Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Engineer III, Cyber Threat Hunter

$128k - $139k

College Board

College Board - Technology - Cyber Security Operations Team

Location: 1) This is a fully remote role. Candidates who live near CB offices have the option of being fully remote or hybrid (Tuesday and Wednesday in office).


Type: This is a full-time position


About the Team

The Cyber Security Operations team is critical to the strategic foundation of our products, most notably the secure delivery of our Digital SAT and AP programs. We are a highly motivated group of cyber security experts who take a proactive approach to ensuring a strong security posture. We partner across the organization to mature our Threat Management and Incident Response procedures and are constantly seeking and experimenting with new technologies. We are currently using a variety of cutting-edge tools that provide comprehensive cyber security operations for the College Board's critical infrastructure in support of the College Board's mission to connect students to college success and opportunity. College Board is committed to creating an inclusive environment where all team members feel valued, respected, and supported in their work. We welcome individuals from diverse backgrounds and experiences to join our team and contribute to our ongoing success.


About the Opportunity

As a Cyber Threat Hunter, you will play a hands-on role in defending the cloud and enterprise environments that power the Digital SAT, AP, and other high-stakes programs. You will work in an AWS-heavy environment at national scale, where detection quality, investigation speed, and clear documentation directly support exam integrity and student trust.


This role exists to strengthen our detection and response capabilities. You will build and improve SIEM detections, execute structured threat hunts, and help validate controls through purple team exercises. You will contribute to incident investigations, refine response playbooks, and use automation to make our workflows faster and more reliable.


You will partner closely with engineers, architects, and product teams to close visibility gaps and reduce risk in practical, measurable ways. Success in this role means fewer blind spots, higher fidelity alerts, and a cyber defense program that is proactive rather than reactive.


In this role, you will:

Threat Hunting & Detection Engineering (45%)
  • Execute hypothesis-driven threat hunts across AWS, identity, endpoint, and network telemetry, documenting findings and recommended control or detection improvements.
  • Build, tune, and maintain SIEM detections focused on high-risk behaviors such as IAM misuse, persistence, privilege escalation, and data access or exfiltration.
  • Reduce alert noise through structured tuning, baselining, and enrichment while preserving meaningful coverage.
  • Map detections and hunts to MITRE ATT&CK techniques to identify and close visibility gaps.
Incident Response & Investigation (30%)
  • Support investigation and containment of security incidents, performing log analysis, scoping impact, and documenting findings.
  • Contribute to the development and refinement of incident response playbooks for common cloud and identity-based scenarios.
  • Produce clear after-action reports that identify root cause, control gaps, and prioritized remediation steps.
  • Participate in periodic tabletop or fire drill exercises to validate readiness and improve response coordination.
Purple Teaming & Continuous Improvement (15%)
  • Participate in purple team exercises to validate detection effectiveness and help prioritize remediation of identified gaps.
  • Partner with offensive testing and engineering teams to translate findings into improved detections and hardened configurations.
  • Identify opportunities to strengthen logging, telemetry coverage, and control effectiveness across cloud and enterprise systems.
Automation, Documentation & Knowledge Sharing (10%)
  • Develop lightweight automation and scripts to improve investigation speed, enrichment, and reporting consistency.
  • Maintain well-documented detection logic, hunt results, and response procedures to improve repeatability and team scalability.
  • Share threat insights and lessons learned with the broader security and engineering community through briefings or written updates.
About you, you have:
  • 3 to 5 years of progressive experience in cyber defense, including threat hunting, detection engineering, and incident response in enterprise environments.
  • Strong cloud security experience in AWS-heavy environments, including building detections and investigations using cloud-native telemetry (for example CloudTrail, IAM, VPC Flow Logs, CloudWatch logs, and compute or container logs).
  • Hands-on experience developing, tuning, and maintaining SIEM detections and analytics, including writing high-quality queries, building dashboards, and improving signal-to-noise. Experience with Sumo Logic is strongly preferred.
  • Ability to lead threat hunts end-to-end, including hypothesis creation, data collection, analysis, documentation of findings, and recommendations grounded in attacker TTPs and frameworks such as MITRE ATT&CK.
  • Experience supporting high-severity incident response, including triage, scoping, containment guidance, and deeper analysis, with comfort serving as an escalation point for complex investigations.
  • Practical knowledge of investigative and forensic methods, including log forensics, timeline analysis, evidence handling, and documentation, to support enterprise incident investigations and E-Discovery needs as required.
  • Experience planning or participating in purple team and detection validation activities to evaluate control effectiveness and improve alerting and response outcomes.
  • Ability to operationalize and optimize security tooling by integrating log sources, improving visibility, and aligning detection coverage to current threats and business risk.
  • Strong automation and scripting skills (for example Python, PowerShell, Bash) to streamline investigations, enrich alerts, and improve repeatability across hunting and response workflows.
  • Excellent written and verbal communication skills, including producing after-action reports, threat briefings, and clear, actionable remediation guidance for technical and non-technical stakeholders.
  • A collaborative mindset with experience partnering across engineering, architecture, and development teams, and mentoring junior analysts or engineers to raise team capability.
  • Nice to have
  • Relevant certifications (for example GCIA, GCIH, GNFA, AWS Security Specialty, Security+).
  • Experience securing modern cloud platforms such as containers and Kubernetes, serverless, and CI/CD pipelines, and detecting identity-based attacks in cloud environments.
For all roles at College Board:
We are seeking individuals who are passionate about expanding educational and career opportunities and committed to mission-driven work. Candidates must be authorized to work in the United States for any employer and should possess clear and concise communication skills, both written and verbal. Proficiency in Microsoft Suite tools is preferred, though a willingness to learn is equally valued. We look for those with curiosity and enthusiasm for emerging technologies, particularly AI-driven solutions, and a proactive approach to independently learning and applying new digital tools. Most importantly, applicants should demonstrate the skills and mindsets aligned with College Board's Operating Principles, reflecting a commitment to continuous growth, collaboration, and impact, notably:
  • A commitment to candid, timely, respectful feedback
  • A learner orientation and an openness to ideas and diverse perspectives
  • The ability to push for excellence through data-informed decision-making, iterative learning, external benchmarking and user-inputs
  • Strong problem-solving skills, including the ability to break down complex issues and identify clear paths forward
  • A track record of prioritizing high-impact work, simplifying complexity, taking initiative, and making decisions quickly with clarity of purpose
  • A habit of collaborating across differences, practicing empathy, and contributing to a culture of trust and shared success
About Our Process
  • Application review will begin immediately and will continue until the position is filled. This role is expected to accept applications for a minimum of 5 business days.
  • While the hiring process may vary, it generally includes: resume and application submission, recruiter phone/video screen, hiring manager interview, performance exercise such as live coding, a panel interview, a conversation with leadership and reference checks.
What We Offer
At College Board, we offer more than just a paycheck-we provide a meaningful career, a supportive team, and a comprehensive package designed to help you thrive. We're a self-sustaining nonprofit that believes in fair and competitive compensation, grounded in your qualifications, experience, impact, and the market.

