Who we're looking for:
We are seeking a highly capable Senior Incident Responder / Threat Hunter for a potential opportunity with demonstrated experience in proactive threat hunting, cyber threat intelligence integration, incident investigation and digital evidence handling. The ideal candidate will possess strong investigative instincts, a deep understanding of adversary Tactics, Techniques and Procedures (TTPs) and the ability to translate findings into defensive action. The Sr. Incident Responder / Threat Hunter role leads structured threat hunts, complex Incident Response (IR) actions, technical investigations and forensic fact-finding efforts to detect and mitigate malicious activity across enterprise environments. This is a unique opportunity to shape the growth, development and culture of an exciting and fast-growing company in the cybersecurity market. Employment for this position is dependent on the successful award of the contract.
What you'll be doing:
- Lead structured monthly threat hunts, documenting hypotheses, rationale, methods, findings, what is being hunted, why the hunt is being conducted and recommended detection improvements.
- Perform proactive threat hunting across available telemetry sources to detect, identify and neutralize malicious activity and cybersecurity threats that evade traditional perimeter controls.
- Lead or support IR, reporting, handling and resolution activities, conducting technical investigations and fact-finding for suspected or confirmed security incidents and security concerns.
- Perform cybersecurity threat intelligence gathering from open and closed sources to integrate threat intelligence into hunts, detections and operational alerting capabilities for specific systems and applications.
- Perform digital forensic investigations to collect, preserve and analyze digital evidence, supporting comprehensive IR, fact-finding and technical coordination with IR stakeholders.
- Perform day-to-day continuous monitoring telemetry reviews and log analysis to support ongoing threat detection, event tracking and incident investigations.
- Identify gaps in detection coverage and recommend improvements to reduce risk, improve visibility and track metrics related to detection queries and identified security gaps.
What you need to know:
- Experience in IR, threat hunting and cyber threat intelligence analysis.
- Familiarity with adversary TTPs, detection engineering concepts and forensic handling practices.
- Strong analytical and investigative skills with the ability to derive actionable conclusions from telemetry and intelligence.
- Experience documenting hunt results, lessons learned and recommendations for operational improvement.
- Ability to communicate technical findings to both technical and non-technical audiences.
Must have's:
- Bachelor's degree from an accredited university; a postgraduate degree from an accredited university may substitute for 6 years of experience.
- 10+ years of relevant work experience.
- Proven ability to analyze complex requirements and translate them into clear, actionable tasks and processes through critical thinking.
- Applicants must currently be a U.S. citizen and eligible to obtain and maintain a security clearance, in compliance with federal contract requirements.
Beneficial to have:
- Active DOE Q or equivalent DoD Top Secret clearance.
Where it's done:
- Onsite (Albuquerque, NM).