AOUSC - Cyber Threat Intelligence & Threat Hunting Lead

Posted 14 Days Ago
Be an Early Applicant
Washington, DC, USA
In-Office
Expert/Leader
Software
The Role
Lead CTI, detection engineering, and threat hunting operations. Develop intelligence-driven detections, hunt playbooks, SIEM/analytics content, and SOAR integrations. Conduct hypothesis-based hunts aligned to MITRE ATT&CK, analyze malware and adversary campaigns, produce threat intelligence reporting, and brief executives on emerging threats and operational risk.
Summary Generated by Built In
Position Title
Cyber Threat Intelligence & Threat Hunting Lead
Position Overview
The Cyber Threat Intelligence & Threat Hunting Lead will oversee integrated cyber threat intelligence (CTI), detection engineering, and proactive threat hunting operations supporting enterprise cyber defense missions.
The Lead will drive development of intelligence-driven detections, hunt methodologies, adversary tracking, SIEM content engineering, and operational threat-informed defense capabilities.
Key Responsibilities
  • Lead CTI, detection engineering, and threat hunting operations.
  • Develop intelligence-driven detection and hunt strategies.
  • Produce operational and strategic threat intelligence reporting.
  • Develop and maintain:
    • SIEM detections,
    • analytics,
    • correlation rules,
    • behavioral detections,
    • and hunt playbooks.
  • Conduct hypothesis-based threat hunting aligned to:
    • MITRE ATT&CK,
    • adversary TTPs,
    • malware campaigns,
    • and emerging threats.
  • Integrate CTI into SOC workflows, detection engineering, and incident response operations.
  • Analyze:
    • malware trends,
    • adversary infrastructure,
    • campaigns,
    • indicators,
    • and attack patterns.
  • Support automation and SOAR integration initiatives.
  • Brief executives and technical leadership on emerging threats and operational risk.
Required Qualifications
  • 10+ years of cybersecurity operations experience.
  • 5+ years supporting CTI, threat hunting, or detection engineering programs.
  • Experience with:
    • Splunk,
    • Sentinel,
    • CrowdStrike,
    • EDR telemetry,
    • detection content engineering,
    • and intelligence platforms.
  • Strong understanding of:
    • MITRE ATT&CK,
    • adversary tradecraft,
    • malware analysis,
    • and intelligence analysis methodologies.
  • Experience developing:
    • SIEM detections,
    • hunt analytics,
    • detection tuning,
    • and operational reporting.
Preferred Certifications
  • GCTI
  • GCFA
  • GCIH
  • GMON
  • GCDA
  • CISSP
  • Splunk Security certifications

 

Skills Required

  • 10+ years of cybersecurity operations experience
  • 5+ years supporting CTI, threat hunting, or detection engineering programs
  • Experience with Splunk
  • Experience with Microsoft Sentinel
  • Experience with CrowdStrike
  • Experience with EDR telemetry
  • Experience with detection content engineering
  • Experience with intelligence platforms
  • Strong understanding of MITRE ATT&CK
  • Strong understanding of adversary tradecraft
  • Strong understanding of malware analysis
  • Strong understanding of intelligence analysis methodologies
  • Experience developing SIEM detections, hunt analytics, detection tuning, and operational reporting
  • Support automation and SOAR integration initiatives
  • Ability to brief executives and technical leadership on emerging threats and operational risk
  • GCTI
  • GCFA
  • GCIH
  • GMON
  • GCDA
  • CISSP
  • Splunk Security certifications
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Largo, MD
25 Employees
Year Founded: 2006

What We Do

Established in 2006, cFocus Software automates FedRAMP compliance and develops government chatbots for the Azure Government Cloud, Office 365, and SharePoint. cFocus Software is the exclusive vendor of ATO (Authority To Operate) as a Service™, which automates FedRAMP compliance for the Azure Government Cloud and Office 365. Contact Us for a demo of ATO as a Service™ or a FREE government chatbot proof of concept project today!

Similar Jobs

Wells Fargo Logo Wells Fargo

Operations Coordinator

Fintech • Financial Services
Hybrid
Washington, DC, USA
205000 Employees
25K-33K Hourly
Hybrid
Washington, DC, USA
205000 Employees
119K-224K Annually

Wells Fargo Logo Wells Fargo

Counsel

Fintech • Financial Services
Hybrid
Washington, DC, USA
205000 Employees
215K-355K Annually

Enverus Logo Enverus

Owner Relations Agent - 26291

Big Data • Information Technology • Software • Analytics • Energy
In-Office or Remote
6 Locations
1800 Employees
55K-59K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account