A Thoughtful Approach to Compensation
  • The hiring range for this role is $128,000-$139,000.
  • Your exact salary will depend on your location, experience, and how your background compares to others in similar roles at the College Board.
  • We aim to make our best offer upfront, rooted in fairness, transparency, and market data.
  • We adjust salaries by location to ensure fairness, no matter where you live.
  • You'll have open, transparent conversations about compensation, benefits, and what it's like to work at College Board throughout your hiring process. Check out our careers page for more.

#LI-MC1

#LI-Remote
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Engineer III, Cyber Threat Hunter in United States vacancy
  •  ...industrial cybersecurity. You will be responsible for developing detection strategies and analyzing network traffic to protect against cyber threats. With competitive compensation and comprehensive benefits, this position is ideal for those passionate about making a... 
    Cyber

    Galvanick

    Seattle, WA
    4 days ago
  • $94.1k - $150k

    Position Overview The Cyber Threat Hunter proactively protects enterprise environments from advanced cyber threats by analyzing network, endpoint...  ...a proactive SOC model by contributing to detection engineering, monitoring enhancements, automation development and continuous... 
    Cyber
    Contract work
    Work at office

    ASM Research, An Accenture Federal Services Company

    Washington DC
    11 hours ago
  • $115k - $165k

     ...Threat Detection & Response Engineer III Denver, CO or Long Beach, CA Space is a warfighting domain. True Anomaly seeks those with the talent and...  ..., and security frameworks such as MITRE ATT&CK and the Cyber Kill Chain ~ Experience with scripting (Python, PowerShell... 
    Cyber
    Permanent employment
    Work at office

    True Anomaly

    Long Beach, CA
    11 hours ago
  • SubCom, based in Newington, NH, is seeking a Cybersecurity Analyst to monitor and respond to security incidents, manage cybersecurity technologies, and ensure compliance with security best practices. The ideal candidate will have a Bachelor's degree in Cybersecurity, experience...
    Cyber
    Night shift

    SubCom

    Newington, Strafford County, NH
    6 hours ago
  • $107.9k - $195.05k

     ...Modernization sector is looking for a Cyber Threat Hunter to support a Defensive Cyber Operations...  ...that evade automated detection. Detection Engineering Pipeline: Partner with detection teams...  ...lieu of degrees. DoD 8570 IAT Level II/III: Must hold an IAT Level II or higher... 
    Cyber
    Summer work
    Casual work
    Local area
    Remote work
    Shift work
    Night shift
    Rotating shift

