|
Title: Cybersecurity Threat Analyst Subject Matter Expert IV Location: Alexandria, VA Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph Job Details:
- Serve as the senior technical authority for proactive threat hunting and adversary-focused analysis within the SOC
- Lead development of the SOC threat-hunting methodology, hunt lifecycle, prioritization model, documentation standards, quality criteria, and integration with watch operations and engineering
- Proactively search across enterprise network, endpoint, identity, SIEM, and other security telemetry for indicators of compromise and behavioral evidence of malicious activity that has evaded automated detection
- Develop and direct advanced hunt campaigns based on threat intelligence, adversary TTPs, mission priorities, predictive/advanced analytics, environmental changes, incidents, and identified detection gaps
- Assess and validate analytical or predictive models and determine whether identified patterns represent meaningful adversary behavior, benign activity, or require additional collection and analysis
- Lead complex analytical pivots across multiple sources and enclaves and direct expansion of scope when evidence indicates broader adversary activity
- Ensure actionable hunt findings are transitioned to incident response, watch operations, detection engineering, or security engineering with clear evidence and recommended actions
- Provide senior technical input to daily/weekly SOC reporting, leadership briefings, threat assessments, and defensive priorities
- Establish reusable hunt playbooks, analytical techniques, ATT&CK mappings, queries, knowledge repositories, and lessons-learned processes
- Mentor threat analysts at all levels and provide technical leadership for exercises, training, and proficiency development
- Identify telemetry and detection blind spots and work with engineering teams to improve collection, analytics, enrichment, and automated detection coverage
Requirements:
- Bachelor's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree
- Minimum of eight (8) years of relevant experience in addition to education level
- Expert-level hands-on experience in threat hunting, adversary analysis, advanced cyber defense analysis, or closely related work
- Demonstrated experience leading complex hunt campaigns and identifying malicious activity not detected through routine alerting
- Expert knowledge of adversary TTPs, MITRE ATT&CK, threat intelligence operationalization, network/endpoint/identity telemetry, and analytical methodologies
- Experience establishing or materially improving a threat-hunting or proactive cyber-defense program
- Experience translating hunt findings into detection engineering requirements and measurable defensive improvements
- Must possess current DoD 8570 IAT II or IAM II certification
- Experience working in a DoD or IC environment
- Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph
Equal Opportunity Employer/Veteran/Disabled
|