Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Threat Hunt Lead - Top Secret

Gdit

Threat Hunt Lead is responsible for overseeing all cyber threat hunt, adversary analysis, malware analysis, and digital forensics mission activities under an upcoming government contract. Hunts will include operations within sensitive environments such as Operation Technology (OT), Industrial Control Systems (ICS), and other Critical Infrastructure (CI) networks. The successful leader directs multidisciplinary hunt and forensic teams providing full spectrum detection, analysis, and response capabilities that enable federal stakeholders to identify, understand, and counter sophisticated cyber threats across federal, State Local Tribal and Territorial (SLTT), commercial, critical infrastructure, and cloud environments. The Threat Hunt Lead ensures continuous detection of adversary behavior, manages simultaneous deployed hunt operations, oversees advanced malware and forensics workflows, and delivers high quality analytic products that inform national cyber defense actions. The role maintains readiness of personnel, tools, and flyaway kits to support rapid, remote, or onsite engagements. Adversary, Malware, and Forensics Analysis Oversight Oversee simultaneously deployed hunt operations teams performing adversary tool analysis, including dynamic and static malware analysis and full reverse engineering of binaries, scripts, malicious documents, and artifacts to determine functionality, behavior, and command-and-control mechanisms. Oversee simultaneously deployed teams conducting digital forensic analysis of affected systems to determine malware impact, persistence mechanisms, and threat actor behavior. Deep understanding of all levels of threat actor tools, techniques, and procedures (TTPs) that actors may deploy, including advanced (AI/ML) modeling techniques. Extensive knowledge of emerging, established, and nation‑state level threat actor behaviors, including subversion and/or false‑flag operations designed to circumvent established cyber inspection tools. In‑depth ability to adapt to diverse cyber environments in which teams may need to “live off the land” with on-site‑provided cyber tools. Strong knowledge of air‑gap environments and how to deploy teams within them to ensure consistent reporting. Ensure teams develop custom scripts, tools, and analytic methods to identify, characterize, and visualize adversary techniques across hunt, malware, and forensics workflows within both established and atypical cyber environments, e.g., OT/ICS and commercial environments. Ensure production of high‑quality indicators of compromise, detection artifacts, and adversary capability assessments that support national cyber defense operations. Thread Hunt Operations Management Oversee full spectrum hunt and incident response engagements, onsite and/or remote, ensuring teams identify threats, assess impact, and recommend remedial actions to local stakeholders. Direct continuous analysis of established and atypical cyber‑defense sensor data, endpoint activity, network flows, cloud telemetry, and communications data to detect adversarial behavior and anomalous activity. Ensure teams maintain continuous awareness of emerging attack techniques, threat actors, tools, and methodologies to remain effective and up to date. Oversee both classified and unclassified delivery of federal stakeholder‑branded analytic products, intelligence deliverables, threat assessments, and technical reports that contextualize adversary activity. Determine mechanisms for timely and accurate release of indicators to maintain a proactive threat posture against cyber threat actors. Prepare, support the delivery, and oversee the creation of on‑demand and formal reporting to ensure timely and accurate reporting of shifting threat actor TTPs regardless of attribution. Host‑Based, Network, Cloud, and OT/ICS Forensics Leadership Oversee simultaneously deployed teams performing forensic examination across host systems and digital media (phones, hard drives, memory images, etc.). Direct network forensics operations to identify attacker behavior, develop network signatures, analyze traffic and configurations, and produce authoritative forensic reports. Oversee cloud forensic teams. Manage OT/ICS forensic teams conducting analysis across industrial control systems. Support, lead, direct and oversee remediation suggestions and work with local stakeholders, including OT/ICS engineers. Malware Analysis and Operations Oversight Oversee malware operations teams responsible for evaluating complex malicious code, performing static/dynamic analysis, triaging samples, and generating high‑quality technical reports. Ensure development of custom detection signatures (YARA, SIGMA) and automated cleanup tools to enhance detection and remediation activities. Oversee team workflows for management of malware submissions to pre‑approved stakeholders only, including triage, prioritization, and status tracking. Ensure teams develop metrics to evaluate analysis throughput, accuracy, timeliness, and mission impact. Operational Processes, Procedures, and Performance Metrics Oversee the stakeholder‑approved development, maintenance, and improvement of Standard Operating Procedures (SOPs), playbooks, analytic processes, workflows, robotic process automations (RPAs), and procedures supporting hunt, malware, and forensic operations. Ensure teams contribute to performance metrics measuring forensic effectiveness, response quality, hunt mission impact, and operational readiness. Oversee the threat hunt team’s participation in classified and unclassified interagency technical exchanges and communities of interest to strengthen national cyber defense integration. Deployable Hunt and Forensic Capability Management (Flyaway Kits) Oversee readiness of all deployable hunt and forensics resources, including full and reduced capacity flyaway kits, storage media, imaging systems, and tools. Ensure kits are provisioned, tested, updated, sanitized, and secured in accordance with chain of custody and data handling requirements. Oversee rapid deployment capabilities supporting remotely or onsite incident response, exercises, and surge support events. Required Qualifications Experience leading simultaneously deployed hunt, malware analysis, digital forensics, or incident response teams within large, scale, enterprise, commercial and OT/ICS cyber defense programs. Deep knowledge of nation‑state, emerging and established adversary TTP analysis, reverse engineering, forensic acquisition, and threat detection methodologies. Deep understanding and experience with host‑based, network, cloud, and OT/ICS forensics. Strong understanding of malware analysis, dynamic/static analysis tools, and detection signature development across multiple operating environments, including OT/ICS. Ability to oversee multidisciplinary teams and coordinate multiple concurrent engagements. Strong communication, reporting, and analytic leadership skills. 10 years of overall cybersecurity experience with 5 years of management of cybersecurity teams. Preferred Qualifications Experience supporting federal stakeholders such as DHS, DoW, the Intelligence Community (IC), the FBI, and/or other national security cyber missions. Experience supporting commercial threat hunting operations. Experience supporting, leading and/or directing threat hunt teams within OT/ICS environments. Experience supporting, leading and/or directing cyber protection teams. Significant hands‑on experience with advanced threat hunting techniques in air‑gapped and/or otherwise sensitive operating environments. Certifications such as GREM, Certified Threat Hunter (MTH), Offensive Security Certified Professional Plus (OSCP+), GIAC Penetration Tester (GPEN), GCTI, GNFA, GRID, CRTO or similar advanced technical credentials. Experience with ATT&CK frameworks across Enterprise, Cloud, and IC. Experience managing deployable cyber hunt kits or rapid response teams. #J-18808-Ljbffr

Vacancy posted 8 hours ago
Similar jobs that could be interesting for youBased on the Threat Hunt Lead - Top Secret in Herndon, VA vacancy
  • $170k - $230k

     ...Clearance Level Must Currently Possess: Top Secret Clearance Level Must Be Able to...  ...: Skills: Cyber Operations, Cyber Threat Analysis, Cyber Threat Modeling, Team Management...  ...Yes Job Description: The Threat Hunt Lead is responsible for overseeing all cyber... 
    Suggested
    Full time
    Contract work
    Temporary work
    Part time
    Local area
    Immediate start
    Remote work
    Worldwide
    Flexible hours
    Shift work

    GDIT

    Herndon, VA
    a month ago
  •  ...Leyden Solutions, Inc. is seeking a highly qualified individual with Top-Secret Clearance to engage with customers and establish priorities to meet operational needs. The role involves leading teams in threat analysis, providing expert recommendations, and ensuring... 
    Suggested

    Leyden Solutions, Inc.

    Vienna, VA
    8 hours ago
  • $170k - $230k

     ...Level Must Currently Possess: Top Secret Clearance Level Must Be...  ...The NextGen Command Center Lead is responsible for overseeing...  ...response, situational awareness, threat monitoring, operational reporting...  ...mission areas such as Threat Hunt, CTI, and Vulnerability... 
    Suggested
    Full time
    Contract work
    Temporary work
    Part time
    Immediate start
    Remote work
    Worldwide
    Flexible hours
    Shift work

    GDIT

    Herndon, VA
    22 days ago
  • $170k - $230k

     ...Level Must Currently Possess: Top Secret Clearance Level Must Be...  ...Mitigation, Team Leadership, Threat Mitigation Certifications:...  ...Remediation and Mitigation (R&M) Lead oversees teams that plan, manage...  ..., enforcing R&M and Threat Hunt (TH) guidance and feeding insights... 
    Suggested
    Full time
    Temporary work
    Part time
    Local area
    Immediate start
    Remote work
    Worldwide
    Flexible hours

    GDIT

    Herndon, VA
    22 days ago
  •  ...Job Summary Agile Defense is seeking an accomplished Threat Hunt Lead to support USG enterprise cybersecurity programs delivering 24/7/365 Cybersecurity Operations Center (SOC) services. To ensure the integrity, security and resiliency of critical operations, candidates... 
    Suggested

    Agile Defense

    Reston, VA
    8 hours ago
  •  ...strategies, and managing pipeline growth in space programs. Candidates must possess 7+ years of experience in business development and a Top Secret clearance. The position offers competitive pay, comprehensive benefits, and opportunities for career growth within a culture... 

    Northrop Grumman

    Dulles, VA
    5 days ago
  •  ...Analyst in Merrifield, Virginia. This role involves leading incident detection and response efforts while...  ...Information Security. Responsibilities include threat hunting, forensic analysis, and improving SOC processes. A Secret clearance is required. Join a dynamic team... 

    NTT DATA

    Fairfax, VA
    8 hours ago
  • $170k - $230k

     ...Clearance Level Must Currently Possess: Top Secret/SCI Clearance Level Must Be Able to...  ...Malware Reverse Engineering, Team Leadership, Threat and Vulnerability Management,...  ...Summary The Vulnerability Management Lead oversees teams that delivers comprehensive... 
    Full time
    Temporary work
    Part time
    Immediate start
    Remote work
    Worldwide
    Flexible hours

    GDIT

    Herndon, VA
    22 days ago
  •  ...space programs and business development, with a strong focus on shaping customer requirements. The role requires a current active Top Secret security clearance. Competitive salary and benefits offered, including relocation assistance and performance bonuses, enhance the... 
    Relocation package

    Northrop Grumman

    Mc Lean, VA
    1 day ago
  • $129k - $171k

     ...solutions firm is seeking an Embedded CI Program Lead in Reston, Virginia. The role supports...  ...mitigating risks related to nation state threats. Candidates must have a bachelor’s or...  ...functions. An active security clearance (Top Secret/SCI) is mandatory. The salary range is $1... 

    Slope

    Reston, VA
    8 hours ago
  • $104k - $166k

     ...Cybersecurity Lead Job Locations US-VA-Herndon Requisition ID...  ...Information Technology Clearance Top Secret/SCI Responsibilities We are seeking...  ...management. Oversee vulnerability management, threat/hunt analysis, incident response coordination... 
    Contract work
    Shift work

    Peraton

    Herndon, VA
    1 day ago
  • 4305 Cyber Threat Intelligence Team Lead 4305 | Top Secret Job Description: OVERVIEW: We are looking for a talented Cyber Threat Intelligence Team Lead to join our team and support our mission critical customer in Reston, VA. This position leads a team... 
    Contract work

    Procession Systems

    Reston, VA
    3 days ago
  • 4257 Cyber Threat Deputy Lead 4257 | Top Secret Job Description: OVERVIEW: We are seeking a Cyber Threat Deputy Team Lead to join our team and support our mission critical customer in Reston, VA. As our Cyber Threat Deputy Team Lead, you will supervise... 
    Temporary work

    Procession Systems

    Reston, VA
    1 day ago
  • $80k - $128k

     ...Detection & Case Management Lead Job Locations US-VA-Herndon Requisition ID 2026-164814 Position Category Intel and Threat Analysis Clearance Top Secret/SCI Responsibilities We are seeking a highly skilled and innovative... 
    Contract work
    Shift work

    Peraton

    Herndon, VA
    1 day ago
  • $112k - $179k

     ...NOC Shift Lead Job Locations US-VA-Herndon Requisition ID 202...  ...Project Management Clearance Top Secret/SCI Responsibilities We are seeking...  ...nexus between traditional and nontraditional threats across all domains: land, sea, space, air... 
    Contract work
    Shift work
    Night shift

    Peraton

    Herndon, VA
    3 days ago
  • $86k - $138k

     ...Knowledge Transfer (KT) Lead Job Locations US-VA-Herndon Requisition...  ...Knowledge Mgmt Clearance Top Secret/SCI Responsibilities We are seeking...  ...nexus between traditional and nontraditional threats across all domains: land, sea, space, air... 
    Contract work
    Shift work

    Peraton

    Herndon, VA
    1 day ago
  • $112k - $179k

     ...CDES Lead/Cross Domain SME Job Locations US-VA-Herndon Requisition ID...  ...Information Technology Clearance Top Secret/SCI Responsibilities We are...  ...nexus between traditional and nontraditional threats across all domains: land, sea, space, air... 
    Contract work
    Shift work