    Leidos

    Washington DC
    2 days ago
  • Valkyrie Enterprises is seeking a Cyber Protection Team Member to support the DCRIOS Program...  ...Responsibilities include conducting cyber threat hunting and managing first-level responses...  ...possess a high school diploma, IAT Level III certification, and proficiency in UNIX/... 
    Cyber

    Valkyrie-Enterprises

    San Antonio, TX
    3 days ago
  • A premier defense contractor is seeking a Cyber Protection Professional to support the DCRIOS...  .... This role involves conducting cyber threat hunting, incident management, and network...  ...have a high school diploma, an IAT Level III certification, and strong UNIX/Linux knowledge... 
    Cyber
    For contractors

    Valkyrie Enterprises Inc.

    San Antonio, TX
    4 days ago
  •  ...A cybersecurity firm is hiring a Cyber Threat Analyst III in Raleigh, NC. The role involves monitoring security events, handling incident responses, and utilizing AI/ML for automation. Candidates should have at least 7 years of experience, strong knowledge of SIEM tools... 
    Cyber
    Remote work
    Monday to Friday

    PLANIT Group

    Raleigh, NC
    7 days ago
  •  ...WinTrio LLC seeks a SOC Tier III Analyst / Threat Hunter to lead incident investigations and support high-severity escalations. This remote position requires over 8 years of relevant experience and advanced skills in Microsoft Sentinel, KQL, and threat hunting. The ideal... 
    Remote work

    Wintrio LLC

    New York, NY
    11 hours ago
  •  ...are currently seeking a Cybersecurity Engineer III to support a federal customer. This role...  ...protect, detect, respond, and recover from threats. The ideal candidate brings advanced...  ...best practices. Monitor and evaluate cyber threat intelligence to proactively... 
    Cyber

    Rapid Strategy

    Reston, VA
    1 day ago
  • A national cybersecurity firm is seeking a Remote Sr. Cyber Threat Hunter with 5 years of experience in Information Security. The ideal candidate will have knowledge of malicious code, security methodologies for various operating systems, and experience in analyzing security... 
    Cyber
    Remote work

    Global Channel Management

    Atlanta, GA
    4 days ago
  •  ...a skilled and experienced Cybersecurity Engineer III to provide critical Cybersecurity (CS) engineering...  ...DoD cybersecurity policies. National Cyber Range Complex (NCRC) Total Ship...  ...a zero-tolerance policy for harassment, threats, coercion, discrimination, and... 
    Cyber
    For contractors
    Local area

    DirectViz Solutions

    San Diego, CA
    1 day ago
  • $116.2k - $194k

     ...NISSC 3 Information Systems Security Engineer III Location US-CO-Colorado Springs...  ...2026-3940 Category IT / Cyber Security / Network Systems Position Type...  ...Develop andsubmitsecurity reports and threat analysis. #NISSC Qualifications... 
    Cyber
    Full time
    Contract work
    Remote work

    American Systems

    Colorado Springs, CO
    3 days ago
  •  ...ManTech International in McLean, VA is seeking a skilled Cyber Threat Hunter to join their dynamic team focused on national security. The ideal candidate will utilize their expertise in cybersecurity to proactively identify and mitigate threats using advanced technological... 
    Cyber

    ManTech International Corporation

    McLean, VA
    6 hours ago
  •  ...Threat Hunter ShorePoint is a fast-growing, industry recognized and award-winning cybersecurity...  .... Conduct incident investigation, Cyber Threat Assessment and Remediation...  ...malware, data exposure, phishing and social engineering techniques. Experience developing... 
    Cyber
    Remote work

    ShorePoint Inc

    United States
    1 day ago
  •  ...Security Systems Engineer III Position Highlights: The Security Systems Engineer Ill...  ...host-based security systems. Research threats and vulnerabilities and, where...  ...exceptions as necessary. Also works with Cyber Security on any issues or challenges... 
    Cyber

    Moffitt Cancer Center

    Tampa, FL
    4 days ago
  •  ...Cyber Threat Hunter Bethesda, MD Role Summary: Mid-level hunter conducting proactive threat hunts, identifying behavioral anomalies...  ...: • 3-5 years threat hunting, SOC, IR, or detection engineering experience. • Skilled with MITRE Telecommunication&CK;, Splunk... 
    Cyber

    Merit 321

    Rockville, MD
    1 day ago
  •  ...MANTECH! MANTECH seeks a motivated, career and customer-oriented Cyber Threat Hunter to join our team in Mclean, VA . The Cyber Threat Hunter...  ...in cyber security/information security, computer science, engineering, or other closely related IT discipline). 4+ years of... 
    Cyber
    Work at office
    Local area

