Cyber Threat Hunter
$94.1k - $150kASM Research, An Accenture Federal Services Company
Position Overview
The Cyber Threat Hunter proactively protects enterprise environments from advanced cyber threats by analyzing network, endpoint, and log data to identify malicious activity that may evade conventional security controls. This role establishes normal traffic and data-flow baselines, detects anomalies, develops threat hypotheses, and investigates adversary tactics, techniques, and procedures to strengthen cyber defense and incident response operations. This role directly supports a proactive SOC model by contributing to detection engineering, monitoring enhancements, automation development and continuous gap analysis to identify and mitigate emerging threats before they materialize.
Key Responsibilities
Conduct proactive threat hunting across networks, endpoints, and security datasets to identify, isolate, and help eradicate advanced threats before they impact operations.
Analyze logs from multiple sources, including packet captures, correlation engines, parsed security data, and endpoint telemetry, to detect suspicious behavior and validate threat activity.
Establish and maintain baseline patterns for normal traffic, system activity, and data flows to improve anomaly detection and investigative accuracy.
Collaborate closely with SOC analysts and detection engineers to recommend new alerts, analytics, and monitoring logic based on threat hunting findings, emerging trends, and identified visibility gaps.
Develop automation scripts and workflows (using SOAR platforms, Python, PowerShell, or similar tools) to streamline threat hunting activities, automate repetitive analytical tasks, and reduce detection and response time.
Research and track adversary tactics, techniques, and procedures (TTPs), developing technical hypotheses and investigative leads based on threat intelligence and observed behaviors.
Support incident response activities by creating incident documentation, follow-up actions, reporting criteria, and recommendations that improve overall response maturity and operational resilience.
Examine and characterize malware and cyber threats, including viruses, worms, bots, rootkits, and Trojan horses, to determine threat nature, scope, and potential impact.
Apply reverse engineering and binary analysis techniques using tools such as Ghidra and IDA Pro to support vulnerability research and understand malicious code behavior.
Required Qualifications
Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or a related field, or equivalent relevant experience.
4 years of experience in cybersecurity or a closely related technical security role.
Demonstrated ability to perform system administrator-level analysis across multiple platforms and operating systems in support of cyber investigations.
Strong analytical and problem-solving skills with the ability to identify, track, and assess adversary TTPs and suspicious activity.
Knowledge of intrusion detection methodologies, evidence preservation practices, and cyber defense and information security policies, procedures, and regulations.
Preferred Qualifications
Relevant cybersecurity certifications such as GCDA, GNFA, CompTIA PenTest+ (Removed CISSP), CISM, or CompTIA CySA+.
Experience with reverse engineering, malware analysis, vulnerability research, and threat analysis in enterprise or government environments.
Familiarity with U.S. Army Corps of Engineers (USACE) IT policies and operational security requirements.
Experience preparing technical reports, incident summaries, and threat findings for stakeholders and operational leadership.
Job Specific Skills
Threat hunting and anomaly detection.
Log correlation and security event analysis.
Packet capture analysis and data parsing.
Malware analysis, reverse engineering, and binary analysis.
Threat intelligence analysis and TTP identification.
Incident response documentation and reporting.
Detection engineering collaboration and monitoring enhancement support.
Compensation Ranges
Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.
EEO Requirements
It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.
All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment.
Physical Requirements
The physical requirements described in "Knowledge, Skills and Abilities" above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, "light office duties' or "lifting up to 50 pounds" or "some travel" required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions.
Disclaimer
The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.
$94,100 - $150,000
EEO Requirements
It is the policy of ASM that an individual's race, color, religion, sex, disability, age, gender identity, veteran status, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.
All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, veteran status, disability, gender identity, or age. All decisions on employment are made to abide by the principle of equal employment.
$50 per hour
...procedures. Monitoring for non-compliance, anomalous activity (i.e., threats), and effectively reporting such activity and associated risks.... ...and non-compliance. Investigating, analyzing and responding to cyber events, incidents and non-compliance, including trend analysis,...CyberFull timeTemporary workWork experience placementCasual workFlexible hoursShift workDay shift$132.23k - $176.31k
...to hunt, investigate, and scale discovery of evolving malicious threats, provide mission-relevant intelligence, and support mitigations... ...procedures (TTPs) with a goal of automating detection. Work with cyber operators, when requested, to conduct in-depth investigations on...CyberFull timeTemporary workWork experience placementWork at officeRemote work- ...tools below: - ProofPoint Targeted Attack Protection, Cloud Threat Response, Protection Server, ZenGuide - CrowdStrike Falcon EDR... ...NG Preferred Certifications: CompTia Security ISC2 Certified in Cyber security Certified Ethical Hacker Microsoft SC-200CyberWork at office
$80.2k - $111.3k
...Creates cyber-intelligence tools / methods and performs research and analysis in order to mitigate and eliminate high level data and... ...Maintains the computer and information security incident, damage and threat assessment programs. Responsible for the formal Security Test...CyberContract workWork at office$66.9k - $82.1k
...strategies with infrastructure and application teams to contain threats while preserving evidence and minimizing operational disruption.... ...tools and service management platforms integrated with SOC and cyber defense functions. Certifications such as ITIL Foundation plus...CyberContract workWork experience placementWork at office- ...Responsibilities include: Conducting complex criminal investigations into financial crimes, including counterfeiting, cyber fraud, and other threats to the financial infrastructure of the United States. Providing physical protection for the President, Vice...Cyber
- ...maintain, and facilitate custom queries, reports, and dashboards for system, module, and policy compliance. Monitor and report cyber and insider threats. Facilitate and approve endpoint protection application upgrades and changes. Monitor, evaluate, remediate, and prevent...CyberFull timeContract workTemporary workWork at officeShift work
$76.4k - $138.6k
...Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider... ...role goes beyond traditional scanning by actively emulating threat actors, performing penetration testing and assessing the true impact...CyberSummer holidayLocal areaFlexible hours$152.7k - $294k
...strategist will combine deep knowledge of emerging technologies and threats with strong business acumen to drive security programs that... ...Security program a step ahead of evolving business demands and cyber risks. Key Responsibilities: Strategic Program Development...CyberSummer holidayLocal areaFlexible hoursShift work- ...HackerOne is a global leader in Continuous Threat Exposure Management (CTEM). The HackerOne Platform unites agentic AI solutions with... ...security, HackerOne delivers measurable, continuous reduction of cyber risk for enterprises. Industry leaders, including Anthropic, Crypto...CyberApprenticeshipLocal areaRemote workShift work
- ...execution.Preferred Qualifications:Certified Information Systems Security Professional (CISSP certification).Experience with the primary cyber risk and compliance automation tools.Clearance Requirements:An active Secret security clearancePhysical Requirements:Must be able to...CyberFull timeContract workWork at officeLocal areaRemote work
- ...core network services (i.e., Active Directory, network file servers, storage area network, virtual server environment, etc.).Provide cyber security services in support of the Authorization to Operate (ATO) for the Development, Test, and Evaluation (DT&E) authorizing...CyberFull time
$40k
...assisting with containment, vulnerability management, and compliance activities. The role works under senior guidance to execute defined cyber actions, maintain incident documentation, support POA&M and ISVM tracking, and assist with patching, testing, and spill response....CyberContract workRemote work- ...Cyber Excepted Service Position This position is being recruited under 10 USC 1599f into the Cyber Excepted Service and does NOT convey eligibility to be converted to the Competitive Service. It has been identified as a position necessary to carry out and support the...CyberWork at office
- OverviewAbout M.C. DeanM.C. Dean is Building Intelligence®. We design, build, operate, and maintain cyber-physical solutions for the nation’s most mission-critical facilities, secure environments, complex infrastructure, and global enterprises. With over 9,000 employees...CyberWork at officeLocal areaFlexible hours
$86.4k
...JOB SUMMARY This Position is the top investigator in the Cyber Fusion Center, capable of working any kind of incident, leading... ...and intrusion detection system [IDS] logs) to identify possible threats to network security. (10%) Perform cyber defense incident triage...CyberFor contractorsWork at officeLocal areaRemote work- ...steadfast in our journey toward a future that is both bright and transformative. Our expertise spans Enterprise IT, Mission IT and Cyber. With our global footprint, we place a strong emphasis on nurturing our people and culture, which forms the core of our successful...CyberContract workDay shift
- ...steadfast in our journey toward a future that is both bright and transformative. Our expertise spans Enterprise IT, Mission IT and Cyber. With our global footprint, we place a strong emphasis on nurturing our people and culture, which forms the core of our successful...CyberContract workDay shift
- ...Assurance Technical (IAT) Level II baseline certification A Bachelors Degree with Technical training related to Information Technology, Cyber Security, Computer Science, or related discipline Or a High School diploma/GED with Technical training related to Information...CyberFull timeContract workPart timeInterim roleLocal areaFlexible hours
$130k - $135k
...incident response, security operations, and security initiatives. Background in SOC operations, detection engineering, threat hunting, or cyber threat intelligence. Must be comfortable supporting a weekend schedule. ( 2 nd Shift WEEKEND schedule, Wednesday – Sunday...CyberFull timeRemote workFlexible hoursShift workWeekend workAfternoon shift$18 - $25 per hour
...Consulting, Machine Learning Operations, Multicloud, and Security. Relevant Majors: Business Administration Computer Science Cyber Security Data Science/Analytics Economics/Statistics Information Technology Software Engineering Master of Business...CyberRemote jobHourly paySummer workInternshipWork at officeImmediate startShift work- ...future that is both bright and transformative. Our expertise spans consulting and analytics, digital workplace solutions, and cyber compliance. With our global footprint, we place a strong emphasis on nurturing our people and culture, which forms the core of our successful...CyberContract workWork at officeLocal areaAfternoon shift
- DescriptionSAIC is hiring a Cloud Computing Cyber Engineer for the SAIC Cloud One Digital Engineering Team. This team is responsible for the architecture, engineering and sustainment of the Air Force Cloud Digital Engineering platform currently deployed on AWS and Azure...CyberInterim roleWork at officeRemote work
- ...technical and security training (e.g., operating system, networking, security management) relative to assigned duties Execute the cyber security portion of the self-inspection, to include provide security coordination and review of all system assessment plans...CyberWork at office
$60k
...across enterprise IT and OT environments. Perform escalation-level response actions, including coordinating and executing directed cyber activities. Lead and support containment and restoration efforts during security incidents, ensuring timely resolution and...CyberContract workRemote workShift work- ...steadfast in our journey toward a future that is both bright and transformative. Our expertise spans Enterprise IT, Mission IT and Cyber. With our global footprint, we place a strong emphasis on nurturing our people and culture, which forms the core of our successful...CyberContract work
- ...timelines, and impacts accurately. Telemetry‑Informed Engagement: Use monitoring/ITSM data to route incidents; engage infra/app/cyber/vendor dependencies. Communications & Handoffs: Provide structured internal messaging (leadership updates, stakeholder briefings,...CyberContract workWork experience placementWork at officeShift work
- ...role executes the incident response process as defined by enterprise ITSM governance and the Senior Incident Manager, integrates with cyber defenders when needed, and champions readiness and continual improvement. Key Responsibilities War-Room Facilitation:...CyberContract workWork experience placementWork at officeShift work
$55.7k - $82.1k
...Incident Response Engineer, Jr. monitors enterprise security tools and logs to detect, analyze, and triage potential cybersecurity threats targeting mission-critical systems and data. The role performs initial investigations, distinguishes false positives from genuine incidents...Contract workWork at officeShift work- ...their businesses. And the Fortinet NSE Training Institute, an initiative of Fortinet's Training Advancement Agenda (TAA), provides one of the largest and broadest training programs in the industry to make cyber training and new career opportunities available to everyone....CyberWorldwideHome office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Threat Hunter. Be the first to apply!



