Cybersecurity Threat Hunter
Listed on 2026-10-02
-
IT/Tech
Cybersecurity, Security Management & Operations, Information Security & Data Protection
AGE Solutions is a premier technology and professional services company, providing in-depth consulting, advanced technology solutions, and essential services throughout the U.S. government, defense, and intelligence sectors. Prioritizing innovation and client-focused solutions, we assist major agencies in addressing intricate issues and ensuring a more secure future.
AGE Solutions is seeking a highly skilled Cybersecurity Threat Hunter to join a mission-focused team defending complex enterprise environments against advanced cyber threats. In this role, you will go beyond traditional monitoring by proactively hunting for sophisticated adversaries, uncovering malicious activity that may have evaded existing security controls, and turning threat intelligence into actionable investigations. You will analyze large-scale security data, identify attacker tactics, techniques, and procedures (TTPs), develop advanced hunting strategies, and build automated capabilities using Splunk, Python, and Power Shell.
Working alongside Threat Detection and Incident Response teams, you will play a critical role in identifying emerging threats, investigating potential compromises, and strengthening the organization’s ability to detect and respond to advanced adversaries.
Responsibilities Include:
- Proactively hunt for advanced cyber threats and malicious activity that may have evaded existing security controls within enterprise environments.
- Analyze network traffic, security logs, endpoint telemetry, and large-scale security datasets to identify anomalous or suspicious activity.
- Develop and execute threat-hunting strategies to identify sophisticated adversaries and previously undetected compromises.
- Investigate attacker activity across the attack lifecycle and identify adversary tactics, techniques, and procedures (TTPs).
- Apply the MITRE ATT&CK framework to identify, analyze, categorize, and document adversary behaviors and attack patterns.
- Correlate internal security events and trends with current threat intelligence to identify emerging threats and develop actionable hunting leads.
- Transform threat intelligence into actionable queries, detection opportunities, investigative leads, and recommended defensive measures.
- Develop and automate threat-hunting and detection capabilities using Splunk, Python, Power Shell, and related cybersecurity tools.
- Collaborate with Threat Detection, Cyber Threat Intelligence, Security Operations, and Incident Response teams to investigate suspicious activity and potential compromises.
- Lead or support technical analysis when Advanced Persistent Threat (APT) activity or other significant compromises are identified.
- Perform incident response activities for critical cybersecurity incidents, including investigation, analysis, containment support, and documentation.
- Identify security vulnerabilities and defensive gaps discovered during threat-hunting activities and recommend appropriate mitigations.
- Analyze security threats and attacker behaviors across multiple operating systems and enterprise technologies.
- Develop clear, evidence-based documentation of threat-hunting methodologies, investigative activities, findings, and recommended actions.
- Communicate threat activity, technical findings, and recommended mitigations to cybersecurity teams, technical stakeholders, and leadership.
- Continuously improve threat-hunting methodologies, tools, automation, and detection capabilities based on emerging adversary techniques and lessons learned.
Required Skills, Qualifications, and
Experience:
- Experience:
- Five (5) years of technical experience in one of the following areas:
Threat Intelligence, Cybersecurity Incident Response, Penetration Testing, Reverse Engineering, or Digital Forensics. - Three (3) years of…
- Five (5) years of technical experience in one of the following areas:
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).