AOUSC - Cyber Threat Intelligence & Threat Hunting Lead

cFocus Software Inc
  • Washington, DC
    12 days ago

    Job Description

    Position Title

    Cyber Threat Intelligence & Threat Hunting Lead

    Position Overview

    The Cyber Threat Intelligence & Threat Hunting Lead will oversee integrated cyber threat intelligence (CTI), detection engineering, and proactive threat hunting operations supporting enterprise cyber defense missions.

    The Lead will drive development of intelligence-driven detections, hunt methodologies, adversary tracking, SIEM content engineering, and operational threat-informed defense capabilities.

    Key Responsibilities

    • Lead CTI, detection engineering, and threat hunting operations.

    • Develop intelligence-driven detection and hunt strategies.

    • Produce operational and strategic threat intelligence reporting.

    • Develop and maintain:

    • SIEM detections,

    • analytics,

    • correlation rules,

    • behavioral detections,

    • and hunt playbooks.

    • Conduct hypothesis-based threat hunting aligned to:

    • MITRE ATT&CK,

    • adversary TTPs,

    • malware campaigns,

    • and emerging threats.

    • Integrate CTI into SOC workflows, detection engineering, and incident response operations.

    • Analyze:

    • malware trends,

    • adversary infrastructure,

    • campaigns,

    • indicators,

    • and attack patterns.

    • Support automation and SOAR integration initiatives.

    • Brief executives and technical leadership on emerging threats and operational risk.

    Required Qualifications

    • 10+ years of cybersecurity operations experience.

    • 5+ years supporting CTI, threat hunting, or detection engineering programs.

    • Experience with:

    • Splunk,

    • Sentinel,

    • CrowdStrike,

    • EDR telemetry,

    • detection content engineering,

    • and intelligence platforms.

    • Strong understanding of:

    • MITRE ATT&CK,

    • adversary tradecraft,

    • malware analysis,

    • and intelligence analysis methodologies.

    • Experience developing:

    • SIEM detections,

    • hunt analytics,

    • detection tuning,

    • and operational reporting.

    Preferred Certifications

    • GCTI
    • GCFA
    • GCIH
    • GMON
    • GCDA
    • CISSP
    • Splunk Security certifications

    Numbers & Facts

    LocationWashington, DC

    Skills

    • Automationunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Computer Telephony Integration (CTI)unmatched
    • Cyber Threat Huntingunmatched
    • Emerging Technologyunmatched
    • GCFA - GIAC Certified Forensic Analystunmatched
    • GCIH - GIAC Certified Incident Handlerunmatched
    • Huntingunmatched
    • Incident Responseunmatched
    • Internet Securityunmatched
    • Operational Strategyunmatched
    • Operational Supportunmatched
    • Riskunmatched
    • Security Attacksunmatched
    • Security Information and Event Management (SIEM)unmatched
    • Splunkunmatched
    • Technical Leadershipunmatched
    • Technical Presentationunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder