Talent.com
Cyber Threat Hunt Analyst

Cyber Threat Hunt Analyst

Leidos IncAshburn, VA, United States
job_description.job_card.30_days_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

Description

The U.S. Department of Homeland Security (DHS), Customs and Border Protection (CBP) Security Operations Center (SOC) is a U.S. Government program responsible to prevent, identify, contain and eradicate cyber threats to CBP networks through monitoring, intrusion detection and protective security services to CBP information systems including local area networks / wide area networks (LAN / WAN), commercial Internet connection, public facing websites, wireless, mobile / cellular, cloud, security devices, servers and workstations. The CBP SOC is responsible for the overall security of CBP Enterprise-wide information systems, and collects, investigates, and reports any suspected and confirmed security violations.

Leidos is seeking an experienced Cyber Threat Hunt Analyst to join our team. As a member of this highly technical Cyber Threat Hunt team supporting U.S. Customs and Border Protection (CBP), you will be responsible for in-depth technical analysis of network and endpoint logs & activity, executing various types of cyber threat hunts on various agency assets, escalating findings as deemed appropriate, and authoring technical reports summarizing operations and findings in support of the protection of the customers' systems, networks, and assets.

Primary Responsibilities :

Will conduct cyber threat analysis, identifying mitigation and / or remediation courses of action; developing actionable intelligence used to protect organizational IT assets; and trending cyber threat metrics for leadership situational awareness.

Utilize Threat Intelligence and Threat Models to create threat hypotheses for threat hunts.

Identify, track, and investigate high priority threat campaigns, malicious actors with the interest, capability and Tactics, Techniques, and Procedures (TTPs).

Utilize Cyber Threat Intelligence to execute ad hoc threat hunts on agency assets, networks, and systems to identify threat activity that may evade endpoint detection tools.

Utilize the MITRE ATT&CK framework to understand TTPs of adversaries, threat actors, APTs, and threats targeting the customer agency and organize threat hunts around ATT&CK techniques and sub-techniques.

Responsible for maintaining a comprehensive understanding of the cyber threat landscape, including identifying and analyzing cyber threats actors and / or activities to enhance cybersecurity posture of the organization's IT operating environment.

Prepare and report risk analysis and threat findings to appropriate stakeholders.

Create, recommend, and assist with development of new security content as the result of hunt missions to include signatures, alerts, workflows, and automation.

Coordinate with different teams to improve threat detection, response, and improve overall security posture of the Enterprise.

Plan, scope, and execute Threat Hunt Missions to verify threat hypotheses, deconflict findings, and escalate as necessary.

Proactively and iteratively search through systems and networks to detect advanced threats.

Analyze host, network, and application logs in addition to malware and code.

Will be responsible for developing scripts to support cyber threat detection that outputs results in a variety of formats, such as VB scripts, Python, C++, HTML, XML or other type most appropriate for the task.

Produce high quality technical and non-technical products, briefings, whitepapers, etc., with minimal supervision and emphasis on effective / accurate reporting on product topics.

Maintain the daily battle rhythm for the Cyber Threat Hunt team with an emphasis on adherence to deadlines, attention to detail, and clear / concise communication with the customer and stakeholders.

Will be responsible for :

Implementing defined procedures for remediation or make an informed decision to escalate.

Maintain the daily battle rhythm of threat hunts and Cyber Threat Hunt reporting.

Author technical and non-technical reports and briefings to ensure leadership awareness of findings and observations.

Create daily, weekly, and monthly reports and metrics for products and briefings.

Process technical data from various sources and fuse the data with intelligence reporting to improve the security posture of the customer, as well as manage Threat Hunt tools.

Basic Qualifications :

Possess a minimum of five (5) years of professional experience in incident detection and response, malware analysis, or cyber forensics.

Have a bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or related field with three (3) years of experience in incident detection and response, malware analysis, or cyber forensics.

Have 2+ years recent experience with host-based and network-based security monitoring using cybersecurity capabilities.

Must be experienced developing scripts to support cyber threat detection that outputs results in a variety of formats, such as VB scripts, Python, C++, HTML, XML or other.

Established experience with incident response and SIEM tools, host-based logs, network-based logs, and regex.

Ability to work independently with minimal direction; self-starter / self-motivated.

Must be a US Citizen.

