Cybersecurity Threat Hunter II
Invictus International Consulting, LLC Colorado Springs, Colorado, United States
Defense and Space Manufacturing · 201-500 employees
About the role
Independently conduct hypothesis-driven threat hunts across enterprise telemetry to identify malicious or anomalous activity. Document findings, correlate data from multiple security sources, and recommend defensive improvements based on hunt outcomes.
What they look for
Requirements
Requires a bachelor's degree in a technical discipline or 4 years of equivalent experience, plus at least 4 years of relevant professional experience. Candidates must hold an active TS/SCI clearance and a DoD 8570 IAT II or IAM II certification.
Full description
Title: Cybersecurity Threat Hunter II
Location: Colorado Springs, CO
Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph
Job Details:
- Independently conduct hypothesis-driven threat hunts across available enterprise telemetry to identify malicious or anomalous activity not detected by automated controls
- Proactively analyze security telemetry to identify indicators of compromise, anomalous behavior, and adversary activity that has not met an incident threshold or has evaded automated security controls
- Assess and correlate data from multiple sources, including network, endpoint, identity, SIEM, threat intelligence, vulnerability, and other available security data
- Document hunt activity, findings, evidence, and recommended follow-on actions in authorized systems and initiate or support incident-response processes when malicious activity is identified
- Provide relevant findings and trends for SOC operational reporting, significant-activity reporting, and defensive awareness
- Develop hunt hypotheses based on threat intelligence, adversary TTPs, environmental observations, emerging threats, and known detection gaps
- Use MITRE ATT&CK and other threat-informed methodologies to characterize observed behavior and guide analytical pivots
- Identify patterns, relationships, and potential adversary activity across users, hosts, network segments, and time periods
- Recommend new or improved detections, data collection, enrichment, and defensive controls based on hunt outcomes
Requirements:
- Bachelor's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree
- Minimum four (4) years of relevant experience in addition to education level
- Hands-on experience with threat hunting, security analysis, incident investigation, threat intelligence analysis, or comparable proactive cyber defense work
- Working knowledge of adversary TTPs, MITRE ATT&CK, network and endpoint telemetry, and analytical search techniques
- Experience using SIEM, network-security monitoring, endpoint telemetry, or other large-scale security data sources
- Must possess current DoD 8570 IAT II or IAM II certification
- Experience working in a DoD or IC environment
- Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph
Equal Opportunity Employer/Veteran/Disabled
Similar roles
-
Senior Cybersecurity Analyst
Orbia Bogota, Capital District, RAP (Especial) Central, Colombia
-
CyberSecurity - Interns
Auctane Wrocław, Lower Silesian Voivodeship, Poland
-
Senior Manager Cybersecurity
Sia Brussels, Brussels-Capital, Belgium
-
Senior Consultant in Cybersecurity
Sia Antwerp, Antwerp, Belgium
-
Senior Security Engineer, AI/ML, National Security, Public Sector
Google Washington, District of Columbia, United States · $174K–$252K/yr
-
Pre-Sales Engineer, Cybersecurity
Hewlett Packard Enterprise Washington, District of Columbia, United States · $146K–$343K/yr