AOUSC - Threat Hunt Lead
cFocus Software Incorporated
Job Description
Job Description
cFocus Software seeks a Threat Hunt Lead to join our program supporting the Administrative Office of the United States Courts (AOUSC). This position is Hybrid with the onsite location being in Washington, DC. This position requires a Public Trust clearance.
Qualifications:
- Active Public Trust clearance
- B.S. Computer Science, Information Technology, or a related field
- 5+ years within IR in a large SOC (over 5,000 endpoints) with at least 3 years focused on proactive threat hunting or adversary emulation.
- 3+ years of experience with demonstrated proficiency in forming hypothesis, querying large datasets and identifying APT behavior.
- 2+ years’ experience with demonstrated proficiency in scripting languages including Python and PowerShell to develop new tools.
- This role most closely aligns with the NICE work role PD-WRL-006 (Threat Analysis).
- Active OSCP or GXPN certification
- Lead proactive threat hunting operations to identify Advanced Persistent Threats (APT), insider threats, malicious activity, and anomalous behaviors that evade traditional security controls.
- Develop and execute hypothesis-driven threat hunts leveraging threat intelligence, adversary tactics, techniques, and procedures (TTPs), behavioral analytics, and anomalous telemetry.
- Coordinate threat hunt activities within Agile two-week sprint cycles and ensure successful execution of all assigned hunt objectives and deliverables.
- Develop Threat Hunt Execution Plans that define hunt hypotheses, objectives, technical methodologies, required telemetry, and investigative procedures.
- Analyze endpoint, network, cloud, identity, SIEM, EDR, and log telemetry to identify indicators of compromise (IOCs), suspicious activity, and attack patterns.
- Coordinate and escalate confirmed or suspected findings to the Cybersecurity Triage and Incident Response teams in accordance with the Judiciary SOC Incident Response Plan (JSOCIRP).
- Collaborate with Detection Engineering teams to identify and remediate logging, telemetry, detection, or visibility gaps discovered during threat hunting operations.
- Work closely with Cyber Threat Intelligence teams to operationalize intelligence, enrich investigations, and identify emerging threats impacting the Judiciary.
- Conduct advanced analysis of threat actor behaviors, malware campaigns, phishing activity, suspicious infrastructure, and attack trends.
- Develop detailed Threat Hunt Reports documenting hunt objectives, findings, TTPs, queries used, telemetry gaps, identified risks, and recommendations for improved detections.
- Produce executive-level Hunt Sprint Reports summarizing hunt activities, operational impacts, recommendations, and emerging cybersecurity risks.
- Provide real-time investigative support during cybersecurity incidents and high-priority threat investigations.
- Perform analysis utilizing Splunk Enterprise Security, Microsoft Sentinel, Splunk SOAR, CrowdStrike, Qualys, ServiceNow, Jira, and other AO-approved security platforms.
- Support the development and refinement of threat models tailored to Judiciary systems, high-value assets, and mission-critical environments.
- Develop and maintain threat hunting SOPs, playbooks, technical procedures, and investigative methodologies aligned with AO and federal cybersecurity standards.
- Support enterprise security awareness initiatives through threat briefings, technical reporting, and operational presentations.
- Participate in weekly technical meetings, operational reviews, and status briefings with AO leadership and federal stakeholders.
- Provide mentorship, technical guidance, and quality oversight to threat hunters and supporting analysts.
- Support transition-in and transition-out activities, operational readiness, documentation development, and knowledge transfer activities.
- Drive continuous improvement initiatives focused on detection coverage, telemetry enrichment, operational efficiency, and threat hunting maturity.
