Cyber Threat Hunter, Mid

Booz Allen HamiltonBethesda, MD
$62,000 - $141,000Remote

About The Position

The Threat Hunter supports a Cybersecurity Operations Division by proactively identifying malicious activity, uncovering hidden threats, and strengthening the organization’s defensive posture. This role conducts hypothesis‑driven hunts across enterprise networks, leveraging threat intelligence, adversary TTPs, and behavioral analytics to detect early indicators of compromise. The hunter performs deep‑dive analysis of logs, endpoint telemetry, and network data to validate findings, uncover patterns, and escalate confirmed threats to SOC and IR teams. This position contributes to the continuous improvement of detection capabilities by developing new analytics, refining existing logic, and identifying visibility gaps across the environment. The hunter documents repeatable workflows, produces high‑quality hunt reports, and briefs leadership and mission stakeholders on emerging threats, hunt outcomes, and recommended defensive improvements. The role also collaborates closely with SOC, IR, CTI, and platform engineering teams to operationalize intelligence, integrate new data sources, and mature the organization’s hunt program.

Requirements

  • 2+ years of experience analyzing adversary behaviors, developing hunt hypotheses, and executing structured, hypothesis-driven hunt operations
  • Experience conducting hunts aligned to MITRE ATT&CK and frameworks such as Splunk PEAK
  • Experience leveraging threat intelligence and emerging adversary TTPs to develop hunt hypotheses
  • Experience performing advanced analytics, log analysis, and forensic triage to support CI and insider threat investigations
  • Experience maintaining documentation, including SOPs, analytic development notes, deployment records, and review cycles that provide repeatable and auditable workflows
  • Ability to translate hunt findings into actionable improvements such as detection enhancements, visibility recommendations, and updated playbooks
  • Ability to obtain and maintain a Public Trust or Suitability/Fitness determination based on client requirements
  • Bachelor’s degree

Nice To Haves

  • Experience with Splunk Enterprise, SPL queries, and analytic development
  • Experience with behavioral analytics, anomaly detection, and statistical or machine learning-based hunting techniques
  • Experience supporting insider threat programs, CI investigations, or sensitive case forensics
  • Possession of strong written and verbal communication skills, for producing hunt reports, briefing leadership, and collaborating with SOC and IR teams

Responsibilities

  • Proactively identifying malicious activity
  • Uncovering hidden threats
  • Strengthening the organization’s defensive posture
  • Conducting hypothesis‑driven hunts across enterprise networks
  • Leveraging threat intelligence, adversary TTPs, and behavioral analytics to detect early indicators of compromise
  • Performing deep‑dive analysis of logs, endpoint telemetry, and network data to validate findings, uncover patterns, and escalate confirmed threats to SOC and IR teams
  • Contributing to the continuous improvement of detection capabilities by developing new analytics, refining existing logic, and identifying visibility gaps across the environment
  • Documenting repeatable workflows
  • Producing high‑quality hunt reports
  • Briefing leadership and mission stakeholders on emerging threats, hunt outcomes, and recommended defensive improvements
  • Collaborating closely with SOC, IR, CTI, and platform engineering teams to operationalize intelligence, integrate new data sources, and mature the organization’s hunt program

Benefits

  • health, life, disability, financial, and retirement benefits
  • paid leave
  • professional development
  • tuition assistance
  • work-life programs
  • dependent care
  • recognition awards program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service