Threat Hunter, FedCloud (Remote)
$85,000–$120,000 year
RemoteUnited States
Job Summary
Conduct advanced threat hunting operations across client environments to analyze sophisticated threat actor activities and identify intrusions within government cloud infrastructure. Develop and implement new detection methodologies while communicating findings to both technical and executive stakeholders. Contribute to threat intelligence and detection engineering initiatives to enhance the Falcon platform's capabilities against advanced persistent threats. This role requires experience with network/host-based intrusion analysis, digital forensics, and AI technologies to streamline workflows, and involves a night shift schedule from Tuesday through Friday (23:00–09:00 ET).
Required Qualifications
- Bachelor's degree in relevant field or related work experience
- Strong proficiency in English (written and verbal)
- Demonstrated experience in network/host-based intrusion analysis, digital forensics, or malware analysis
- Comprehensive understanding of Windows, MacOS, and Linux operating systems
- Programming/scripting knowledge, particularly Python or Go
- Understanding of administrative tools and living-off-the-land techniques
- Familiarity with MITRE ATT&CK framework and adversary techniques
- Ability to communicate complex technical concepts to varied audiences
- Proven experience utilizing AI technologies to enhance decision-making, streamline workflows and processes, improve efficiency and drive business outcomes
- Willingness to undergo government required background checks and fingerprinting
- US Citizens and Green Card Holders
- Night shift schedule (Tuesday - Friday 23:00-09:00 ET)
- This role may require the candidate to periodically undergo and pass alcohol and/or drug test(s) during the course of employment
- This role will require the candidate to periodically undergo and pass additional background and fingerprint check(s) consistent with government customer requirements
Desired Qualifications
- Advanced knowledge of Linux and MacOS environments
- Hands-on experience with eCrime and nation-state threat actors
- SOC or incident response experience
- Expertise with logging platforms (LogScale, NGSIEM, Splunk, Kibana)
- Experience with Cloud technologies, preferable related to threat hunting and/or incident response (AWS, Azure, GCP)
- Published security research (conferences, blogs, articles)
- Experience with cloud security fundamentals
- Demonstrated track record of security research and emerging threats analysis
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.