Cybersecurity Analyst, Threat Hunter

Digital Global Connectors

McLean, UShybridPosted Jul 28, 2026
Posting intelligenceActively listed

Skills

hypothesispythonazurejiraaws

About the role

Cybersecurity Analyst, Threat Hunter

Location: Bethesda, MD (Hybrid; On-site as Required)

Clearance: Tier 2 Public Trust (Required)

Employment Type: Full-Time

Position Summary

Digital Global Connectors (DGC) is seeking an experienced Cybersecurity Analyst – Tier 3 (Threat Hunter) to support a Federal information security program. The Tier 3 Threat Hunter is responsible for proactively identifying advanced threats, uncovering malicious activity that has evaded traditional security controls, and improving the organization's overall cyber defense capabilities through advanced threat hunting, behavioral analytics, and detection engineering.

This position conducts hypothesis-driven threat hunting, analyzes attacker tactics, techniques, and procedures (TTPs), develops advanced detection methodologies, and collaborates with Security Operations Center (SOC) personnel, Incident Responders, Threat Intelligence Analysts, Security Engineers, and ISSOs to strengthen enterprise security operations and reduce organizational cyber risk.

The successful candidate will possess extensive experience detecting sophisticated cyber threats, performing advanced threat hunting, and applying intelligence-driven methodologies to identify adversary activity across enterprise environments.

Essential Duties and Responsibilities:

Threat Hunting Operations

Conduct proactive threat hunting across enterprise networks, endpoints, cloud environments, and information systems.

Develop hypothesis-driven hunting campaigns based on threat intelligence, emerging attack trends, and organizational risk.

Identify indicators of compromise (IOCs), indicators of attack (IOAs), and anomalous system behavior.

Detect malicious activity that bypasses traditional security controls.

Validate findings and coordinate response activities with Incident Response personnel.

Continuously improve threat hunting methodologies and operational effectiveness.

Advanced Threat Analysis

Analyze attacker tactics, techniques, and procedures (TTPs).

Correlate data across multiple security platforms to identify sophisticated attack campaigns.

Evaluate suspicious user activity, authentication anomalies, privilege escalation, persistence mechanisms, and lateral movement.

Identify advanced persistent threats (APTs), insider threats, and emerging attack patterns.

Develop recommendations to improve organizational cyber resilience.

Detection Engineering

Design, develop, and optimize advanced detection logic.

Create and refine SIEM detection rules, behavioral analytics, correlation searches, and custom alerts.

Reduce false positives while improving detection fidelity.

Develop threat detection use cases aligned with known adversary techniques.

Validate detection effectiveness through testing and simulation.

Support continuous improvement of enterprise detection capabilities.

Threat Intelligence Integration

Incorporate internal and external threat intelligence into hunting operations.

Analyze intelligence reports to identify threats relevant to the enterprise.

Map adversary behaviors to organizational assets and risks.

Correlate threat intelligence with enterprise telemetry.

Collaborate with Threat Intelligence Analysts to operationalize intelligence.

Recommend defensive measures based on intelligence findings.

Security Tool Operations

Utilize enterprise security technologies including:

Microsoft Sentinel

Splunk Enterprise Security

Microsoft Defender XDR

Microsoft Defender for Endpoint

Microsoft Defender for Identity

Microsoft Defender for Cloud

CrowdStrike Falcon

Palo Alto Cortex XDR

Microsoft Defender for Office 365

Velociraptor

Sysmon

Security Information and Event Management (SIEM)

Endpoint Detection and Response (EDR)

Extended Detection and Response (XDR)

User and Entity Behavior Analytics (UEBA)

Develop and optimize detection capabilities utilizing these technologies.

Threat Hunting Automation

Develop scripts and automation to improve threat hunting efficiency.

Automate repetitive investigative tasks where appropriate.

Create reusable hunting playbooks and workflows.

Improve data collection and enrichment processes.

Support Security Orchestration, Automation, and Response (SOAR) initiatives.

Recommend automation opportunities across cybersecurity operations.

Incident Support

Support Tier 2 Incident Responders during complex cybersecurity investigations.

Assist in identifying attack scope, persistence mechanisms, and attacker objectives.

Provide advanced technical expertise during incident response activities.

Recommend containment, eradication, and recovery strategies.

Validate remediation activities following incident resolution.

Reporting and Documentation

Develop and maintain:

Threat Hunting Reports

Threat Assessments

Detection Use Cases

Threat Intelligence Summaries

Hunting Playbooks

Executive Briefings

Adversary Profiles

Hunting Metrics

Lessons Learned

Standard Operating Procedures

Ensure documentation accurately reflects technical findings and supports operational decision-making.