Required certifications :

The candidate should have at minimum ONE of the following certifications :

CompTIA Cyber Security Analyst (CySA+)

CompTIA Linux Network Professional (CLNP)

CompTIA Pentest+

CompTIA Cybersecurity Analyst (CySA+)

GPEN - Penetration Tester

GWAPT - Web Application Penetration Tester

GSNA - System and Network Auditor

GISF - Security Fundamentals

GXPN - Exploit Researcher and Advanced Penetration Tester

GWEB - Web Application Defender

GNFA - Network Forensic Analyst

GMON - Continuous Monitoring Certification

GCTI - Cyber Threat Intelligence

GOSI - Open Source Intelligence

OSCP (Certified Professional)

OSCE (Certified Expert)

OSWP (Wireless Professional)

OSEE (Exploitation Expert)

CCFP - Certified Cyber Forensics Professional

CISSP - Certified Information Systems Security

CEH - Certified Ethical Hacker

CHFI - Computer Hacking Forensic Investigator

LPT - Licensed Penetration Tester

CSA - EC Council Certified SOC Analyst (Previously ECSA - EC-Council Certified Security Analyst)

ENSA - EC-Council Network Security Administrator

ECIH - EC-Council Certified Incident Handler

ECSS - EC-Council Certified Security Specialist

ECES - EC-Council Certified Encryption Specialist

Preferred Qualifications :

A minimum of five (5) years of hands-on experience with experience in the last two (2) years that includes host-based and network-based security monitoring using cybersecurity capabilities.

Previous DOD, IC or Law Enforcement Intelligence or Counterintelligence Training / Experience

Demonstrated experience planning and executing threat hunt missions.

Understanding of complex Enterprise networks to include routing, switching, firewalls, proxies, load balancers.

Working knowledge of common (HTTP, DNS, SMB, etc) networking protocols

Familiarity with operation of both Windows and Linux based systems.

Proficient with scripting languages such as Python or PowerShell

Familiarity with Splunk Search Processing Language (SPL) and / or Elastic Domain Specific Language (DSL)

Clearance :

All Department of Homeland Security CBP SOC employees are required to favorably pass a 5-year (BI) Background Investigation

The candidate must currently possess a Top Secret Clearance with the ability to obtain a Top Secret / SCI Clearance

Come break things (in a good way). Then build them smarter.

We're the tech company everyone calls when things get weird. We don't wear capes (they're a safety hazard), but we do solve high-stakes problems with code, caffeine, and a healthy disregard for "how it's always been done."

Original Posting : August 12, 2025

For U.S. Positions : While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range :

Pay Range $85,150.00 - $153,925.00

The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

#Remote

serp_jobs.job_alerts.create_a_job

Cyber Threat Analyst • Ashburn, VA, United States

Job_description.internal_linking.related_jobs
  • serp_jobs.job_card.promoted
Cyber Security Deception / Threat Hunter

Cyber Security Deception / Threat Hunter

AGR, LLCArlington, VA, US
serp_jobs.job_card.full_time
We are currently seeking an experienced.Senior Cyber Security Deception Engineer / Threat Hunter.Department of State (DoS) Diplomatic Security Cyber Mission (DSCM) program providing leading cyber and...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
Senior Cyber Intrusion Detection Analyst

Senior Cyber Intrusion Detection Analyst

Vets HiredWashington, D.C., District of Columbia, United States
serp_jobs.job_card.full_time
serp_jobs.filters_job_card.quick_apply
A Senior Cyber Intrusion Detection Analyst is needed to provide advanced incident response and monitoring support.This is a hybrid position based in Washington, D. Saturday & Sunday, Friday 11pm7am,...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
  • serp_jobs.job_card.promoted
  • serp_jobs.job_card.new
Threat Hunter

Threat Hunter

VirtualVocationsFairfax, Virginia, United States
serp_jobs.job_card.full_time
A company is looking for a Threat Hunter to proactively identify and mitigate threats using advanced SPL queries in Splunk. Key Responsibilities Develop SPL queries to detect IOCs, anomalies, and ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
  • serp_jobs.job_card.new
Cyber Defense Threat Hunting Analyst

Cyber Defense Threat Hunting Analyst

Resource Management Concepts, Inc.Quantico, VA, US
serp_jobs.job_card.full_time
serp_jobs.filters_job_card.quick_apply
Resource Management Concepts, Inc.RMC) provides high-quality, professional services to government and commercial sectors. Our mission is to deliver exceptional management and technology solutions su...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
  • serp_jobs.job_card.promoted
  • serp_jobs.job_card.new
Cyber Threat Hunter

Cyber Threat Hunter

Leidos IncAshburn, VA, United States
serp_jobs.job_card.full_time
Leidos is seeking a highly motivated and experienced.This role supports the Department of Homeland Security's mission to protect its enterprise-wide information systems from cyber threats through p...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
  • serp_jobs.job_card.promoted
Cyber Network Defense Analyst

