Cybersecurity Analyst, Threat Hunter
Skills
About the role
Cybersecurity Analyst, Threat Hunter
Location: Bethesda, MD (Hybrid; On-site as Required)
Clearance: Tier 2 Public Trust (Required)
Employment Type: Full-Time
Position Summary
Digital Global Connectors (DGC) is seeking an experienced Cybersecurity Analyst – Tier 3 (Threat Hunter) to support a Federal information security program. The Tier 3 Threat Hunter is responsible for proactively identifying advanced threats, uncovering malicious activity that has evaded traditional security controls, and improving the organization's overall cyber defense capabilities through advanced threat hunting, behavioral analytics, and detection engineering.
This position conducts hypothesis-driven threat hunting, analyzes attacker tactics, techniques, and procedures (TTPs), develops advanced detection methodologies, and collaborates with Security Operations Center (SOC) personnel, Incident Responders, Threat Intelligence Analysts, Security Engineers, and ISSOs to strengthen enterprise security operations and reduce organizational cyber risk.
The successful candidate will possess extensive experience detecting sophisticated cyber threats, performing advanced threat hunting, and applying intelligence-driven methodologies to identify adversary activity across enterprise environments.
Essential Duties and Responsibilities:
Threat Hunting Operations
Conduct proactive threat hunting across enterprise networks, endpoints, cloud environments, and information systems.
Develop hypothesis-driven hunting campaigns based on threat intelligence, emerging attack trends, and organizational risk.
Identify indicators of compromise (IOCs), indicators of attack (IOAs), and anomalous system behavior.
Detect malicious activity that bypasses traditional security controls.
Validate findings and coordinate response activities with Incident Response personnel.
Continuously improve threat hunting methodologies and operational effectiveness.
Advanced Threat Analysis
Analyze attacker tactics, techniques, and procedures (TTPs).
Correlate data across multiple security platforms to identify sophisticated attack campaigns.
Evaluate suspicious user activity, authentication anomalies, privilege escalation, persistence mechanisms, and lateral movement.
Identify advanced persistent threats (APTs), insider threats, and emerging attack patterns.
Develop recommendations to improve organizational cyber resilience.
Detection Engineering
Design, develop, and optimize advanced detection logic.
Create and refine SIEM detection rules, behavioral analytics, correlation searches, and custom alerts.
Reduce false positives while improving detection fidelity.
Develop threat detection use cases aligned with known adversary techniques.
Validate detection effectiveness through testing and simulation.
Support continuous improvement of enterprise detection capabilities.
Threat Intelligence Integration
Incorporate internal and external threat intelligence into hunting operations.
Analyze intelligence reports to identify threats relevant to the enterprise.
Map adversary behaviors to organizational assets and risks.
Correlate threat intelligence with enterprise telemetry.
Collaborate with Threat Intelligence Analysts to operationalize intelligence.
Recommend defensive measures based on intelligence findings.
Security Tool Operations
Utilize enterprise security technologies including:
Microsoft Sentinel
Splunk Enterprise Security
Microsoft Defender XDR
Microsoft Defender for Endpoint
Microsoft Defender for Identity
Microsoft Defender for Cloud
CrowdStrike Falcon
Palo Alto Cortex XDR
Microsoft Defender for Office 365
Velociraptor
Sysmon
Security Information and Event Management (SIEM)
Endpoint Detection and Response (EDR)
Extended Detection and Response (XDR)
User and Entity Behavior Analytics (UEBA)
Develop and optimize detection capabilities utilizing these technologies.
Threat Hunting Automation
Develop scripts and automation to improve threat hunting efficiency.
Automate repetitive investigative tasks where appropriate.
Create reusable hunting playbooks and workflows.
Improve data collection and enrichment processes.
Support Security Orchestration, Automation, and Response (SOAR) initiatives.
Recommend automation opportunities across cybersecurity operations.
Incident Support
Support Tier 2 Incident Responders during complex cybersecurity investigations.
Assist in identifying attack scope, persistence mechanisms, and attacker objectives.
Provide advanced technical expertise during incident response activities.
Recommend containment, eradication, and recovery strategies.
