Job Description
SarelaTech is seeking an experienced Cybersecurity Threat Hunter to support a Department of War (DoW) cybersecurity mission. This position will proactively search for cyber threats that may exist undetected within the network and initiate investigations to identify unusual behavior indicative of malicious activity, operating under the assumption that a threat actor may already reside within the network.
The Cybersecurity Threat Hunter will analyze raw log and network data and work with Threat Detection and Incident Response analysts to generate threat-hunting leads. The position will cross-reference trends and activity within the enterprise environment with current threat intelligence regarding external threat trends.
The Cybersecurity Threat Hunter will identify mitigations for key vulnerabilities discovered during threat-hunting activities and take the lead on analysis when an Advanced Persistent Threat (APT) or other compromise is identified during hunting operations. The position will develop threat-hunting strategies to increase capabilities for identifying new threats and build hunting tools and automation capabilities to identify sophisticated adversaries.
The Cybersecurity Threat Hunter will also perform incident response for critical security incidents.
Required Qualifications
Five (5) years of technical experience in at least one of the following areas:
Threat Intelligence
Cybersecurity Incident Response
Penetration Testing
Reverse Engineering
Digital Forensics
Three (3) years of experience analyzing attacker techniques at all levels of attack.
Knowledge of security challenges across multiple operating systems.
Ability to work with large data sets.
Experience using tools and scripting languages such as Splunk, Python, and PowerShell.
Ability to turn threat intelligence into actionable information.
Knowledge of the MITRE ATT&CK framework.
Ability to use data to build a narrative supporting the documentation of threat-hunting operations.
Certification
Must possess at least one current certification meeting DoD 8570/8140 Cybersecurity Service Provider Incident Responder (CSSP-IR) requirements, including:
Certified Ethical Hacker (CEH)
CyberSec First Responder (CFR)
Cisco Certified CyberOps Associate
Computer Hacking Forensic Investigator (CHFI)
CompTIA Cybersecurity Analyst (CySA+)
CompTIA PenTest+
GIAC Certified Forensic Analyst (GCFA)
GIAC Certified Incident Handler (GCIH)
Systems Security Certified Practitioner (SSCP)
Security Clearance
Active TS
Full Time