Cyber Threat Hunter

4 weeks ago


Ashburn, United States Base One Technology Full time

Primary Responsibilities

The ideal Cyber Threat Hunter is someone who is process driven, curious, and enjoys identifying patterns and anomalies in data that are not immediately obvious. The Cyber Threat Hunter will:

Create Threat Models to better understand the agency IT Enterprise, identify defensive gaps, and prioritize mitigations
Author, update, and maintain SOPs, playbooks, work instructions
Utilize Threat Intelligence and Threat Models to create threat hypotheses
Plan and scope Threat Hunt Missions to verify threat hypotheses
Proactively and iteratively search through systems and networks to detect advanced threats
Analyze host, network, and application logs in addition to malware and code
Prepare and report risk analysis and threat findings to appropriate stakeholders
Create, recommend, and assist with development of new security content as the result of hunt missions to include signatures, alerts, workflows, and automation
Coordinate with different teams to improve threat detection, response, and improve overall security posture of the Enterprise



Required Education/Experience

BS degree in Science, Technology, Engineering, Math or related field and 3 years of prior relevant experience with a focus on CyberSecurity or Masters with 1 years of prior relevant experience.



Basic Qualifications

NEW REQUIREMENT as of 6/27/2022: In addition to uploading the resume, please email us a copy of the candidate’s current certifications (actual certificate) as a way to validate that certs are current and active.



The ideal candidate will have the following qualifications:

Expertise in network and host based analysis and investigation
Demonstrated experience planning and executing threat hunt missions
Understanding of complex Enterprise networks to include routing, switching, firewalls, proxies, load balancers
Working knowledge of common (HTTP, DNS, SMB, etc) networking protocols
Familiar with operation of both Windows and Linux based systems
Proficient with scripting languages such as Python or PowerShell
Familiarity with Splunk Search Processing Language (SPL) and/or Elastic Domain Specific Language (DSL)
The candidate must currently possess a Top Secret Clearance. In addition to clearance requirement, all CBP personnel must have a current or be able to favorably pass a 5 year background investigation (BI).
Should have 2 years of experience serving as a SOC Analyst or Incident Responder
Ability to work independently with minimal direction; self-starter/self-motivated



Must have One of the following certifications:

CCFP – Certified Cyber Forensics Professional

CCNA Security

CCNP Security

CEH – Certified Ethical Hacker

CHFI – Computer Hacking Forensic Investigator

CISSP – Certified Information Systems Security

CIRC

ECES – EC-Council Certified Encryption Specialist

ECIH – EC-Council Certified Incident Handler

ECSA – EC-Council Certified Security Analyst

ECSS – EC-Council Certified Security Specialist

EnCE

ENSA – EC-Council Network Security Administrator

FIWE

GCFA – Forensic Analyst

GCFE – Forensic Examiner

GCIH – Incident Handler

GISF – Security Fundamentals

GNFA – Network Forensic Analyst

GREM – Reverse Engineering Malware

GWEB – Web Application Defender

GXPN – Exploit Researcher and Advanced Penetration Tester

LPT – Licensed Penetration Tester

OSCE (Certified Expert)

OSCP (Certified Professional)

OSEE (Exploitation Expert)

OSWP (Wireless Professional)

WFE-E-CI

FTK-WFE-FTK

CompTIA Cyber Security Analyst (CySA+)

CompTIA Linux Network Professional (CLNP)

CompTIA PenTest+

GCTI – Cyber Threat Intelligence

GOSI – Open Source Intelligence

CTIA – Certified Threat Intelligence Analyst

Splunk Core Certified Advanced Power User

Splunk Core Certified Consultant

Splunk SOAR Certified Automation Developer

IACRB Certified Security Awareness Practitioner (CSAP)


  • Cyber Threat Hunter

    2 weeks ago


    ashburn, United States Base One Technology Full time

    Primary Responsibilities The ideal Cyber Threat Hunter is someone who is process driven, curious, and enjoys identifying patterns and anomalies in data that are not immediately obvious. The Cyber Threat Hunter will:Create Threat Models to better understand t...

  • Cyber Threat Analyst

    4 hours ago


    Ashburn, United States Gray Tier Technologies LLC Full time

    Primary Responsibilities: Shift schedule: 7pm-7am, Thurs-Sat, every other Wednesday. · Utilize state of the art technologies such as Endpoint Detection & Response tools, log analysis (Splunk) and possibly network forensics (full packet capture solution) to perform hunt and investigative activity to examine endpoint and network-based data. · Conduct log...

  • Cyber Security Analyst

    2 months ago


    Ashburn, United States IMPYRIAN Full time

    Job DescriptionJob DescriptionCOMPANY OVERVIEWAt Impyrian, our commitment to excellence, client-centric approach, and deep industry expertise set us apart. We strive to be a trusted partner for organizations seeking to embrace digital transformation, bolster cybersecurity, streamline operations, leverage advanced audio-visual technologies, drive successful...


  • Ashburn, United States Customs And Border Protection Full time

    This position starts at a salary of $117,962.00 (GS-13, Step 1) to $153,354.00 (GS-13, Step 10) with promotion potential to $153,354 (GS-13 Step 10). In this position, you will perform the typical work assignments below: Fusing multiple intelligence disciplines to assess cyber threat capabilities of current and emerging threats to drive insight to inform...


  • Ashburn, Virginia, United States Customs And Border Protection Full time

    This position starts at a salary of $117, GS-13, Step 1) to $153, GS-13, Step 10) with promotion potential to $153,354 (GS-13 Step 10).In this position, you will perform the typical work assignments below:Fusing multiple intelligence disciplines to assess cyber threat capabilities of current and emerging threats to drive insight to inform...