Powered by JazzHR
lD4K8q96QQ
Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the AOUSC - Threat Hunt Lead in Washington DC vacancy
- ...Position Title Cyber Threat Intelligence & Threat Hunting Lead Position Overview The Cyber Threat Intelligence & Threat Hunting Lead will oversee integrated cyber threat intelligence (CTI), detection engineering, and proactive threat hunting operations supporting...SuggestedFull time
- cFocus Software seeks a Threat Hunt Lead to join our program supporting AOUSC. The role is Hybrid with onsite in Washington, DC, and requires a Public Trust clearance. You will lead threat hunting operations, develop execution plans, and collaborate across intelligence,...Suggested
- ...Position Title Threat Emulation & Readiness Lead / Red Team Lead Position Overview The Threat Emulation & Readiness Lead will oversee adversary... ...behaviors. Coordinate closely with SOC, CTI, Threat Hunt, and Detection Engineering teams. Assess detection and...SuggestedFull time
- cFocus Software Incorporated is seeking a Cyber Threat Intelligence & Threat Hunting Lead to oversee CTI, detection engineering, and proactive threat hunting operations supporting enterprise cyber defense missions. The Lead will drive development of intelligence-driven...Suggested
- ...SecOps Analyst to monitor and respond to threats across endpoints, cloud, and SaaS. You’ll... ...signatures, participate in threat modeling, and lead incident response as needed. As part of... ...mentor junior analysts, perform threat hunting, and communicate findings to stakeholders...Suggested
- ...seeks a Forensic and Malware Lead to join our program supporting... ...of the United States Courts (AOUSC). This position is Hybrid with... ...analysis of advanced persistent threats (APT), ransomware, phishing campaigns... ...investigations and threat hunting operations. Coordinate...Full timeWork at office
- cFocus Software seeks a Blue Team Lead to join our program supporting... ...of the United States Courts (AOUSC). This position is Hybrid with... ...aligned to current cyber threats, adversary tactics, techniques... ...Detection Engineering, Threat Hunting, Incident Response, and Cyber...Full timeWork at office
- ...Position Title Insider Threat Program Lead Position Overview The Insider Threat Lead will design, mature, and oversee insider threat detection, analysis, and investigative support capabilities for a federal enterprise environment. The Lead will integrate user...Full time
- Information International Associates, Inc. is seeking a Cyber Threat Intelligence (CTI) Lead in Alexandria, VA. This role involves providing technical support to a 24x7 cyber program with responsibilities including the development of CTI analysis and incident response....
$145k - $200k
A leading software company in Washington, D.C. seeks a Defensive Security Analyst to safeguard their global operations. The role involves managing SOC systems and developing threat detection strategies. Ideal candidates should have a TS/SCI Clearance and experience in...- ...government program. The ideal candidate will bring strong incident response, malware analysis, and forensics skills, with cloud, SOC, and CIRT experience, and will contribute to threat hunting, reporting, and cross-team coordination. #J-18808-Ljbffr Edgewater Federal SolutionsContract work
- ...Lead Cyber Threat Analyst Evolver Federal is seeking a Lead Cyber Threat Analyst to fulfil a requirement for a potential government client... ...infrastructure. This role focuses on proactive threat hunting, intelligence analysis, and developing strategies to detect and...Flexible hours
$130k - $180k
...prioritizing speed, ownership, and execution over bureaucracy. Lead Cyber Threat Intelligence Analyst Location: Onsite - Government-controlled... ...behavior Coordinate with SOC, incident response, and threat hunting teams to ensure CTI products are operationally relevant and...Full timeWork experience placementFlexible hoursShift work- ...Position Title SOC Operations Lead / Managed Detection & Response (MDR) Lead Position Overview The SOC Operations Lead... ...and incident impact assessments. Coordinate closely with Threat Hunting, CTI, Detection Engineering, and Incident Response teams. Brief...Full time
- ...Strategic Non‑Kinetic Effects Mission Division is seeking a Cyber Threat Intelligence Analyst with deep, cross-disciplinary expertise in... ...engineering.Experience in all-source intelligence, threat hunting, vulnerability analysis, network reverse engineering and network...Work experience placementLocal area
$150k - $165k
...Job Description Job Description Position Title: Threat Intelligence Lead Location: Camp Springs, MD Employment Type: Full‑Time Salary Range: $150,000 - $165,000 Clearance Requirement: Ability to obtain and maintain Top Secret / SCI Position Overview...Full timeImmediate startFlexible hours- cFocus Software seeks a Cybersecurity Shift Lead to join our program supporting the Administrative Office of the United States Courts (AOUSC). This position is Hybrid with the onsite location being in Washington, DC. This position requires a Public Trust clearance....Full timeWork at officeShift work
- ...that our employees are our number one resource. If you are a problem-solving people-person, apply today! Position Title: Lead Cyber Threat Analyst Location: Washington, DC Position Summary The Lead Cyber Threat Analyst serves as the technical and...For contractorsLocal area
- United States Digital Space LLC seeks a Threat Intel Manager to lead the CBRN-E and Advanced Weapons team within Threat Intelligence. You will hire and mentor investigators, steer investigations into misuse of AI for CBRN-E threats, and elevate detection toward threat-...
- Overview The Counter-UAS Emerging Threat & Risk Analysis Team Lead will direct a team responsible for identifying, assessing, and mitigating evolving unmanned aircraft system (UAS) threats to critical infrastructure and national security. This role involves strategic risk...Temporary workFor contractorsLocal areaFlexible hours
- Anthropic is seeking a threat intel manager to build and run the CBRN-E & Advanced Weapons team within Threat Intelligence. This role detects... ...-E threats and for development of advanced weapons. You will lead a team of investigators with deep domain expertise, engage with...Weekend work
$140k - $160k
Constant Associates is seeking an Emerging Threats Portfolio Manager based in Washington, DC. This role involves building and leading a portfolio across national security and complex risk environments. The ideal candidate will have over 10 years of experience supporting...Remote work- Amyx, Inc. is seeking a Team Lead for Counter-UAS Emerging Threat & Risk Analysis in Washington, DC. The role directs a team responsible for identifying, assessing, and mitigating evolving UAS threats to critical infrastructure and national security. The position emphasizes...
$204k - $284k
...user questions, authoring documentation, and delivering training. Lead a team of individuals, set and communicate team priorities that... ...enterprise to improve performance. Drive strategic planning of Threat Intelligence Analysis in support of broader Global Intel Google...Temporary work- Johns Hopkins Applied Physics Laboratory in Laurel, MD, seeks a Strategic Systems Program Protection Analyst to lead threat intelligence applications and program protection for U.S. Nuclear Triad and strategic deterrent systems. You will collaborate with systems engineers...
- ## Senior Lead Insider Threat Investigator (US)Postulerremote type: À distancelocations: Mount Laurel, New Jersey: Remote Charlotte (NC): Remote Port Charlotte (FL)time type: Temps pleinposted on: Publié aujourd'huitime left to apply: Date de fin : 3 juillet 2026 (Il reste...Temporary workWork at officeLocal areaRemote workWork from homeFlexible hours
- ...Center Analyst to support SBA’s enterprise security operations in Washington, DC. The role emphasizes expert threat detection, incident analysis, and leading response efforts within a federal government IT environment. Ideal candidates will have 6+ years in cybersecurity...
- Job Announcement Lead Editor, Emerging Threats About MBN Middle East Broadcasting Networks (MBN) is the premier Arabic-first media organization that connects the Middle East and the United States. The company is in the midst of an exciting digital transformation and looking...
- ...monitor, investigate, contain, and recover from sophisticated threats targeting TikTok's US operations. You will join a high-stakes SOC... ...response and post-incident analysis. Responsibilities include leading technical response actions, performing deep investigations, and...
- ...strategic initiatives. You will provide technical expertise in cyber threat intelligence, security operations, and cyber incident response,... ...for executive audiences through briefings and written products, while leading staff and #J-18808-Ljbffr ARETUM Holdings LLC
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to AOUSC - Threat Hunt Lead. Be the first to apply!


