Threat Hunt Analyst with Security Clearance

4 weeks ago


Ashburn, United States Base One Technologies Full time
Threat Hunt Analyst Mid
Primary Responsibilities
• Create Threat Models to better understand the Agency's IT Enterprise, identify defensive gaps, and prioritize mitigations
• Author, update, and maintain SOPs, playbooks, work instructions
• Utilize Threat Intelligence and Threat Models to create threat hypotheses
• Plan and scope Threat Hunt Missions to verify threat hypotheses
• Proactively and iteratively search through systems and networks to detect advanced threats
• Analyze host, network, and application logs in addition to malware and code
• Prepare and report risk analysis and threat findings to appropriate stakeholders
• Create, recommend, and assist with development of new security content as the result of hunt missions to include signatures, alerts, workflows, and automation.
• Coordinate with different teams to improve threat detection, response, and improve overall security posture of the Enterprise Basic Qualifications
• Positions at this career level typically require BS degree or equivalent and 2-4 years of prior relevant experience, or a master’s with less than 2 years, in order to operate within the scope contemplated by the level.
• The candidate must currently possess a Top Secret Clearance. In addition to clearance requirement, all CBP personnel must have a current or be able to favorably pass a 5 year background investigation (BI).
• Experience in the areas of incident detection and response, malware analysis, or computer forensics. Required Education/Experience
BS degree or equivalent and 2-4 years of prior relevant experience, or a master’s with less than 2 years, in order to operate within the scope contemplated by the level. Preferred Qualifications
• Expertise in network and host-based analysis and investigation
• Demonstrated experience planning and executing threat hunt missions
• Understanding of complex Enterprise networks to include routing, switching, firewalls, proxies, load balancers
• Working knowledge of common (HTTP, DNS, SMB, etc) networking protocols
• Familiar with operation of both Windows and Linux based systems
• Proficient with scripting languages such as Python or PowerShell
• Familiarity with Splunk Search Processing Language (SPL) and/or Elastic Domain Specific Language (DSL)
• Demonstrated experience triaging and responding to APT activities.
• Experience working with various technologies and platform such as AWS, Azure, O365, containers, etc.
• Understanding of current cyber threat landscape, the different tactics commonly used by adversaries and how you would investigate, contain and recover against their attacks. Certifications
Must have at least one of the following certifications: CCFP – Certified Cyber Forensics Professional
CCNA Security
CCNP Security
CEH – Certified Ethical Hacker
CHFI – Computer Hacking Forensic Investigator
CISSP – Certified Information Systems Security
ECES – EC-Council Certified Encryption Specialist
ECIH – EC-Council Certified Incident Handler
ECSA – EC-Council Certified Security Analyst
ECSS – EC-Council Certified Security Specialist
EnCE
ENSA – EC-Council Network Security Administrator
GCFA – Forensic Analyst
GCFE – Forensic Examiner
GCIH – Incident Handler
GISF – Security Fundamentals
GNFA – Network Forensic Analyst
GREM – Reverse Engineering Malware
GWEB – Web Application Defender
GXPN – Exploit Researcher and Advanced Penetration Tester
LPT – Licensed Penetration Tester
OSCE (Certified Expert)
OSCP (Certified Professional)
OSEE (Exploitation Expert)
OSWP (Wireless Professional)
CIRC
FIWE
WFE-E-CI
FTK-WFE-FTK Preferred Qualifications
SANS GCIA (GIAC Certified Intrustion Analyst)
SANS GNFA (GIAC Network Forensic Analyst)
SANS GWAPT (GIAC Web Application Pentester)
SANS GPEN (GIAC Penetration Tester)
Offensive Security Certified Professional (OSCP)

  • Ashburn, United States Anonymous Employer Full time

    Primary ResponsibilitiesThe ideal Cyber Threat Hunter is someone who is process driven, curious, and enjoys identifying patterns and anomalies in data that are not immediately obvious. The Cyber Threat Hunter will:• Create Threat Models to better understand the Agency IT Enterprise, identify defensive gaps, and prioritize mitigations• Author, update, and...


  • Ashburn, United States Gray Tier LLC Full time

    Primary Responsibilities: The ideal Cyber Threat Hunter is someone who is process driven, curious, and enjoys identifying patterns and anomalies in data that are not immediately obvious. The Cyber Threat Hunter will:• Create Threat Models to better understand the CBP IT Enterprise, identify defensive gaps, and prioritize mitigations• Author, update, and...


  • Ashburn, United States Base One Technologies Full time

    Primary Responsibilities• Create Threat Models to better understand the Agency's IT Enterprise, identify defensive gaps, and prioritize mitigations• Author, update, and maintain SOPs, playbooks, work instructions• Utilize Threat Intelligence and Threat Models to create threat hypotheses• Plan and scope Threat Hunt Missions to verify threat...


  • Ashburn, United States Base One Technologies Full time

    Primary Responsibilities• Create Threat Models to better understand the DHS IT Enterprise, identify defensive gaps, and prioritize mitigations• Author, update, and maintain SOPs, playbooks, work instructions• Utilize Threat Intelligence and Threat Models to create threat hypotheses• Plan and scope Threat Hunt Missions to verify threat hypotheses•...


  • Ashburn, United States Base One Technologies Full time

    Primary ResponsibilitiesPerform research on current threats and vulnerabilities. Will be responsible for authoring security advisories. Manage enterprise vulnerability compliance and will conduct vulnerability assessments of IT systems. This position location is Ashburn, Virginia Basic QualificationsNEW REQUIREMENT as of 6/27/2022: In addition to uploading...