  • Ashburn, United States USAJobs Full time

    DutiesThis position starts at a salary of $117,962.00 (GS-13, Step 1) to $153,354.00 (GS-13, Step 10) with promotion potential to $153,354 (GS-13 Step 10).In this position, you will perform the typical work assignments below: Fusing multiple intelligence disciplines to assess cyber threat capabilities of current and emerging threats to drive insight to...


  • Ashburn, United States Leidos Full time

    Description We are seeking a Cybersecurity Strategy Specialist to join our fast-paced cyber prime contract team. As a key player in preventing, identifying, and eradicating cyber threats to our networks, you will be responsible for developing and communicating strategies that keep us at the forefront of our industry. This role requires collaborating with...


  • Ashburn, United States Base One Technologies Full time

    Our Ashburn VA based client is looking for multiple Senior Incident Response Analyst. If you are qualified for this position, please email your updated resume in word format to Required Education/Experience A bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or related field PLUS 4 years of experience in incident...


  • Ashburn, United States Agile Defense Full time

    Agile Defense We are in the business of innovation through information technology and cybersecurity, delivered exceptionally. View company page Agile Defense provides leading-edge Digital Transformation solutions to support and advance our customers' mission. We deliver innovative and high-quality services to our customers worldwide through an empowered and...


  • Ashburn, United States Visa Full time

    Company Description Visa is a world leader in digital payments, facilitating more than 215 billion payments transactions between consumers, merchants, financial institutions and government entities across more than 200 countries and territories each year. Our mission is to connect the world through the most innovative, convenient, reliable and secure...


  • Ashburn, United States Agile Defense Full time

    You will need to login before you can apply for a job. Incident Response Analyst with Security Clearance Agile Defense provides leading–edge Digital Transformation solutions to support and advance our customers' mission. We deliver innovative and high–quality services to our customers worldwide through an empowered and engaged workforce. Requisition #:...

  • Penetration Tester

    2 months ago


    Ashburn, United States Gray Tier Technologies LLC Full time

    Gray Tier Technologies is looking for a Penetration Tester to support Department of Homeland Security (DHS), Customs and Border Protection (CBP) Security Operations Center (SOC) which is a US Government program responsible to prevent, identify, contain and eradicate cyber threats to CBP networks through monitoring, intrusion detection and protective security...


  • Ashburn, United States Gray Tier Technologies LLC Full time

    Gray Tier Technologies is looking for a Penetration Tester to support Department of Homeland Security (DHS), Customs and Border Protection (CBP) Security Operations Center (SOC) which is a US Government program responsible to prevent, identify, contain and eradicate cyber threats to CBP networks through monitoring, intrusion detection and protective security...


  • Ashburn, United States Gray Tier Technologies LLC Full time

    Department of Homeland Security (DHS), Enterprise Security Operations Center (ESOC) Support Services is a US Government program responsible to monitor, detect, analyze, mitigate, and respond to cyber threats and adversarial activity on the DHS Enterprise. The DHS SOC has primary responsibility for monitoring and responding to security events and incidents...


  • Ashburn, United States Esmcorp Full time

    Enterprise Solutions and Management (ESM) is a rapidly growing government contractor that provides strategic IT services that meet mission needs for Defense and Federal customers. We are hiring a Sr Cybersecurity Analyst TL (KP) for an exciting opportunity located in Ashburn, Va. Job Description and Responsibilities Exciting opportunity supporting a...

  • Cybersecurity SME

    2 months ago


    Ashburn, United States Family Promise of NorthCentral Palm Beach County Full time

    Enterprise Solutions and Management (ESM) is a rapidly growing government contractor that provides strategic IT services that meet mission needs for Defense and Federal customers. We are hiring a Cybersecurity SME (real KP) for an exciting opportunity located in Ashburn, Va. Job Description and Responsibilities Exciting opportunity supporting a Department...

  • Cybersecurity SME

    2 months ago


    Ashburn, United States ESM Full time

    Job DescriptionJob DescriptionEnterprise Solutions and Management (ESM) is a rapidly growing government contractor that provides strategic IT services that meet mission needs for Defense and Federal customers. We are hiring a Cybersecurity SME (real KP) for an exciting opportunity located in Ashburn, Va. Job Description and ResponsibilitiesExciting...


  • Ashburn, United States ESM Full time

    Job DescriptionJob DescriptionEnterprise Solutions and Management (ESM) is a rapidly growing government contractor that provides strategic IT services that meet mission needs for Defense and Federal customers. We are hiring a Sr Cybersecurity Analyst TL (KP) for an exciting opportunity located in Ashburn, Va. Job Description and ResponsibilitiesExciting...

  • Director - SOC

    4 weeks ago


    Ashburn, United States Visa Full time

    Job DescriptionJob DescriptionCompany DescriptionVisa is a world leader in payments and technology, with over 259 billion payments transactions flowing safely between consumers, merchants, financial institutions, and government entities in more than 200 countries and territories each year. Our mission is to connect the world through the most innovative,...


  • Ashburn, United States Visa Full time

    Job Description Make a Difference. Join Visa’s newly formed, cutting-edge Risk Operations Center (ROC). The ROC is a critical priority of executive leadership and focuses on the fast identification and mitigation of high impact fraud attempts in the global payment ecosystem. This team will operate 24/7 working 12-hour shifts. The schedule will be...