Cyber Threat Hunt Lead

Gritter Francona
Ashburn, VA

Gritter Francona is looking for a Cyber Threat Hunt Lead to support a potential project with the Department of Homeland Security. The Threat Hunt Lead will build and guide a proactive threat hunting capability for the Department of U.S. Customs and Border Protection (CBP). The Threat Hunt Lead will direct a specialized team in proactively searching for malicious activity across CBP networks that evades traditional security solutions. This role requires an offensive mindset, deep knowledge of attacker TTPs, and expert-level skills with SIEM and endpoint management tools. The Threat Hunt Lead will be responsible for developing hunt hypotheses, executing hunt missions, and coordinating with the SOC to create new detections based on your findings.

Key Responsibilities:

• Lead the CTH team to proactively and iteratively conduct threat hunting efforts against CBP networks, systems, and high value assets to detect and isolate advanced threats.

• Utilize threat models and Cyber Threat Intelligence to formulate hypotheses about attacker activity on CBP networks and systems to investigate during formal hunt missions.

• Propose corrective actions and inform necessary parties of security issues, reportable offenses, or cybersecurity best practices.

• Work with the CBP SOC to create new security content, including signatures and detection alerts, resulting from hunt missions and Purple Team engagements.

• Lead the Cyber Threat Hunt team to report significant findings to leadership and coordinate with asset owners to deconflict findings.

Requirements

  • A minimum of five (5) years of experience as a Tier III senior cyber threat hunt analyst performing threat analysis, technical analysis, and network asset traversal.
  • A minimum of five (5) years of hands-on experience, including recent experience with network-based security monitoring using cybersecurity capabilities.
  • A strong background in host and network-based forensics, intrusion detection, malware identification, and security content development.
  • Deep knowledge of and experience with security information and event management (SIEM) and networked-device management tools such as Splunk and Tanium.
  • Experience interpreting scripts (e.g., VB scripts, Python, C++) to support cyber threat detection.
  • Certified Ethical Hacker (CEH) or one of the following: DoD 8570 IAT Level II or IAM Level I or CSSP Analyst / Incident Responder.

Benefits

  • Health Care Plan (Medical, Dental & Vision)
  • Retirement Plan (401k, IRA)
  • Life Insurance (Basic, Voluntary & AD&D)
  • Paid Time Off (Vacation, Sick & Public Holidays)
  • Short Term & Long Term Disability
  • Training & Development
Posted 2026-02-20

Recommended Jobs

Physical Therapist Assistant (PTA)

Gotham Enterprises Ltd
Richmond, VA

Physical Therapist Assistant Location: Richmond, VA Position: Full-Time Schedule: Monday–Friday, 9:00 AM – 5:00 PM Salary: $90,000 – $104,000 per year Summary This PTA position …

View Details
Posted 2026-02-12

Team Lead - Active TS/SCI w/Poly Required

Arlington, VA

Team Lead - Active TS/SCI w/Poly Required Position Description CGI Federal has an exciting opportunity for a Team Lead within our Intel sector advancing the national security mission through cut…

View Details
Posted 2026-01-23

Security Testing IT Project Manager

gTANGIBLE Corporation
Arlington, VA

Description gTANGIBLE Corporation (gTC), www.gtangible.com, is a C corporation and a registered Government contractor that provides services and solutions in: ~National Security Programs ~Profe…

View Details
Posted 2026-01-28

Emergency Medicine Nurse Practitioner in Low Moor, VA Mon-Fri. NO WEEKENDS

SCP Health
Low Moor, VA

Emergency Medicine Nurse Practitoner at LewisGale Hospital Alleghany Location: Low Moor , VA Job Type: Full-time VISA Sponsorship: No Recruiter Info: Matthew Lewis| | | Schedule time to…

View Details
Posted 2026-04-04

Chemical and Nuclear Surety Lead

IDS International
Arlington, VA

Job Title Chemical and Nuclear Surety Lead Why IDS? IDS believes in resolving conflict and building innovative approaches to do so. Combining operational expertise with an intimate understand…

View Details
Posted 2026-02-13

SAP Analyst - Supply Chain

Phlow Corp.
Richmond, VA

Job Description Job Description Description: The SAP Analyst – Supply Chain is responsible for supporting, maintaining, and optimizing SAP S/4HANA systems to ensure efficient, compliant, and acc…

View Details
Posted 2026-03-17

DevSecOps Engineer

Astrion
Dahlgren, VA

Job Description Job Description Overview DevSecOps Engineer Location: Dahlgren, Virginia Job Status: Full Time Clearance: Top Secret Clearance Astrion is seeking a highly mo…

View Details
Posted 2026-03-17

Contracts Manager

Fairfax, VA

Contracts Manager Position Description Seeking a Contracts Manager to work at CGI Federal where we value our members and our company culture. We are proud to be able to offer an innovative, posi…

View Details
Posted 2026-01-06

Customer Service

NaturaLawn of America
Newport News, VA

Customer Service & Data Entry Great benefits, exciting work, and a friendly team! NaturaLawn of America  ( is seeking a dedicated Customer Service / Data Entry Rep to join our growing Newport News…

View Details
Posted 2026-03-28