Collaboration

Coordinate with Tier 1 SOC Analysts, Tier 2 Incident Responders, Threat Intelligence Analysts, Security Engineers, Digital Forensics Analysts, ISSOs, and Government stakeholders.

Participate in cyber defense working groups and operational planning sessions.

Mentor junior analysts in threat hunting methodologies.

Present technical findings to both technical and executive audiences.

Support enterprise cybersecurity exercises and adversary simulations.

Continuous Improvement

Monitor emerging cyber threats, adversary tradecraft, and evolving attack techniques.

Evaluate new threat hunting technologies and methodologies.

Recommend enhancements to enterprise detection and monitoring capabilities.

Participate in purple team exercises and detection validation activities.

Maintain professional certifications and technical expertise in advanced cyber defense operations.

Minimum Qualifications

Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, Digital Forensics, or a related discipline.

Minimum six (6) years of experience supporting cybersecurity operations, threat hunting, cyber defense, or incident response.

Experience conducting proactive threat hunting within enterprise environments.

Experience utilizing SIEM, EDR, XDR, and behavioral analytics platforms.

Strong understanding of attacker tactics, techniques, and procedures (TTPs).

Experience analyzing Windows, Linux, cloud, and network security telemetry.

Experience with scripting languages such as PowerShell or Python.

Strong analytical, investigative, communication, and documentation skills.

U.S. Citizenship required.

Ability to obtain and maintain a Tier 2 Public Trust.

Preferred Qualifications

Master's degree in Cybersecurity, Computer Science, Information Assurance, or a related discipline.

Experience supporting a Federal civilian agency.

Experience utilizing the MITRE ATT&CK Framework for threat hunting and detection engineering.

Experience supporting Microsoft Azure, Microsoft 365, or AWS security operations.

GIAC Cyber Threat Intelligence (GCTI)

GIAC Certified Intrusion Analyst (GCIA)

GIAC Certified Incident Handler (GCIH)

CompTIA CySA+

Microsoft Certified: Security Operations Analyst Associate (SC-200)

Certified Information Systems Security Professional (CISSP) (preferred)

Knowledge, Skills, and Abilities

Threat Hunting

Detection Engineering

Threat Intelligence

Adversary Emulation

MITRE ATT&CK Framework

Microsoft Sentinel

Splunk Enterprise Security

Microsoft Defender XDR

Microsoft Defender for Endpoint

Microsoft Defender for Identity

Microsoft Defender for Cloud

Security Information and Event Management (SIEM)

Endpoint Detection and Response (EDR)

Extended Detection and Response (XDR)

User and Entity Behavior Analytics (UEBA)

Windows Security

Linux Security

Cloud Security

Network Security

Threat Analytics

Malware Identification

Behavioral Analysis

PowerShell

Python

Log Analysis

Kusto Query Language (KQL)

Microsoft Office Suite

ServiceNow

Jira

Security Requirements

Ability to successfully obtain and maintain a Tier 2 Public Trust investigation.

Compliance with all applicable Federal security, privacy, ethics, and information assurance training requirements before receiving system access.

Ability to support advanced cyber defense operations, incident response activities, scheduled maintenance windows, continuity of operations (COOP), and surge support as required.

Must maintain strict confidentiality while handling sensitive threat intelligence, investigative findings, enterprise telemetry, and Federal information systems.

Ability to independently identify sophisticated cyber threats, develop advanced detection methodologies, and collaborate with Government stakeholders and cybersecurity teams to strengthen enterprise defensive capabilities through proactive threat hunting and continuous operational improvement.

Questions about this role

Click "Apply with AI Applyd" above and you are done. Your resume is rewritten for this advert, the screening questions are answered, and it is submitted on Digital Global Connectors's own hiring system. No retyping your history, no fourteen tabs, no evening lost.

Compensation for SOC Analyst roles in United States varies widely by seniority, employer size, and remote vs onsite arrangement. Check the salary range on this listing when published, or browse our SOC Analyst hub for United States medians across recent openings.

You never touch the form - the application is filled and submitted for you on Digital Global Connectors's own hiring system. It is not marked sent when we press submit. It is marked sent when a confirmation from their system arrives at the address we apply with, and your dashboard shows which stage each application is at until then.

Twelve applicant tracking systems have a real apply path: Workday, Greenhouse, Lever, Ashby, Workable, iCIMS, Personio, Recruitee, Teamtailor, Rippling, Breezy and SmartRecruiters. Your application goes in on the employer's own hiring system, never into an aggregator queue.

Want AI Applyd to auto-apply to roles like this?

We tailor your resume per posting, fill the forms, and track replies for you.