    Peraton

    Herndon, VA
    1 day ago
  • $129k - $171k

     ...proactively identifying risk, mitigating threats and delivering actionable investigative insights...  ...skills. The Embedded CI Program Lead is responsible for executing a variety of...  ...Must possess an active security clearance (Top Secret/SCI is required). PREFERRED QUALIFICATIONS... 
    Work experience placement

    Slope

    Reston, VA
    7 hours ago
  •  ...Advanced Threat Team Lead - Senior ECS is seeking an Advanced Threat Team Lead - Senior to support the Army National Guard (ARNG) Enterprise...  ...U.S. Citizenship is required Security Clearance: Secret Eligible Required Certifications: DCWF Work Role 212-Cyber... 
    Contract work

    ECS

    Fairfax, VA
    3 days ago
  • $86k - $138k

     ...Risk Management Framework (RMF) Lead Job Locations US-VA-Herndon Requisition...  ...Cyber Security Clearance Top Secret/SCI Responsibilities We are seeking...  ...between traditional and nontraditional threats across all domains: land, sea, space, air... 
    Contract work
    Shift work

    Peraton

    Herndon, VA
    3 days ago
  •  ...industry-standard tools. This position is vital for ensuring the security of cloud infrastructure and involves continuous monitoring and threat analysis to protect against vulnerabilities. Ideal applicants should be technically agile and have a passion for security. #J-18808... 

    Career-Mover

    Reston, VA
    1 day ago
  • $104k - $166k

     ...SOC Shift Lead Job Locations US-VA-Herndon Requisition ID 202...  ...Cyber Security Clearance Top Secret/SCI Responsibilities We are seeking...  ...nexus between traditional and nontraditional threats across all domains: land, sea, space, air... 
    Contract work
    Shift work
    Night shift

    Peraton

    Herndon, VA
    3 days ago
  • A technology solutions provider is seeking a Logistician to join the DARPA ITD SD-WAN project management team. The successful candidate will manage logistics operations including purchasing and inventory for technology installations. This role requires strong leadership...

    HugoNet

    Oakton, VA
    3 days ago
  • $135k - $216k

     ...Capabilities Engineer - NASA and NOAA Programs Lead Job Locations US-VA-Reston...  ...Growth Clearance Top Secret/SCI Responsibilities Advanced Capabilities...  ...nexus between traditional and nontraditional threats across all domains: land, sea, space, air... 
    Full time
    Contract work
    Work experience placement
    Work at office
    Immediate start
    Remote work
    Shift work

    Peraton

    Reston, VA
    2 days ago
  • $104k - $166k

     ...Strategic Partnerships Lead Associate Job Locations US-VA-Reston | US-MD...  ...Category Growth Clearance Top Secret/SCI Responsibilities We are...  ...nexus between traditional and nontraditional threats across all domains: land, sea, space, air... 
    Contract work
    Shift work

    Peraton

    Reston, VA
    3 days ago
  • $131.3k - $237.35k

     ...contain and eradicate cyber threats to CBP networks through monitoring...  ...efforts of the team, leading by example, andconducting comprehensive...  ...team, and Cyber Threat Hunt teamtoexecute actions designed...  ...with the ability to obtain a Top Secret/SCI Clearance Preferred... 
    Work at office
    Local area
    Immediate start

    Leidos

    Ashburn, VA
    3 days ago
  •  ...Capital in McLean, Virginia is seeking a Principal Insider Threat Analyst to lead the development of their Insider Threat Program. The role requires...  ...conducting complex investigations, architecting threat hunting operations, and maintaining a world-class insider threat... 

    B Capital

    McLean, VA
    1 day ago
  •  ...be Performed: AnaVation is looking for a talented Cyber Threat Intelligence Team Lead to join our team and support our mission critical customer...  ...operational success of our customers. We offer complex challenges, a top-notch work environment, and a world-class, collaborative... 
    Full time
    Contract work
    Temporary work
    Immediate start

    AnaVation

    Reston, VA
    16 days ago
  •  ...candidates should have at least 5 years of program management experience and a strong background in facilities operations. A variety of certifications related to safety and compliance are preferred, along with an active Top Secret security clearance. #J-18808-Ljbffr Intrepid

    Intrepid

    Mc Lean, VA
    4 days ago
  • $65k - $75k

    Orkin in Fairfax, Virginia seeks a Service Manager to lead service operations and ensure top-notch pest control services. Candidates will demonstrate strong leadership, sales experience, and a commitment to exceptional customer service. The role includes motivating a team... 

    Orkin

    Fairfax, VA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Threat Hunt Lead - Top Secret. Be the first to apply!