Validate remediation activities following incident resolution.
Reporting and Documentation
Develop and maintain:
Threat Hunting Reports
Threat Assessments
Detection Use Cases
Threat Intelligence Summaries
Hunting Playbooks
Executive Briefings
Adversary Profiles
Hunting Metrics
Lessons Learned
Standard Operating Procedures
Ensure documentation accurately reflects technical findings and supports operational decision-making.
Collaboration
Coordinate with Tier 1 SOC Analysts, Tier 2 Incident Responders, Threat Intelligence Analysts, Security Engineers, Digital Forensics Analysts, ISSOs, and Government stakeholders.
Participate in cyber defense working groups and operational planning sessions.
Mentor junior analysts in threat hunting methodologies.
Present technical findings to both technical and executive audiences.
Support enterprise cybersecurity exercises and adversary simulations.
Continuous Improvement
Monitor emerging cyber threats, adversary tradecraft, and evolving attack techniques.
Evaluate new threat hunting technologies and methodologies.
Recommend enhancements to enterprise detection and monitoring capabilities.
Participate in purple team exercises and detection validation activities.
Maintain professional certifications and technical expertise in advanced cyber defense operations.
Minimum Qualifications
Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, Digital Forensics, or a related discipline.
Minimum six (6) years of experience supporting cybersecurity operations, threat hunting, cyber defense, or incident response.
Experience conducting proactive threat hunting within enterprise environments.
Experience utilizing SIEM, EDR, XDR, and behavioral analytics platforms.
Strong understanding of attacker tactics, techniques, and procedures (TTPs).
Experience analyzing Windows, Linux, cloud, and network security telemetry.
Experience with scripting languages such as PowerShell or Python.
Strong analytical, investigative, communication, and documentation skills.
U.S. Citizenship required.
Ability to obtain and maintain a Tier 2 Public Trust.
Preferred Qualifications
Master's degree in Cybersecurity, Computer Science, Information Assurance, or a related discipline.
Experience supporting a Federal civilian agency.
Experience utilizing the MITRE ATT&CK Framework for threat hunting and detection engineering.
Experience supporting Microsoft Azure, Microsoft 365, or AWS security operations.
GIAC Cyber Threat Intelligence (GCTI)
GIAC Certified Intrusion Analyst (GCIA)
GIAC Certified Incident Handler (GCIH)
CompTIA CySA+
Microsoft Certified: Security Operations Analyst Associate (SC-200)
Certified Information Systems Security Professional (CISSP) (preferred)
Knowledge, Skills, and Abilities
Threat Hunting
Detection Engineering
Threat Intelligence
Adversary Emulation
MITRE ATT&CK Framework
Microsoft Sentinel
Splunk Enterprise Security
Microsoft Defender XDR
Microsoft Defender for Endpoint
Microsoft Defender for Identity
Microsoft Defender for Cloud
Security Information and Event Management (SIEM)
Endpoint Detection and Response (EDR)
Extended Detection and Response (XDR)
User and Entity Behavior Analytics (UEBA)
Windows Security
Linux Security
Cloud Security
Network Security
Threat Analytics
Malware Identification
Behavioral Analysis
PowerShell
Python
Log Analysis
Kusto Query Language (KQL)
Microsoft Office Suite
ServiceNow
Jira
Security Requirements
Ability to successfully obtain and maintain a Tier 2 Public Trust investigation.
Compliance with all applicable Federal security, privacy, ethics, and information assurance training requirements before receiving system access.
Ability to support advanced cyber defense operations, incident response activities, scheduled maintenance windows, continuity of operations (COOP), and surge support as required.
Must maintain strict confidentiality while handling sensitive threat intelligence, investigative findings, enterprise telemetry, and Federal information systems.
Ability to independently identify sophisticated cyber threats, develop advanced detection methodologies, and collaborate with Government stakeholders and cybersecurity teams to strengthen enterprise defensive capabilities through proactive threat hunting and continuous operational improvement.
Questions about this role
Want AI Applyd to auto-apply to roles like this?
We tailor your resume per posting, fill the forms, and track replies for you.