    ManTech International Corporation

    McLean, VA
    6 hours ago
  • $75.2k - $158.1k

     ...Job Title: Cyber Threat Hunter Job Category: Information Technology Time Type: Full time Minimum Clearance Required to Start: TS/SCI Employee Type: Regular Percentage of Travel Required: Up to 10% Type of Travel: Local The Opportunity: Our client... 
    Cyber
    Full time
    Contract work
    Work experience placement
    Local area
    Flexible hours
    Shift work

    CACI International

    Hampton, VA
    3 days ago
  •  ...the mapping of cybersecurity talent to integrate into a SOC team as specialists in advanced detection to strengthen Threat Hunting and Detection Engineering capabilities. Responsibilities Development of detection rules (Sigma, YARA, SIEM queries). Proactive... 
    Remote work

    Babel Inc

    United States
    11 hours ago
  •  ...A company is looking for a Senior Cyber Threat Hunter to enhance its cybersecurity capabilities. Key Responsibilities Identify vulnerabilities using penetration testing tools to secure computer systems and networks Provide technical expertise for the development and... 
    Cyber
    Work experience placement
    Remote work

    Virtual Vocations Inc

    United States
    3 days ago
  •  ...Responder to support the Administrative Offices of the United States Courts in Washington, DC. This role involves incident response and threat hunting, requiring a minimum of 5 years of experience across cloud and non-cloud environments, as well as proficiency in tools like... 
    Cyber

    cFocus Software Incorporated

    Washington DC
    3 days ago
  • $94.1k - $150k

    ASM Research, An Accenture Federal Services Company is seeking a Cyber Threat Hunter in Denver, Colorado. This position involves analyzing endpoint and log data to identify cyber threats, conducting threat hunting across networks, and collaborating with Security Operations... 
    Cyber

    ASM Research, An Accenture Federal Services Company

    Denver, CO
    3 days ago
  •  ...About the job Remote Sr. Cyber Threat Hunter Remote Sr. Cyber Threat Hunter needs 5 years experience in Information Security required and 1 year experience with information technology concepts, terminology, and standards required Remote Sr. Cyber Threat Hunter requires... 
    Cyber
    Work at office
    Remote work

    Global Channel Management

    Atlanta, GA
    4 days ago
  • $70k - $100k

    Bolster Inc. is looking for a Security Analyst - Threat Hunting / Cybersecurity Analyst to join our team in Santa Clara. This position...  ...involves investigating suspicious domains and validating emerging cyber threats. The ideal candidate will have expertise in phishing... 
    Cyber
    Remote job

    Bolster Inc.

    Santa Clara, CA
    11 hours ago
  •  ...Cyber Security Lead Employment Eligibility Statement: Due to specific project and...  ...Science, Information Technology, or Computer Engineering. Post-graduate degree in Computer...  ...understand and assess applicable IT security threats. Familiarity with applicable legal... 
    Cyber
    Permanent employment
    Contract work
    Local area

    Danta Technologies

    Frisco, TX
    1 day ago
  •  ...Technology Job Description Our team, in Chesapeake, VA has an immediate need for a Security Operations Center Analyst (Cyber Threat Hunter) to monitor and maintain an active defense security posture by preventing, monitoring, detecting, and responding to cybersecurity... 
    Cyber
    Full time
    Immediate start

    STRATASCORP

    Chesapeake, VA
    4 days ago
  •  ...identifying, analyzing, and responding to cyber threats to inform the customer’s vulnerability...  ...Local agencies. We possess highly skilled engineers, providing innovative solutions backed...  ...weeks of annual leave Incident Manager - III - IMG03 ESS 3322, 3324 Powered by... 
    Cyber
    Local area
    Flexible hours

    BCMC, LLC

    Arlington, VA
    4 days ago
  • cFocus Software seeks a Mid Level Cyber Threat Hunter to join our program supporting US Courts in Washington, DC. This position is 4 days a week onsite in DC and one day remote. Required Qualifications include: ~3- 5 years of experience performing threat hunts & incident... 
    Cyber
    Work at office
    Remote work

    cFocus Software Incorporated

    Washington DC
    4 days ago
  •  ...evolving techniques to help identify and analyze potential threats. Your skills will support our team's ability to detect and respond to cyber attacks; experience with cloud security is a plus! As a Cyber Threat Hunter, you'll play an important role in helping us stay... 
    Cyber
    Work experience placement
    Work at office
    Remote work
    Work from home

    BlueCross BlueShield of Tennessee

    United States
    11 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Engineer III, Cyber Threat Hunter. Be the first to apply!