Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

AOUSC - Threat Hunt Lead

cFocus Software Incorporated

Job Description

Job Description

cFocus Software seeks a Threat Hunt Lead to join our program supporting the Administrative Office of the United States Courts (AOUSC). This position is Hybrid with the onsite location being in Washington, DC. This position requires a Public Trust clearance.
Qualifications:

  • Active Public Trust clearance
  • B.S. Computer Science, Information Technology, or a related field
  • 5+ years within IR in a large SOC (over 5,000 endpoints) with at least 3 years focused on proactive threat hunting or adversary emulation. 
  • 3+ years of experience with demonstrated proficiency in forming hypothesis, querying large datasets and identifying APT behavior. 
  • 2+ years’ experience with demonstrated proficiency in scripting languages including Python and PowerShell to develop new tools.
  • This role most closely aligns with the NICE work role PD-WRL-006 (Threat Analysis).
  • Active OSCP or GXPN certification
Duties:
  • Lead proactive threat hunting operations to identify Advanced Persistent Threats (APT), insider threats, malicious activity, and anomalous behaviors that evade traditional security controls.
  • Develop and execute hypothesis-driven threat hunts leveraging threat intelligence, adversary tactics, techniques, and procedures (TTPs), behavioral analytics, and anomalous telemetry.
  • Coordinate threat hunt activities within Agile two-week sprint cycles and ensure successful execution of all assigned hunt objectives and deliverables.
  • Develop Threat Hunt Execution Plans that define hunt hypotheses, objectives, technical methodologies, required telemetry, and investigative procedures.
  • Analyze endpoint, network, cloud, identity, SIEM, EDR, and log telemetry to identify indicators of compromise (IOCs), suspicious activity, and attack patterns.
  • Coordinate and escalate confirmed or suspected findings to the Cybersecurity Triage and Incident Response teams in accordance with the Judiciary SOC Incident Response Plan (JSOCIRP).
  • Collaborate with Detection Engineering teams to identify and remediate logging, telemetry, detection, or visibility gaps discovered during threat hunting operations.
  • Work closely with Cyber Threat Intelligence teams to operationalize intelligence, enrich investigations, and identify emerging threats impacting the Judiciary.
  • Conduct advanced analysis of threat actor behaviors, malware campaigns, phishing activity, suspicious infrastructure, and attack trends.
  • Develop detailed Threat Hunt Reports documenting hunt objectives, findings, TTPs, queries used, telemetry gaps, identified risks, and recommendations for improved detections.
  • Produce executive-level Hunt Sprint Reports summarizing hunt activities, operational impacts, recommendations, and emerging cybersecurity risks.
  • Provide real-time investigative support during cybersecurity incidents and high-priority threat investigations.
  • Perform analysis utilizing Splunk Enterprise Security, Microsoft Sentinel, Splunk SOAR, CrowdStrike, Qualys, ServiceNow, Jira, and other AO-approved security platforms.
  • Support the development and refinement of threat models tailored to Judiciary systems, high-value assets, and mission-critical environments.
  • Develop and maintain threat hunting SOPs, playbooks, technical procedures, and investigative methodologies aligned with AO and federal cybersecurity standards.
  • Support enterprise security awareness initiatives through threat briefings, technical reporting, and operational presentations.
  • Participate in weekly technical meetings, operational reviews, and status briefings with AO leadership and federal stakeholders.
  • Provide mentorship, technical guidance, and quality oversight to threat hunters and supporting analysts.
  • Support transition-in and transition-out activities, operational readiness, documentation development, and knowledge transfer activities.
  • Drive continuous improvement initiatives focused on detection coverage, telemetry enrichment, operational efficiency, and threat hunting maturity.

Powered by JazzHR

lD4K8q96QQ

Vacancy posted 21 days ago
Similar jobs that could be interesting for youBased on the AOUSC - Threat Hunt Lead in Washington DC vacancy
  • cFocus Software seeks a Threat Hunt Lead to join our program supporting the Administrative Office of the United States Courts (AOUSC). This position is Hybrid with the onsite location being in Washington, DC. This position requires a Public Trust clearance. Qualifications... 
    Suggested
    Full time
    Work at office

    cFocus Software Incorporated

    Washington DC
    21 days ago
  •  ...Position Title Cyber Threat Intelligence & Threat Hunting Lead Position Overview The Cyber Threat Intelligence & Threat Hunting Lead will oversee integrated cyber threat intelligence (CTI), detection engineering, and proactive threat hunting operations supporting... 
    Suggested
    Full time

    cFocus Software Incorporated

    Washington DC
    21 days ago
  •  ...A leading consulting firm is seeking a Security Operations Lead to oversee SOC functions and manage a team of Analysts and Engineers...  ...experience with specific expertise in incident response, threat hunting, and SIEM technologies like Splunk and ExtraHop. Responsibilities... 
    Suggested

