Position Summary
Strategic Operational Solutions (STOPSO) is seeking a Threat Hunter to support the U.S. Army Reserve Command (USARC) Defensive Cyberspace Operations Mission Support Services (DCOMSS) program at Fort Bragg, North Carolina. Find adversary activity through hypothesis-driven hunts that combine defensive telemetry and cyber threat intelligence. The Threat Hunter develops findings and detection improvements for Blue Team and CTI operations.
Essential Duties and Responsibilities
• Develop hunt hypotheses from adversary tactics, intelligence, indicators, and observed telemetry gaps.
• Search SIEM, EDR, NetFlow, packet, host, authentication, and CTI data for complex intrusion activity.
• Analyze findings, distinguish benign behavior from threats, and escalate actionable activity for incident response.
• Develop and validate correlation rules, signatures, and host-based detections with authorized sensor stakeholders.
• Document hunt objectives, methods, data sources, evidence, coverage gaps, and recommended actions.
• Coordinate indicator packages and lessons learned with CTI, Blue Team, and exercise personnel.
• Perform other duties as assigned consistent with the position's responsibilities, qualifications, clearance, and authorized scope.
Required Qualifications
Education and Experience
• Minimum 3 years of documented relevant experience. Relevant threat hunting, intrusion analysis, detection development, SIEM/network analysis, and CTI integration experience.
• DoD Cyber Workforce Framework (DCWF) 511, Cyber Defense Analyst, Advanced proficiency, and DCWF 171, Cyber Threat Intelligence Analyst, Intermediate proficiency.
• Meet DoDM 8140.03 qualification requirements for every assigned work role and proficiency through an approved education, training, certification, or authorized experience route before independent cyber work. Document work-role appointment and qualification; maintain required residential qualification and continuing learning. A higher-level approved option may qualify the same role at a lower level.
• Current matrix-listed certification options for 511 Advanced: CBROPS, CFR, CySA+, GCFA, GCIA, GICSP. The additional 171 Intermediate intelligence qualification must be verified under the Government-approved criteria.
Knowledge, Skills and Abilities
• Demonstrated knowledge of Threat hunting, intrusion analysis, MITRE ATT&CK, adversary TTPs, cyber threat intelligence, and detection engineering.
• Proficiency with SIEM, EDR, NetFlow, packet capture, YARA, Snort or Suricata, and host telemetry appropriate to assigned duties and approved access.
• Ability to produce accurate records, explain findings and decisions, and follow approved procedures and security requirements.
• Strong written and verbal communication skills and sound judgment when coordinating with technical staff and Government stakeholders.
• Strong organizational skills, confidentiality, and ability to work independently and collaboratively in a mission-focused environment.
Preferred Qualifications
• Experience hunting across classified DoD cyber defense environments.
• Relevant DoD or enterprise IT experience with mission tooling and operational reporting.
Security Clearance
Active TS/SCI clearance and ability to maintain required SCI indoctrination and assigned system access. U.S. citizenship is required.
Supervisory Responsibilities
No formal supervisory responsibilities; provides technical findings and detection guidance.
Work Environment and Physical Requirements
Work is primarily performed on site in a secure Government facility using computer systems and standard office equipment. The employee must be able to perform sustained computer-based analysis or coordination, communicate effectively, and support operational activities outside standard business hours when assigned. Mission-essential watch roles may include shifts, weekends, and holidays.
Reasonable accommodations may be made to enable qualified individuals with disabilities to perform the essential functions of the position.
Travel
Occasional local, CONUS, or OCONUS travel may be required for authorized mission activities, exercises, assessments, or conferences.