cFocus Software logo
cFocus SoftwarePosted 1 month ago

Cyber Threat Hunter

HybridWashington, District of Columbia, United States or Washington, United States

Full TimeMid LevelSmallInformation Management

Job Summary

Conduct hypothesis-based threat hunts across cloud and non-cloud environments using Splunk, Microsoft Sentinel, and custom scripts to identify anomalies within the judicial fabric. Respond to government technical requests via ITSM tickets, triage malware events, and perform incident response services for Priority 1 security events with 4-hour response times. Configure and troubleshoot EDR agents like CrowdStrike, analyze network traffic with NetScout, and document findings in Agile Scrum standups. Plan iterative TTP hunts, propose automated detection logic, and create SOPs and playbooks. Track incidents from detection through resolution and submit weekly activity reports to the program manager.

Required Qualifications

  • 5+ years of experience performing threat hunts & incident response activities for cloud-based and non-cloud-based environments
  • 5+ years of experience performing hypothesis-based threat hunt & incident response utilizing Splunk Enterprise Security
  • 5+ years of using Splunk to create queries and look up tables
  • 5+ years of experience collecting and analyzing data from compromised systems using EDR agents (e.g. CrowdStrike) and custom scripts (e.g. Sysmon & Auditd)
  • 5+ years of experience with the following threat hunting tools: Microsoft Sentinel for threat hunting within Microsoft Azure
  • 5+ years of experience with the following threat hunting tools: Tenable Nessus and SYN/ACK for vulnerability management
  • 5+ years of experience with the following threat hunting tools: NetScout for analyzing network traffic flow
  • 5+ years of experience with the following threat hunting tools: SPUR.us enrichment of addresses
  • 5+ years of experience with the following threat hunting tools: Mandiant Threat intel feeds
  • Must be able to work 80% (Monday thru Thursday) onsite at AOUSC office in Washington, DC

Desired Qualifications

  • One of the following certifications: GIAC Certified Intrusion Analyst (GCIA)
  • One of the following certifications: GIAC Certified Incident Handler (GCIH)
  • One of the following certifications: GIAC Continuous Monitoring (GMON)
  • One of the following certifications: GIAC Defending Advanced Threats (GDAT)
  • Splunk Core Power User

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce