Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

AOUSC - Threat Hunt Lead

Full-time

cFocus Software Incorporated

cFocus Software seeks a Threat Hunt Lead to join our program supporting the Administrative Office of the United States Courts (AOUSC). This position is Hybrid with the onsite location being in Washington, DC. This position requires a Public Trust clearance.
Qualifications:
  • Active Public Trust clearance
  • B.S. Computer Science, Information Technology, or a related field
  • 5+ years within IR in a large SOC (over 5,000 endpoints) with at least 3 years focused on proactive threat hunting or adversary emulation. 
  • 3+ years of experience with demonstrated proficiency in forming hypothesis, querying large datasets and identifying APT behavior. 
  • 2+ years’ experience with demonstrated proficiency in scripting languages including Python and PowerShell to develop new tools.
  • This role most closely aligns with the NICE work role PD-WRL-006 (Threat Analysis).
  • Active OSCP or GXPN certification
Duties:
  • Lead proactive threat hunting operations to identify Advanced Persistent Threats (APT), insider threats, malicious activity, and anomalous behaviors that evade traditional security controls.
  • Develop and execute hypothesis-driven threat hunts leveraging threat intelligence, adversary tactics, techniques, and procedures (TTPs), behavioral analytics, and anomalous telemetry.
  • Coordinate threat hunt activities within Agile two-week sprint cycles and ensure successful execution of all assigned hunt objectives and deliverables.
  • Develop Threat Hunt Execution Plans that define hunt hypotheses, objectives, technical methodologies, required telemetry, and investigative procedures.
  • Analyze endpoint, network, cloud, identity, SIEM, EDR, and log telemetry to identify indicators of compromise (IOCs), suspicious activity, and attack patterns.
  • Coordinate and escalate confirmed or suspected findings to the Cybersecurity Triage and Incident Response teams in accordance with the Judiciary SOC Incident Response Plan (JSOCIRP).
  • Collaborate with Detection Engineering teams to identify and remediate logging, telemetry, detection, or visibility gaps discovered during threat hunting operations.
  • Work closely with Cyber Threat Intelligence teams to operationalize intelligence, enrich investigations, and identify emerging threats impacting the Judiciary.
  • Conduct advanced analysis of threat actor behaviors, malware campaigns, phishing activity, suspicious infrastructure, and attack trends.
  • Develop detailed Threat Hunt Reports documenting hunt objectives, findings, TTPs, queries used, telemetry gaps, identified risks, and recommendations for improved detections.
  • Produce executive-level Hunt Sprint Reports summarizing hunt activities, operational impacts, recommendations, and emerging cybersecurity risks.
  • Provide real-time investigative support during cybersecurity incidents and high-priority threat investigations.
  • Perform analysis utilizing Splunk Enterprise Security, Microsoft Sentinel, Splunk SOAR, CrowdStrike, Qualys, ServiceNow, Jira, and other AO-approved security platforms.
  • Support the development and refinement of threat models tailored to Judiciary systems, high-value assets, and mission-critical environments.
  • Develop and maintain threat hunting SOPs, playbooks, technical procedures, and investigative methodologies aligned with AO and federal cybersecurity standards.
  • Support enterprise security awareness initiatives through threat briefings, technical reporting, and operational presentations.
  • Participate in weekly technical meetings, operational reviews, and status briefings with AO leadership and federal stakeholders.
  • Provide mentorship, technical guidance, and quality oversight to threat hunters and supporting analysts.
  • Support transition-in and transition-out activities, operational readiness, documentation development, and knowledge transfer activities.
  • Drive continuous improvement initiatives focused on detection coverage, telemetry enrichment, operational efficiency, and threat hunting maturity.

Vacancy posted more than 2 months ago
Similar jobs that could be interesting for youBased on the AOUSC - Threat Hunt Lead in Washington DC vacancy
  •  ...Position Title Cyber Threat Intelligence & Threat Hunting Lead Position Overview The Cyber Threat Intelligence & Threat Hunting Lead will oversee integrated cyber threat intelligence (CTI), detection engineering, and proactive threat hunting operations supporting... 
    Suggested
    Full time

    cFocus Software Incorporated

    Washington DC
    more than 2 months ago
  •  ...Job Description Job Description cFocus Software seeks a Threat Hunt Lead to join our program supporting the Administrative Office of the United States Courts (AOUSC). This position is Hybrid with the onsite location being in Washington, DC. This position requires... 
    Suggested
    Work at office

    cFocus Software Incorporated

    Washington DC
    16 days ago
  •  ...Position Title Threat Emulation & Readiness Lead / Red Team Lead Position Overview The Threat Emulation & Readiness Lead will oversee adversary...  ...behaviors. Coordinate closely with SOC, CTI, Threat Hunt, and Detection Engineering teams. Assess detection and... 
    Suggested
    Full time

    cFocus Software Incorporated

    Washington DC
    more than 2 months ago
  • Base One Technologies is seeking a seasoned Cyber Threat Hunter to serve as the hunt and incident response SME in a high-security environment. You will apply in-depth knowledge of threat actor tools and TTPs, distill findings into executive summaries and deep technical... 
    Suggested