    Accenture

    Washington DC
    2 days ago
  •  ...Job Description Job Description Position Title Threat Emulation & Readiness Lead / Red Team Lead Position Overview The Threat Emulation...  ...actor behaviors. Coordinate closely with SOC, CTI, Threat Hunt, and Detection Engineering teams. Assess detection and... 
    Suggested

    cFocus Software Incorporated

    Washington DC
    21 days ago
  •  ...seeks a Forensic and Malware Lead to join our program supporting...  ...of the United States Courts (AOUSC). This position is Hybrid with...  ...analysis of advanced persistent threats (APT), ransomware, phishing campaigns...  ...investigations and threat hunting operations. Coordinate... 
    Suggested
    Work at office

    cFocus Software Incorporated

    Washington DC
    21 days ago
  • $130k - $180k

     ...prioritizing speed, ownership, and execution over bureaucracy. Lead Cyber Threat Intelligence Analyst Location: Onsite – Government-controlled...  ...behavior Coordinate with SOC, incident response, and threat hunting teams to ensure CTI products are operationally relevant and... 
    Full time
    Work experience placement
    Flexible hours
    Shift work

    Revolutional

    Suitland, MD
    1 day ago
  •  ...Lead Cyber Threat Analyst Evolver Federal is seeking a Lead Cyber Threat Analyst to fulfil a requirement for a potential government client...  ...infrastructure. This role focuses on proactive threat hunting, intelligence analysis, and developing strategies to detect and... 
    Flexible hours

    Evolver Federal

    Washington DC
    4 days ago
  •  ...Position Title Insider Threat Program Lead Position Overview The Insider Threat Lead will design, mature, and oversee insider threat detection, analysis, and investigative support capabilities for a federal enterprise environment. The Lead will integrate user... 
    Full time

    cFocus Software Incorporated

    Washington DC
    21 days ago
  • cFocus Software seeks a Blue Team Lead to join our program supporting...  ...of the United States Courts (AOUSC). This position is Hybrid with...  ...aligned to current cyber threats, adversary tactics, techniques...  ...Detection Engineering, Threat Hunting, Incident Response, and Cyber... 
    Full time
    Work at office

    cFocus Software Incorporated

    Washington DC
    21 days ago
  •  ...recognize that our employees are our number one resource. If you are a problem-solving people-person, apply today! Position Title: Lead Cyber Threat Analyst Location: Washington, DC Position Summary The Lead Cyber Threat Analyst serves as the technical and... 
    For contractors
    Local area

    DirectViz Solutions

    Washington DC
    23 hours ago
  • ## Senior Lead Insider Threat Investigator (US)Postulerremote type: À distancelocations: Mount Laurel, New Jersey: Remote Charlotte (NC): Remote Port Charlotte (FL)time type: Temps pleinposted on: Publié aujourd'huitime left to apply: Date de fin : 3 juillet 2026 (Il reste... 
    Temporary work
    Work at office
    Local area
    Remote work
    Work from home
    Flexible hours

    TD Bank

    Laurel, MD
    1 day ago
  •  ...Description Job Description Position Title SOC Operations Lead / Managed Detection & Response (MDR) Lead Position Overview...  ...and incident impact assessments. Coordinate closely with Threat Hunting, CTI, Detection Engineering, and Incident Response teams.... 

    cFocus Software Incorporated

    Washington DC
    21 days ago
  •  ...Evolver Federal is seeking a Lead Incident Responder to fulfill a requirement for a...  ...TIC 3.0), lead investigations into complex threats, and deliver compliance reporting to federal...  ...' SELC/SDLC Knowledge of threat hunting methodologies and proactive detection strategies... 
    Contract work
    Flexible hours

    Evolver

    Washington DC
    23 hours ago
  • $135k - $216k

     ...farthest reaches of the galaxy. As the world's leading mission capability integrator and...  ...nexus between traditional and nontraditional threats across all domains: land, sea, space, air...  ...monitoring, alert creation, and threat hunting. ~Experience using Microsoft Azure access... 
    Contract work
    Temporary work
    Work at office
    Local area
    All shifts
    Shift work
    Afternoon shift

    Peraton

    Beltsville, MD
    2 days ago
  • $150k - $165k

     ...Job Description Job Description Position Title: Threat Intelligence Lead Location: Camp Springs, MD Employment Type: Full‑Time Salary Range: $150,000 - $165,000 Clearance Requirement: Ability to obtain and maintain Top Secret / SCI Position Overview... 
    Full time
    Immediate start
    Flexible hours

    Corinth

    Camp Springs, MD
    23 days ago
  • cFocus Software seeks a Cybersecurity Shift Lead to join our program supporting the Administrative Office of the United States Courts (AOUSC). This position is Hybrid with the onsite location being in Washington, DC. This position requires a Public Trust clearance.... 
    Full time
    Work at office
    Shift work

    cFocus Software Incorporated

    Washington DC
    21 days ago
  • $100k - $120k

     ...Description SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering...  ...SkyePoint Decisions is seeking a Cyber Hunt Team Leader to join our team supporting the...  ...Responsibilities: Leads proactive threat hunting missions and advanced analytics.... 
    Contract work
    Remote work

    SkyePoint Decisions

    Washington DC
    2 days ago
  •  ...EmergencyMD is seeking a Lead Incident Responder for a potential government client. This role will involve leading incident response operations, managing complex threats, and ensuring compliance with federal cybersecurity frameworks. The candidate must have a Bachelor... 

    EmergencyMD

    Washington DC
    3 days ago
  • $100k - $120k

     ...Native Corporation is seeking a Sr. Cybersecurity Incident Response Specialist in Washington, DC. This role involves monitoring cyber threats and ensuring the security of networks and systems. The ideal candidate should have a deep understanding of cybersecurity protocols... 

    Bering Straits Native Corporation

    Washington DC
    1 day ago
  •  ...protective measures, workplace violence prevention, behavioral threat assessment, investigations, training, and crisis response within...  ...implementations. Workplace Violence Prevention & Behavioral Threat Assessment Lead enterprise-wide Workplace Violence Prevention (WPVP) programs.... 
    Local area

    Fresenius Medical Care

    Washington DC
    2 days ago
  •  ...A cybersecurity and data operations firm is seeking Cyber Eviction Analysts to support the DHS's Hunt and Incident Response Team. The role requires extensive experience in incident response and the ability to think independently. Candidates must have a strong understanding... 

    Nightwing

    Arlington, VA
    1 day ago
  • $146.2k - $261.4k

     ...overseeing complex technical research and policy analysis projects, and leading multidisciplinary teams of policy researchers, engineers, and...  ...~ Ability to develop rigorous and comprehensive threat models and identify potential system vulnerabilities ~ Strong... 
    Fixed term contract
    Work experience placement
    Remote work
    Work from home

    RAND

    Washington DC
    4 days ago
  • $138k - $209k

     ...difference. You’ll work on projects that matter, alongside industry‑leading experts, in an environment that fosters innovation, drives...  ...teams in identifying, analyzing, and responding to cybersecurity threats. This role will develop incident response strategies, lead... 
    Contract work
    Temporary work

    AIS (Applied Information Sciences)

    Alexandria, VA
    2 days ago
  • $170k - $220k

     ...Job Title: SOC Lead Place of Performance: Springfield, VA Experience Level: Senior-Level (10+ years) About JFL Consulting...  ...clearance preferred but not required Experience with threat hunting frameworks and platforms Reverse engineering experience (IDA... 
    Temporary work
    Local area
    Immediate start
    All shifts
    Flexible hours
    Shift work
    Night shift
    Rotating shift

    JFL Consulting

    Springfield, VA
    4 days ago
  •  ...is seeking a Senior Cybersecurity Engineer / Offensive Security Lead to support high‑visibility federal and IC programs. This role...  .... Maintain currency in offensive tooling, TTPs, and emerging threat vectors Certifications: OSCP (minimum requirement) OSEP... 
    Full time

    Apogee Global Rms

    Washington DC
    23 hours ago
  •  ...Washington, DC Position Overview We are seeking a highly skilled Lead Incident Responder to manage and maintain critical security...  ...Information (PII), and coordinating remediation efforts. Cyber Threat Monitoring: Develop and maintain a Cyberthreat Dashboard for reporting... 
    Contract work
    For contractors
    Work at office
    Local area

    DirectViz Solutions

    Washington DC
    2 days ago
  • $150k - $170k

     ...Zachary Piper Solutions is seeking a SOC Lead to support a company focused on federal cybersecurity operations, network defense, and...  ...role defending sensitive systems against evolving cyber threats. Responsibilities for the SOC Lead include: Lead and... 
    Night shift

    Piper Companies

    Washington DC
    1 day ago
  •  ...Job Description Job Description Description: Joint Staff J5 Counter Threats and International Cooperation (DDCTIC) is seeking a highly skilled and proactive Lead Women Peace and Security (WPS) Expert. This position you will be a full-time member of Joint Staff J... 
    Full time
    Contract work
    Work at office

    Vistra Communications LLC

    Washington DC
    12 days ago
  • $150k - $170k

    Zachary Piper Solutions is seeking a SOC Lead to support a company focused on cybersecurity operations, engineering, and compliance for...  ...nation’s nuclear security infrastructure against evolving cyber threats. Responsibilities for the SOC Lead include: Lead and mentor... 

    Zachary Piper Solutions

    Washington DC
    23 hours ago
  • AECOM Hunt is seeking a Chemical Warfare Material Manager to support remediation services for federal clients. The role can be remote anywhere in the United States and will involve acting as a Deputy Program and Client Manager for USACE Huntsville Center. The position... 
    Remote job

    AECOM Hunt

    Arlington, VA
    23 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to AOUSC - Threat Hunt Lead. Be the first to apply!