Cyber Network Defense Analyst

ManTechHerndon, VA, United States
serp_jobs.job_card.full_time
As a CND Analyst on our team, you will use your expertise in specialized network defense to provide innovative and creative solutions to challenging cyber security problems.You will utilize the lat...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
  • serp_jobs.job_card.promoted
  • serp_jobs.job_card.new
Cyber Security Deception / Threat Hunter (Arlington)

Cyber Security Deception / Threat Hunter (Arlington)

AGR, LLCArlington, VA, United States
serp_jobs.job_card.full_time
We are currently seeking an experienced.Senior Cyber Security Deception Engineer / Threat Hunter.Department of State (DoS) Diplomatic Security Cyber Mission (DSCM) program providing leading cyber and...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
Crypto Threat Analyst

Crypto Threat Analyst

EllipticWashington, Washington DC, US
serp_jobs.job_card.full_time
serp_jobs.filters_job_card.quick_apply
Join a global team of dedicated professionals at the forefront of combating crypto-enabled financial crime.This is a unique opportunity to apply your research and analytical skills as part of a col...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
Counterintelligence Cyber Threat Technical Analyst (TS / SCI)

Counterintelligence Cyber Threat Technical Analyst (TS / SCI)

Xcellent Technology SolutionsSpringfield, VA, US
serp_jobs.job_card.full_time
serp_jobs.filters_job_card.quick_apply
Every day, adversaries attempt to infiltrate systems that hold some of the nation’s most sensitive geospatial and intelligence information. These threats are sophisticated, relentless, and con...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
  • serp_jobs.job_card.promoted
Cyber Security Analyst

Cyber Security Analyst

VirtualVocationsFairfax, Virginia, United States
serp_jobs.job_card.full_time
A company is looking for a Cyber Security Analyst to strengthen security operations and compliance posture.Key Responsibilities Support secure access lifecycle processes and conduct periodic acce...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
Cybersecurity Vulnerability Analyst

Cybersecurity Vulnerability Analyst

Node.DigitalArlington, VA, US
serp_jobs.job_card.full_time
serp_jobs.filters_job_card.quick_apply
Cybersecurity Vulnerability Analyst.Must have an active Top Secret Security Clearance.Government customer to provide cybersecurity vulnerability analysis support to reduce the prevalence and impact...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
  • serp_jobs.job_card.promoted
Insider Threat Program Hunt Team Analyst

Insider Threat Program Hunt Team Analyst

Leidos IncWashington, DC, United States
serp_jobs.job_card.full_time
The Digital Modernization Sector at Leidos currently has an opening for a Hunt Analyst supporting the HEITS Contract as part of the Department of Homeland Security (DHS) Insider Threat Program (ITP...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
Cyber Security Analyst

Cyber Security Analyst

Tactibit TechnologiesSuitland, Maryland, United States, 20746
serp_jobs.job_card.permanent
Tactibit Technologies provides innovative information technology, cybersecurity, and cloud support services to the Federal Government. We support some of the nation's most critical and demanding pro...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
  • serp_jobs.job_card.promoted
Remote Financial Analyst - AI Trainer

Remote Financial Analyst - AI Trainer

Data AnnotationLeesburg, Virginia
serp_jobs.filters.remote
serp_jobs.job_card.full_time +1
We are looking for a finance professional to join our team to train AI models.You will measure the progress of these AI chatbots, evaluate their logic, and solve problems to improve the q...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
  • serp_jobs.job_card.promoted
Principal Cyber Threat Hunter

Principal Cyber Threat Hunter

Leidos IncAdelphi, MD, United States
serp_jobs.job_card.full_time
The Leidos Digital Modernization group has a career opportunity for a.This position will support a large Department of Defense (DOD) Cyber Security Service Providers (CSSP) and is responsible for p...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
  • serp_jobs.job_card.promoted
Cyber Threat Analysis Division Task Lead

Cyber Threat Analysis Division Task Lead

Clearance JobsArlington, VA, US
serp_jobs.job_card.full_time
Seize your opportunity to make a personal impact as a Project / Task Manager supporting our program.GDIT is your place to make meaningful contributions to challenging projects and grow a rewarding ca...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
  • serp_jobs.job_card.promoted
Global Threat Analyst

Global Threat Analyst

GoogleWashington, DC, US
serp_jobs.job_card.full_time
Security is at the core of Google's design and development process : it is built into the DNA of our products.The same is true of our offices. You're an expert who shares our seriousness about securi...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
CI Cyber Threat Technical Analyst (TS / SCI)

CI Cyber Threat Technical Analyst (TS / SCI)

Xcellent Technology SolutionsSpringfield, VA, US
serp_jobs.job_card.full_time
serp_jobs.filters_job_card.quick_apply
Every day, adversaries attempt to infiltrate systems that hold some of the nation’s most sensitive geospatial and intelligence information. These threats are sophisticated, relentless, and con...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days