Logo
Booz Allen Hamilton

Threat Hunter

Booz Allen Hamilton, Washington, District of Columbia, us, 20022

Save Job

Your growth matters to us - explore our career development opportunities. BE EMPOWERED TO SUCCEED

Connect with others in our people-first culture and enhance our collective ingenuity. SUPPORT YOUR WELLBEING

Learn how we’ll support you as you pursue a balanced, fulfilling life. YOUR CANDIDATE JOURNEY

Discover what to expect during your journey as a candidate with us. We are seeking an experienced Threat Hunter join our Security Operations Center ( SOC ) team. As a Cyber Threat Hunter, you are a proactive defender who actively searches for adversary behaviors, hidden malware, and advanced persistent threats ( APTs ) within networks, endpoints, and cloud environments. You bridge the gap between automated detection and human-led analysis by applying threat intelligence, analytics, and adversary tactics, techniques, and procedures ( TTPs ) such as MITRE ATT & CK to uncover threats early. What You’ll Work On: Proactively manage Threat Discovery by formulating hypotheses about potential adversary behaviors. Create hunt queries, scripts, and analytics to detect stealthy threats. Look for Indicators of Compromise ( IOCs ) and Indicators of Behavior ( IOBs ) not yet flagged by tools. Correlate system, application, and security logs to uncover hidden activities. Analyze attacker TTPs mapped to MITRE ATT & CK. Use Threat Intelligence data from open source, commer cia l feeds, and internal research to inform a hunt plan. Anticipate adversary campaigns targeting the organization or industry. Support development of new detection rules and analytics based on evolving threats. Recommend security control enhancements such as hardening endpoints or closing logging gaps. Join us. The world can’t wait. You Have: 10+ years of experience in threat hunting, cybersecurity threat intelligence, intelligence analysis, or a threat analysis cybersecurity role 3+ years of experience in behavioral analysis such as the investigation of suspicious processes, persistence mechanisms, and abnormal network traffic Experience with tool and script development Ability to create custom detection logic, SIEM queries, and hunt playbooks Ability to automate repetitive hunting tasks with scripts such as Python or PowerShell Ability to fine-tune EDR, SIEM, or UEBA rules to reduce false positives and improve coverage Nice If You Have: Experience working in a SOC or cyber operations environment Ability to write succinct briefings, presentations, and reports to convey analysis, threat trends, threat actor profiles, indicator bulletins, vulnerability details, and defensive strategies to varied audiences Ability to partner with penetration testers and red teams to simulate adversaries and validate defenses CISSP, GCTH, GCTI, GCIH, CEH, OSCP, or equivalent Certification Clearance: Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information ; Secret clearance is required. Compensation At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page. Salary at Booz Allen is determined by various factors, including but not limited to location, the individual’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $77,600.00 to $176,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen’s total compensation package for employees. This posting will close within 90 days from the Posting Date. Threat Hunter

The Opportunity: We are seeking an experienced Threat Hunter join our Security Operations Center ( SOC ) team. As a Cyber Threat Hunter, you are a proactive defender who actively searches for adversary behaviors, hidden malware, and advanced persistent threats ( APTs ) within networks, endpoints, and cloud environments. You bridge the gap between automated detection and human-led analysis by applying threat intelligence, analytics, and adversary tactics, techniques, and procedures ( TTPs ) such as MITRE ATT & CK to uncover threats early. What You’ll Work On: Proactively manage Threat Discovery by formulating hypotheses about potential adversary behaviors.

Create hunt queries, scripts, and analytics to detect stealthy threats.

Look for Indicators of Compromise ( IOCs ) and Indicators of Behavior ( IOBs ) not yet flagged by tools.

Correlate system, application, and security logs to uncover hidden activities.

Analyze attacker TTPs mapped to MITRE ATT & CK.

Use Threat Intelligence data from open source, commer cia l feeds, and internal research to inform a hunt plan.

Anticipate adversary campaigns targeting the organization or industry.

Support development of new detection rules and analytics based on evolving threats.

Recommend security control enhancements such as hardening endpoints or closing logging gaps.

Join us. The world can’t wait. You Have: 10+ years of experience in threat hunting, cybersecurity threat intelligence, intelligence analysis, or a threat analysis cybersecurity role

3+ years of experience in behavioral analysis such as the investigation of suspicious processes, persistence mechanisms, and abnormal network traffic

Experience with tool and script development

Ability to create custom detection logic, SIEM queries, and hunt playbooks

Ability to automate repetitive hunting tasks with scripts such as Python or PowerShell

Ability to fine-tune EDR, SIEM, or UEBA rules to reduce false positives and improve coverage

Secret clearance

Bachelor’s degree

Nice If You Have: Experience working in a SOC or cyber operations environment

Ability to write succinct briefings, presentations, and reports to convey analysis, threat trends, threat actor profiles, indicator bulletins, vulnerability details, and defensive strategies to varied audiences

Ability to partner with penetration testers and red teams to simulate adversaries and validate defenses

CISSP, GCTH, GCTI, GCIH, CEH, OSCP, or equivalent Certification

Clearance: Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information ; Secret clearance is required. Compensation At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page. Salary at Booz Allen is determined by various factors, including but not limited to location, the individual’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $77,600.00 to $176,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen’s total compensation package for employees. This posting will close within 90 days from the Posting Date.

Identity Statement As part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud. Work Model Our people-first culture prioritizes the benefits of flexibility and collaboration, whether that happens in person or remotely. If this position is listed as remote or hybrid, you’ll periodically work from a Booz Allen or client site facility. If this position is listed as onsite, you’ll work with colleagues and clients in person, as needed for the specific role. Commitment to Non-Discrimination All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.

#J-18808-Ljbffr