The Senior Cyber Threat Hunting Specialist supports the Missile Defense Agency (MDA) on the Integrated Research and Development for Enterprise Solutions (IRES) contract. The candidate will serve as the primary Subject Matter Expert (SME) on advanced threats for the MDA Cyber Security Service Provider (MDA CSSP), collaborating with Defensive Cyber Operations, Cyber Threat Intelligence (CTI), Cyber Threat Emulation (CTE), and Forensics teams to drive unified defensive strategies. This role involves developing and executing intelligence-driven hunt hypotheses to detect Advanced Persistent Threats (APTs) and anomalies that bypass traditional security controls, mapping adversary Tactics, Techniques, and Procedures (TTPs) using the MITRE ATT&CK framework, and integrating tactical threat intelligence into hunt operations. The specialist will analyze network traffic, host-based logs, and endpoint telemetry utilizing SIEM, EDR, and packet capture tools, and correlate asset, threat, and vulnerability data against known adversary exploits and techniques to determine impact and improve network defensive posture. Leveraging actionable Cyber Threat Intelligence data is key to searching for indicators of compromise and assisting in the development of SIEM content/signatures. The role also includes coordinating with CSSP subscribers to develop configurations, rules, and signatures, and to notify, investigate, and remediate discrepancies. Confirmed threats will be transitioned to Defensive Cyber Operations with forensic artifacts, root cause analysis, and actionable intelligence. The specialist will create and maintain custom scripts for automation, provide technical mentorship, conduct training, and participate in tabletop exercises. Additionally, the role requires reviewing data of ongoing intrusions or cybersecurity incidents, reporting findings in accordance with CJCSM 6510.01B guidelines, and supporting internal and external insider threat and law enforcement/counterintelligence agencies. Advising security leadership and Defensive Cyber Operations teams on emerging adversary capabilities and translating hunt findings into strategic recommendations is also a core function. Finally, the candidate will develop and maintain comprehensive documentation, including hunt runbooks, methodologies, and technical debriefs.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior