Senior Cybersecurity Threat Hunter III
Senior Cybersecurity Threat Hunter III

Invictus International Consulting, LLC • Colorado Springs (CO)

On-site
USD 158,000 - 193,000
Senior Cybersecurity Threat Hunter III
Senior Cybersecurity Threat Hunter III

Invictus International • Alexandria (VA)

On-site
USD 120,000 - 180,000
SOC Tier Two Analyst
SOC Tier Two Analyst

Strategic Operational Solutions, Inc • Fort Bragg (NC)

On-site
USD 85,000 - 125,000
Senior Cybersecurity Threat Hunter III
Senior Cybersecurity Threat Hunter III

Invictus International • Colorado Springs (CO)

On-site
USD 130,000 - 190,000
Senior Cybersecurity Threat Hunter III
Senior Cybersecurity Threat Hunter III

invictusic • Alexandria (VA)

On-site
USD 120,000 - 160,000
Senior Cybersecurity Threat Hunter III
Senior Cybersecurity Threat Hunter III

Invictus International Consulting, LLC. • Colorado Springs (CO)

On-site
USD 120,000 - 170,000