Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cyber Threat Hunter - Onsite in DC, Remote Day

cFocus Software Incorporated

Washington DC
  • Remote job

cFocus Software seeks a Mid Level Cyber Threat Hunter to join our program supporting US Courts in Washington, DC. This position is 4 days a week onsite in DC and one day remote. Required Qualifications include: 3- 5 years of experience performing threat hunts & incident response activities for cloud-based and non-cloud-based environments, such as: Microsoft Azure, Microsoft O365, Microsoft Active Directory, and Zscaler 3- 5 years of experience performing hypothesis-based threat hunt & incident response utilizing Splunk Enterprise Security. 3- 5 years of experience collecting and analyzing data from compromised systems using EDR agents (e.g. CrowdStrike ) and custom scripts (e.g. Sysmon & Auditd ) 3-5 years of experience with the following threat hunting tools: Microsoft Sentinel for threat hunting within Microsoft Azure; Tenable Nessus and SYN/ACK for vulnerability management; NetScout for analyzing network traffic flow; SPUR.us enrichment of addresses Mandiant Threat intel feeds Must be able to work 80% (Monday thru Thursday) onsite at AOUSC office in Washington, DC Desired Qualifications include: One of the following certifications: GIAC Certified Intrusion Analyst (GCIA) GIAC Certified Incident Handler (GCIH) GIAC Continuous Monitoring (GMON) GIAC Defending Advanced Threats (GDAT) Splunk Core Power User Duties: Provide incident response services after an incident is declared and provides a service that proactively searches for security incidents that would not normally be detected through automated alerting. The Threat Hunt mission is to explore datasets across the judicial fabric to identify unique anomalies that may be indicative of threat actor activity based on the assumption that the adversary is already present in the judicial fabric. The extended mission is to conduct counterintelligence, build threat actor dossiers, disrupt adversary operations, identify misconfigurations/ vulnerabilities, and identify visibility/detection gaps, if any. Human analytical thinking is imperative to the primary and extended missions as it is up to the threat hunter to find signs of an intrusion that have bypassed the automatic detection process that may already be in place. Accept and respond to government technical requests through the AOUSC ITSM ticket (e.g., HEAT or Service Now), for threat hunt support. Threat hunt targets include cloud-based and non-cloud-based applications such as: Microsoft Azure, Microsoft O365, Microsoft Active Directory, and Cloud Access Security Brokers (i.e., Zscaler). Review and analyze risk-based Security information and event management (SIEM) alerts when developing hunt hypotheses. Review open-source intelligence about threat actors when developing hunt hypotheses. Plan, conduct, and document iterative, hypothesis based, tactics, techniques, and procedures (TTP) hunts utilizing the agile scrum project management methodology. At the conclusion of each hunt, propose, discuss, and document custom searches for automated detection of threat actor activity based on the hunt hypothesis. Configure, deploy, and troubleshoot Endpoint Detection and Response agents (e.g., CrowdStrike and Sysmon). Collect and analyze data from compromised systems using EDR agents and custom scripts provided by the AOUSC. Track and document cyber defense incidents from initial detection through final resolution. Interface with IT contacts at court or vendor to install or diagnose problems with EDR agents. Participate in government led after action reviews of incidents. Triage malware events to identify the root cause of specific activity. Attend daily Agile Scrum standups and report progress on assigned Jira stories. Deliverables: Hunt Hypotheses : Hunt hypotheses describe how an actor might operate in the network while remaining undetected. The hypothesis describes what is expected to happen if the hypothesis is true and what is expected to happen if the hypothesis is false. The hypothesis contains all data required, is free from errors in grammar, spelling, content, and submitted in the specified times that are stated in the deliverable section. Hunt Reports : Hunt reports describe the original hypothesis and all iterations. At each stage, the report details how the hypothesis was tested and the results. The reports contain all data required, is free from errors in grammar, spelling, content, and submitted in the specified times that are stated in the deliverable section. Detection Logic: Document and test detection logic for automated detection of threat actor activity based on hunt hypothesis. Detection logic in the form of Splunk Enterprise Security (ES) searches that are run at proposed intervals. Proposal and discussion will happen in agile scrum stand up meetings. Document in Jira stories. Advanced SME IR Reports : Timely Advanced SME IR Support for Priority 1 Security Events. SME actively participating in IR activities within 4 hours of request (7x24x365). Incident Report: Document all incident details in an incident report. Report shall include executive summary, details of incident, security impact of incident, timeline of incident, and actions taken. Provide Weekly Reports to the AOUSC Program Manager that documents all activities, tasks, tickets and documents worked on. Document repeatable Standard Operation Procedures (SOPs) and playbooks for security use cases. #J-18808-Ljbffr cFocus Software Incorporated

Vacancy posted 13 hours ago
Similar jobs that could be interesting for youBased on the Cyber Threat Hunter - Onsite in DC, Remote Day in Washington DC vacancy
  • cFocus Software seeks a Threat Hunter to support the Administrative...  ...(AOUSC) in Washington, DC.  This position will require 4 days a week onsite at the Thurgood Marshall Building and 1 day remote with hours of 8am- 4:30...  .... Track and document cyber defense incidents from... 
    Remote work
    Cyber
    Work at office

    cFocus Software Incorporated

    Washington DC
    2 days ago
  •  ...Job Title: Cyber Threat Hunter (TS/SCI Clearance Required) About Trellix...  ...Sector) Work Location: Onsite Fort Belvoir, VA Role Overview...  ...tools. Deliver onsite and remote security application/endpoint...  ...selves to work every day. We offer a variety of social... 
    Remote work
    Cyber
    Full time
    Work at office
    Flexible hours

    Trellix

    Fairfax, VA
    2 days ago
  • $128k - $139k

     ...College Board - Technology - Cyber Security Operations...  ...: 1) This is a fully remote role. Candidates who live...  ...to mature our Threat Management and Incident...  ...As a Cyber Threat Hunter, you will play a hands-...  ...minimum of 5 business days. While the hiring process... 
    Remote work
    Cyber
    Full time
    Work at office
    Immediate start

    College Board

    United States
    2 days ago
  • $107.9k - $195.05k

     ...Digital Modernization sector is looking for a Cyber Threat Hunter to support a Defensive Cyber Operations (DCO) team in Washington, DC. This position is expected to become...  ...team of analysts working 24/7 rotating shifts (days, swings, nights). As such, occasional shift... 
    Remote work
    Cyber
    Summer work
    Casual work
    Local area
    Immediate start
    Shift work
    Night shift
    Rotating shift

    Leidos Inc

    Washington DC
    3 days ago
  • Job Title Cyber Threat Hunter (TS/SCI Clearance Required) Location Fort Belvoir, VA (Onsite) Clearance TS/SCI (Qualified) Role Overview The role involves developing and delivering...  ...vulnerability analysis. Deliver onsite and remote security application/endpoint protection... 
    Remote work
    Cyber
    Work at office

    109 Trellix Public Sector LLC

    Fairfax, VA
    4 days ago
  • $135k - $200k

     ...stay ahead of evolving threats. Founded in 2015 by experts from U.S. Cyber Command and MIT Lincoln...  ...readiness cycles from months to days. Why join SimSpace?...  ...serve. Whether you're remote or office-based, you'll...  ...AI-Centric Threat Hunter We are looking for... 
    Remote work
    Cyber
    For subcontractor
    Work at office
    Local area
    Worldwide
    Flexible hours

    SimSpace Corporation

    United States
    2 days ago
  •  ...Solutions (SGSS), a Parsons company, is hiring a junior Cyber Defense Analyst/Threat Hunter, working full-time and onsite at our customer location in Welcome, MD. This...  ...hybrid networks (on-prem, AWS GovCloud, and remote sites) Perform real-time and retrospective threat... 
    Remote work
    Cyber
    Full time
    Night shift

    Space/Ground System Solutions Inc

    Welcome, MD
    13 hours ago
  •  ....   We are currently seeking a Cyber Security Threat Analyst (Onsite Hybrid) to join our team in Charlotte...  ...to reduce risk. Track zero-day vulnerabilities and high-risk CVEs,...  ...s needs. While many positions offer remote or hybrid work options, these arrangements... 
    Remote work
    Cyber
    Work experience placement
    Work at office
    Flexible hours

    The Nippon Telegraph and Telephone Corporation (NTT)

    Charlotte, NC
    5 days ago
  •  ...Consultant (Public Sector) Work Location Onsite Fort Belvoir, VA Clearance Required TS/...  ...About the Candidate Understanding of cyber threats, attack vectors, detection capabilities,...  ...protocol analysis tools. Deliver onsite and remote security application/endpoint protection... 
    Remote work
    Cyber
    Full time
    Work at office

    Trellix

    Fairfax, VA
    13 hours ago
  • $100k - $155k

    ## Sr. Threat Hunting Intelligence Analyst (Onsite, Atlanta)Applylocations: USA - Remote, GAtime type: Full timeposted on: Posted Todayjob requisition...  ...an onsite presence up to 5 days per week in Atlanta, GA.**...  ...+ Threat hunting + Cyber Threat intelligence + Dark web... 
    Remote work
    Cyber
    Work experience placement
    Work at office
    Local area

    CrowdStrike Holdings, Inc.

    Atlanta, GA
    1 day ago
  • $123k - $194k

     ...focus on proactively hunting for threat‑actor tactics, techniques,...  ...identify gaps in detection and cyber hygiene, and recommend improvements...  ..., and paid vacation, sick days, and holidays. Work Schedule...  ...four days on-site and one day remote per week. Equal Opportunity Employment... 
    Remote work
    Cyber
    Local area
    Weekend work
    1 day per week

    MUFG Bank, Ltd.

    Hoboken, NJ
    1 day ago
  • A national cybersecurity firm is seeking a Remote Sr. Cyber Threat Hunter with 5 years of experience in Information Security. The ideal candidate will have knowledge of malicious code, security methodologies for various operating systems, and experience in analyzing security... 
    Remote job
    Cyber

    Global Channel Management, Inc

    Atlanta, GA
    3 days ago
  • $70k - $100k

    Bolster Inc. is looking for a Security Analyst - Threat Hunting / Cybersecurity Analyst to join our team in Santa Clara. This position...  ...involves investigating suspicious domains and validating emerging cyber threats. The ideal candidate will have expertise in phishing... 
    Remote job
    Cyber

    Bolster Inc.

    Santa Clara, CA
    4 days ago
  • A leading technology company is seeking a Cyber Threat Hunter to join their Defensive Cyber Operations team in Washington, DC. The role involves developing hunt campaigns, conducting advanced telemetry analysis, and maintaining high levels of situational awareness regarding... 
    Remote work
    Cyber

    Leidos Inc

    Washington DC
    13 hours ago
  •  ...Position Overview The Cyber Threat Hunter proactively protects enterprise environments from advanced cyber threats by analyzing network, endpoint, and log data to identify malicious activity that may evade conventional security controls. This role establishes normal... 
    Remote work
    Cyber
    Contract work
    Work at office

    ASM Research

    United States
    3 days ago
  •  ...a focus on high-profile, high-threat, private and public-sector customers...  ...As recognized members of the Cyber Elite, we work together in...  ...: We are seeking a Threat Hunter to support and enhance our 24/...  ...CWAPT or CREA. Where it's done: ~ Remote (Herndon, VA)... 
    Remote work
    Cyber
    Contract work

    ShorePoint Inc

    Herndon, VA
    2 days ago
  • $100k - $155k

     ...CrowdStrike is looking for a passionate cyber professional to join our rapidly growing...  ...understanding their adversaries. As part of our remote close-knit team, you will bring with you...  ...cybersecurity to help evolve how we do threat hunting at CrowdStrike. After a period... 
    Remote work
    Cyber
    Work experience placement
    Work at office
    Local area

    CrowdStrike Holdings, Inc.

    United States
    8 hours ago
  • $100k - $116k

     ...Advanced Threat Hunter (ATH) Location: Remote Employment Type: Full-Time Salary Range: $100,000 - $116,000 Work Schedule: 12x5 coverage (Monday...  ..., analysis, and mitigation of highly sophisticated cyber threats. This role focuses on identifying advanced persistent... 
    Remote work
    Cyber
    Full time
    Immediate start
    Monday to Friday
    Flexible hours

    Corinth Consulting Group

    United States
    3 days ago
  •  ...Senior Threat Hunter At Allstate, great things happen when our people work together to protect families and their belongings from life...  ...and hunting and serve as a liaison for Threat Services for the Cyber Operations organization, and mentor the incident handling, incident... 
    Remote work
    Cyber
    Work experience placement
    Work visa

    Allstate

    United States
    3 days ago
  • About the job Remote Sr. Cyber Threat HunterRemote Sr. Cyber Threat Hunter needs 5 years experience in Information Security required and 1 year experience with information technology concepts, terminology, and standards requiredRemote Sr. Cyber Threat Hunter requires:Common... 
    Remote job
    Cyber
    Work at office

    Global Channel Management, Inc

    Atlanta, GA
    3 days ago
  • 109 Trellix Public Sector LLC is looking for a Cyber Threat Hunter with TS/SCI clearance in Fort Belvoir, VA. The successful candidate will engage clients and manage consulting projects, including developing threat hunting plans while ensuring effective communication and... 
    Cyber

    109 Trellix Public Sector LLC

    Fairfax, VA
    4 days ago
  •  ...over bureaucracy. Title: Senior Threat Hunter Location: Washington, DC or Chandler, AZ Terms: Full-time...  ...security program Current knowledge of cyber adversary tactics, trends, and the...  ...our team who make a difference each day. Some of these recognitions include:... 
    Cyber
    Full time
    Work experience placement
    Flexible hours

    Revolutional, LLC

    Washington DC
    4 days ago
  • $123k - $194k

     ...an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment...  ...will focus on proactively hunting for threat actor's tactics, techniques, procedures...  ..., identify gaps in detection and cyber hygiene, and recommend improvements to... 
    Remote work
    Cyber
    Work at office
    Local area
    Weekend work
    1 day per week

    MUFG Bank, Ltd.

    Jersey City, NJ
    13 hours ago
  • $123k - $194k

     ...an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment...  ...will focus on proactively hunting for threat actor's tactics, techniques, procedures...  ..., identify gaps in detection and cyber hygiene, and recommend improvements to... 
    Remote work
    Cyber
    Work at office
    Local area
    Weekend work
    1 day per week

    MUFG

    Jersey City, NJ
    2 days ago
  •  ...company is seeking a Principal Security Operations Center Analyst based in the United States. In this fully remote role, you will lead investigations into cyber incidents, work alongside a passionate team, and mentor junior analysts. Candidates should have over 6 years... 
    Remote job
    Cyber

    Huntress

    New York, NY
    4 days ago
  •  ...3 trillion events per day and this traffic is growing...  ...depth knowledge of the Threat Detection market to...  ...working with both local and remote teams. ~ Knowledge of...  .... ~ Ability to work onsite from one of COE...  ...about staying ahead of cyber threats and have a proven... 
    Remote work
    Cyber
    Work experience placement
    Local area
    Worldwide
    3 days per week
    1 day per week

    CrowdStrike

    Arlington, VA
    4 days ago
  •  ...seeking an Incident Responder to support the Administrative Offices of the United States Courts in Washington, DC. This role involves incident response and threat hunting, requiring a minimum of 5 years of experience across cloud and non-cloud environments, as well as... 
    Cyber

    cFocus Software Incorporated

    Washington DC
    2 days ago
  •  ...Senior Security Engineer II - Threat Detection & Response Location : New York City, NY (4 days onsite is a must, 1 day remote) Contract: 6+ Months Job Description:...  ...at scale. You will bridge the gap between Cyber Threat Intelligence (CTI) and actionable... 
    Remote work
    Cyber
    Contract work
    Immediate start

    Winmax Systems

    New York, NY
    3 days ago
  •  ...Summary This role supports Walgreens' Threat Detection and Response function, with...  ...role based in Deerfield, IL, with 4 days onsite and 1 day remote. Work Authorization: Work visa...  ...systems. Monitors specific cyber threat actors to understand their tactics... 
    Remote work
    Cyber

    Walgreens Boots Alliance

    Deerfield, IL
    2 days ago
  •  ...Sr. Threat Intelligence Analyst TENEX is an AI-native, automation...  ...will be able to work onsite at our HQ based in Sarasota, FL...  ...MITRE ATT&CK, Diamond Model, Cyber Kill chain, Pyramid of Pain, STIX...  ...-to-date with the latest Zero-Day disclosures. You can stay calm... 
    Remote work
    Cyber
    Relocation

    TenEx

    United States
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cyber Threat Hunter - Onsite in DC, Remote Day. Be the first to apply!