  • Ashburn, United States Base One Technologies Full time

    Our Ashburn VA based client is looking for multiple Senior Incident Response Analyst. If you are qualified for this position, please email your updated resume in word format to Required Education/ExperienceA bachelor’s degree in Computer Science, Engineering, Information Technology, Cybersecurity, or related field PLUS 4 years of experience in incident...


  • Ashburn, United States Base One Technologies Full time

    Primary Responsibilities• Identify gaps in malicious activity detection capabilities• Create new signatures / rules to improve detection of malicious activity• Test and tune existing signatures / rules to ensure low rate of false positives• Assist in playbook development for alert triage and Incident Response• Define and implement alert and threat...


  • Ashburn, United States Base One Technologies Full time

    Required Education/ExperienceBS degree in Science, Technology, Engineering, Math or related field and 8 years of prior relevant experience with a focus on cyber security or Masters with 6 years of prior relevant experience. Should have 5 years of experience serving as a digital media Primary Responsibilities• Identify gaps in malicious activity detection...


  • Ashburn, United States Agile Defense Full time

    Agile Defense We are in the business of innovation through information technology and cybersecurity, delivered exceptionally. View company page Agile Defense provides leading-edge Digital Transformation solutions to support and advance our customers' mission. We deliver innovative and high-quality services to our customers worldwide through an empowered and...


  • Ashburn, United States Base One Technologies Full time

    Our Ashburn VA based client is looking for a Detection Engineer. If you are qualified for this position. Please email me your updated resume in word format to Work location: Ashburn VA Detection EngineerPrimary Responsibilities• Identify gaps in malicious activity detection capabilities• Create new signatures / rules to improve detection of malicious...


  • Ashburn, United States CareerBuilder Full time

    BS degree in Science, Technology, Engineering, Math or related field and 8 years of prior relevant experience with a focus on cyber security or Masters with 6 years of prior relevant experience. Should have 5 years of experience serving as a digital media Primary Responsibilities Identify gaps in malicious activity detection capabilities Create new...


  • Ashburn, United States Anonymous Employer Full time

    Our Arlington VA based client is looking for Cyber Vulnerability Assessment Analyst. If you are qualified for this position, please email your updated resume in word format to Required Education/ExperienceBachelors’ degree from an accredited college in a related discipline, or equivalent experience/combined education, with 2-4 years of professional...


  • Ashburn, United States Base One Technologies Full time

    Our Ashburn VA based client is looking for a Systems Engineer. If you are qualified for this position, please email your updated resume in word format to Primary ResponsibilitiesPerform research on current threats and vulnerabilities. Will be responsible for authoring security advisories. Manage enterprise vulnerability compliance and will conduct...


  • Ashburn, United States Base One Technologies Full time

    Primary ResponsibilitiesNight Shift Back -Shift schedule: 7pm-7am, Thur-Sat, every other Wednesday.• Utilize state of the art technologies such as host forensics tools(FTK/Encase), Endpoint Detection & Response tools, log analysis (Splunk) and network forensics (full packet capture solution) to perform hunt and investigative activity to examine endpoint...


  • Ashburn, United States Leidos Full time

    **Description** Our Security Operations Center (SOC) Support Services is a US Government program responsible to monitor, detect, analyze, mitigate, and respond to cyber threats and adversarial activity on the government Enterprise. We have primary responsibility for monitoring and responding to security events and incidents detected at the Trusted Internet...


  • Ashburn, United States Base One Technologies Full time

    Our Ashburn VA based client is looking for a Tier 2 IR Night Shift Front. This position requires an active DHS Public Trust Clearance. If you are interested in this opening, please forward a copy of your updated resume in word format to Must Have One of the Following J3 Certifications GCIH – Incident Handler GCFA – Forensic Analyst GCFE – Forensic...


  • Ashburn, United States Base One Technologies Full time

    Our Ashburn VA based client is looking for a Tier 2 IR Night Shift Front. This position requires an active Secret and DHS Public Trust Clearance. If you are interested in this opening, please forward a copy of your updated resume in word format to Must Have One of the Following J3 CertificationsGCIH – Incident HandlerGCFA – Forensic AnalystGCFE –...


  • Ashburn, United States Base One Technologies Full time

    Tier 2 IR Night ShiftNight Shift FrontShift schedule: 7pm-7am, Sun-Tues, every other Wednesday.Primary Responsibilities• Utilize state of the art technologies such as host forensics tools(FTK/Encase), Endpoint Detection & Response tools, log analysis (Splunk) and network forensics (full packet capture solution) to perform hunt and investigative activity to...


  • Ashburn, United States Anonymous Employer Full time

    Primary Responsibilities • Perform internal and external pentest against systems to determine vulnerabilities and offer mitigation strategies. • Perform web app pentests • Perform vulnerability risk assessment • Perform physical pentests and social engineering • Perform cyber incident response as needed for programs Basic Qualifications Bachelors'...


  • Ashburn, United States Base One Technologies Full time

    Primary ResponsibilitiesPerform internal and external pentest against systems to determine vulnerabilities and offer mitigation strategies.Perform web app pentestsPerform vulnerability risk assessmentPerform physical pentests and social engineeringPerform cyber incident response as needed for programs Basic QualificationsBachelors’ degree from an...