    Base One Technologies

    Arlington, VA
    2 days ago
  •  ...Position Title Insider Threat Program Lead Position Overview The Insider Threat Lead will design, mature, and oversee insider threat detection, analysis, and investigative support capabilities for a federal enterprise environment. The Lead will integrate user... 
    Suggested
    Full time

    cFocus Software Incorporated

    Washington DC
    more than 2 months ago
  • cFocus Software seeks a Blue Team Lead to join our program supporting...  ...of the United States Courts (AOUSC). This position is Hybrid with...  ...aligned to current cyber threats, adversary tactics, techniques...  ...Detection Engineering, Threat Hunting, Incident Response, and Cyber... 
    Full time
    Work at office

    cFocus Software Incorporated

    Washington DC
    more than 2 months ago
  • Information International Associates, Inc. is seeking a Cyber Threat Intelligence (CTI) Lead in Alexandria, VA. This role involves providing technical support to a 24x7 cyber program with responsibilities including the development of CTI analysis and incident response.... 

    Information International Associates, Inc.

    Alexandria, VA
    1 day ago
  •  ...Description Job Description Evolver Federal is seeking a Lead Cyber Threat Analyst to fulfil a requirement for a potential government...  ...critical infrastructure. This role focuses on proactive threat hunting, intelligence analysis, and developing strategies to detect... 
    Flexible hours

    Evolver Federal

    Washington DC
    13 days ago
  • $165k - $185k

    Cyber Threat Intelligence (CTI) SME (Team Lead) Everforth ECS is seeking a Cyber Threat Intelligence (CTI) SME (Team Lead) to join our team in Arlington...  ...into precise, actionable leads for Proactive Threat Hunting (PHB) and Incident Response (IRB) teams. This position... 
    Remote work

    ECS Limited

    Arlington, VA
    3 days ago
  •  ...seeks a Forensic and Malware Lead to join our program supporting...  ...of the United States Courts (AOUSC). This position is Hybrid with...  ...analysis of advanced persistent threats (APT), ransomware, phishing campaigns...  ...investigations and threat hunting operations. Coordinate... 
    Full time
    Work at office

    cFocus Software Incorporated

    Washington DC
    more than 2 months ago
  • $130k - $180k

     ...prioritizing speed, ownership, and execution over bureaucracy. Lead Cyber Threat Intelligence Analyst Location: Onsite – Government-...  ...behavior Coordinate with SOC, incident response, and threat hunting teams to ensure CTI products are operationally relevant and drive... 
    Full time
    Work experience placement
    Flexible hours
    Shift work

    Revolutional, LLC

    Suitland, MD
    25 days ago
  • Everforth ECS in Arlington, VA is seeking a Cyber Threat Intelligence (CTI) SME (Team Lead) to direct a specialized threat collection and analytics capability...  ...&CK, and drive automation-first analytics pipelines that produce actionable hunt leads #J-18808-Ljbffr ECS Limited
    Remote work

    ECS Limited

    Arlington, VA
    1 day ago
  •  ...Position Title SOC Operations Lead / Managed Detection & Response (MDR) Lead Position Overview The SOC Operations Lead...  ...and incident impact assessments. Coordinate closely with Threat Hunting, CTI, Detection Engineering, and Incident Response teams. Brief... 
    Full time

    cFocus Software Incorporated

    Washington DC
    more than 2 months ago
  • cFocus Software seeks a Cybersecurity Shift Lead to join our program supporting the Administrative Office of the United States Courts (AOUSC). This position is Hybrid with the onsite location being in Washington, DC. This position requires a Public Trust clearance.... 
    Full time
    Work at office
    Shift work

    cFocus Software Incorporated

    Washington DC
    more than 2 months ago
  •  ...recognize that our employees are our number one resource. If you are a problem-solving people-person, apply today! Position Title: Lead Cyber Threat Analyst Location: Washington, DC Position Summary The Lead Cyber Threat Analyst serves as the technical and... 
    For contractors
    Local area

    DirectViz Solutions, LLC

    Washington DC
    13 days ago
  • KBR, Inc. is seeking a Senior OPSEC Threat & Risk Assessment Specialist to serve as the principal deputy to the TRMC Operations Security Program Manager. You will lead comprehensive OPSEC threat and risk assessments across DoD programs and the MRTFB enterprise, leveraging... 

    KBR, Inc

    Alexandria, VA
    4 days ago
  • RMGS, Inc. is recruiting a Threat & Risk Assessment Specialist based in Quito, Ecuador, with in-country travel required and contingent upon contract award. The role focuses on designing structured threat-assessment methodologies and establishing risk-classification criteria... 
    Contract work

    RMGS Inc

    Arlington, VA
    4 days ago
  • Concentric Advisors in Arlington, VA is seeking a Corporate Security Lead to join our client-site team. The role focuses on providing holistic security, incident management, and threat assessment in a high-visibility environment. You will supervise on-site security staff... 

    Concentric Advisors

    Arlington, VA
    2 days ago
  • Business Computers Management Consulting Group, LLC (BCMC) seeks a Senior JCDC Cyber Triage Analyst to provide expert threat triage, analysis, and interagency coordination for national cyber defense. The role mentors junior analysts and liaises with FBI, NSA, USCYBERCOM... 

    bcmcllc

    Arlington, VA
    1 day ago
  • Job Announcement Lead Editor, Emerging Threats About MBN Middle East Broadcasting Networks (MBN) is the premier Arabic-first media organization that connects the Middle East and the United States. The company is in the midst of an exciting digital transformation and looking... 

    Middle East Broadcasting Networks

    Arlington, VA
    2 days ago
  • Sierra Nevada Corporation seeks an AI Threat Analyst III to support Insider Risk and AI-driven security initiatives. You will surface insider-threat trends, enable proactive defenses, and collaborate with stakeholders across cyber tools and data science. A TS clearance... 

    Sierra Nevada Corporation

    Arlington, VA
    5 days ago
  • $140k - $150k

    Job DescriptionEverforth ECS is seeking an Incident Response Lead to work in our Washington, DC office / remote. The role is contingent...  ...as a senior security operations specialist consisting of hunting threats, developing detection mechanisms, refining processes, and... 
    Work at office
    Remote work

    ECS Federal

    Washington DC
    a month ago
  • $100k - $124k

     ...Description SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering...  ...identify anomalous activity and potential threats. Protect against and prevent potential...  ...monitoring, alert creation, and threat hunting. Experience using Microsoft Azure access... 
    Contract work
    Local area
    Remote work
    All shifts
    Shift work
    Day shift

    SkyePoint Decisions

    Beltsville, MD
    26 days ago
  • $112k - $179k

     ...Responsibilities Peraton is now Hiring: TASO Team Lead – Federal Strategic Cyber Programs.Location: Arlington, VAPosition Overview...  ...cyber defense missions. This role provides leadership across threat hunting, malware analysis, digital forensics, and incident response within... 
    Contract work
    Immediate start
    Shift work

    Peraton Corporation

    Arlington, VA
    a month ago
  •  ...Description Evolver Federal is seeking a Lead Incident Responder to fulfill a...  ...TIC 3.0), lead investigations into complex threats, and deliver compliance reporting to federal...  ...programs' SELC/SDLC Knowledge of threat hunting methodologies and proactive detection strategies... 
    Contract work
    Flexible hours

    Evolver Federal

    Washington DC
    13 days ago
  • KBR’s National Security Solutions team seeks a Senior OPSEC Threat & Risk Assessment Specialist / Deputy OPSEC Lead to advance OPSEC across DoD programs and MRTFB. You will serve as the principal deputy to the OPSEC PM and lead threat and risk assessments while implementing... 

    KBR Careers

    Alexandria, VA
    4 days ago
  • $110k - $150k

     ...prioritizing speed, ownership, and execution over bureaucracy. Lead Cyber Defense Forensics Analyst Location: Onsite – Government...  ..., driving incident response analysis, and contributing to threat hunt operations at the classified level. This is a hands-on technical... 
    Full time
    Work experience placement
    Flexible hours

    Revolutional, LLC

    Washington DC
    25 days ago
  •  ...security operations. Minimum of 1-2 years of supervisory, team lead, or shift lead experience preferred. Ability to obtain and...  ...visitor management systems. Understanding of risk management, threat identification, and security assessment principles. Ability to... 
    For contractors
    Work at office
    Shift work
    Rotating shift

    T47 INTERNATIONAL, INC.

    Bowie, MD
    20 days ago
  • Lead Cyber Security Specialist This is currently a remote position in our SOC, but return...  ...event triage, intrusion analysis, threat trends, malware, and anomalous behavior....  ...intrusion detection, malware analysis, threat hunting and all phases of security event monitoring... 
    Part time
    Work experience placement
    Remote work
    Day shift

    Samprasoft

    Washington DC
    2 days ago
  • $175k - $210k

    Senior OPSEC Threat & Risk Assessment Specialist / Deputy OPSEC Lead Belong. Connect. Grow. with KBR! KBR’s National Security Solutions team provides high-end engineering and advanced technology solutions to our customers in the intelligence and national security communities... 
    Temporary work
    For contractors
    Local area
    Immediate start
    Relocation package
    Flexible hours

    KBR Careers

    Alexandria, VA
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to AOUSC - Threat Hunt Lead. Be the first to apply!