The Senior Cyber Threat Hunting Specialist supports the Missile Defense Agency (MDA) on the Integrated Research and Development for Enterprise Solutions (IRES) contract. The candidate will serve as the primary Subject Matter Expert (SME) on advanced threats for the MDA Cyber Security Service Provider (MDA CSSP), collaborating with Defensive Cyber Operations, Cyber Threat Intelligence (CTI), Cyber Threat Emulation (CTE), and Forensics teams to drive unified defensive strategies. They will develop and execute intelligence-driven hunt hypotheses to detect Advanced Persistent Threats (APTs) and anomalies that bypass traditional security controls, map adversary Tactics, Techniques, and Procedures (TTPs) using the MITRE ATT&CK framework, and integrate tactical threat intelligence into hunt operations. The role involves analyzing network traffic, host-based logs, and endpoint telemetry using SIEM, EDR, and packet capture tools, correlating asset, threat, and vulnerability data against known adversary exploits and techniques to determine impact and improve network defensive posture. The specialist will leverage actionable Cyber Threat Intelligence data to search for indicators of compromise, assist in the development of SIEM content/signatures, and make recommendations to improve detection capabilities, tune alerts, and close security gaps. They will coordinate with CSSP subscribers to develop configurations, rules, and signatures for cyber security toolsets, and to notify, investigate, and remediate discrepancies in security logging and CSSP alignment. Confirmed threats will be transitioned to Defensive Cyber Operations, providing forensic artifacts, root cause analysis, and actionable intelligence during active investigations. The role also includes creating and maintaining custom scripts for automation, providing technical mentorship, conducting training sessions, and participating in tabletop exercises. The specialist will review data of ongoing intrusions or cybersecurity incidents, report, analyze, and document findings, and provide support to insider threat and law enforcement/counterintelligence agencies. They will advise security leadership and Defensive Cyber Operations teams on emerging adversary capabilities, translating hunt findings into strategic recommendations, and developing comprehensive documentation for intelligence dissemination.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior