Threat Hunting Analyst

Department of Homeland Security (DHS) - Cybersecurity and Infrastructure Security Agency (CISA)
View company profile
Location
Arlington, VA
Category
Other
Attendance
In-person
Schedule
Full-time
Minimum rank
No requirement
Min. Length
4 months
Seniority
-

Summary description:

This position is located within the Department of Homeland Security (DHS), Cybersecurity and Infrastructure Security Agency (CISA), Cybersecurity Division (CSD). CISA is the Nation’s risk advisor, working with partners to defend against today’s threats and collaborating with industry to build more secure and resilient infrastructure for the future. CISA works with partners across industry and government to understand and manage risk to our critical infrastructure from a constantly evolving range of cyber and physical threats. CSD leads cybersecurity efforts for CISA as the Nation’s flagship civilian cyber defense organization. CSD collaborates with partners across the government and private sector to enhance the Nation’s cybersecurity by sharing information, providing cybersecurity services and technical assistance, as well as through education and awareness.

Job description:

Conduct integrated threat intelligence collection, analysis, and reporting to identify, assess, and brief on adversary cyber operations targeting U.S. national interests. Support decision-making through fused intelligence and coordinated reporting. Perform cybersecurity monitoring, incident analysis, and defensive response coordination through correlation, detection, and evaluation of potential intrusions and vulnerabilities. Develop and coordinate operational planning for cyber defense missions, integrating intelligence, defensive technologies, and security policies to support cross-domain cyber operations.• Collect and correlate all-source cyber threat intelligence data (classified, vendor, OSINT).• Identify and document adversary TTPs, motivations, and capabilities.• Produce threat intelligence summaries, alerts, and warnings.• Monitor validated cyber threat activities and update analytical assessments.• Track adversary operational shifts and report threat posture changes.• Review open-source and dark web information for hostile content.• Deliver oral and written intelligence briefings to tactical and strategic stakeholders.• Support CISA threat hunt operations through actionable intelligence insights.• Liaise with DHS, DoD, IC, and private sector partners to share threat indicators.• Maintain situational awareness of priority cyber actors and operational environments.• Detect and document cybersecurity incidents and escalate as needed.• Correlate events from multiple data sources to identify attack patterns.• Differentiate malicious activity from false positives and benign events.• Determine and document threat actor TTPs within observed incidents.• Recommend tools and software solutions to enhance defensive capabilities.• Evaluate new network, software, or system proposals for security impact.• Coordinate with analysts, architects, and developers to improve defensive design.• Research new cybersecurity technologies and methodologies.• Maintain awareness of emerging threats relevant to CISA mission areas.• Draft and refine plans supporting defensive cyber operations.• Integrate threat intelligence into operational and defensive planning.• Participate in target selection and prioritization for defensive actions.• Coordinate with operators and analysts to align cyber mission objectives.• Analyze internal CISA data to generate actionable planning intelligence.• Align operations with IC, SLTT, and private-sector mission requirements.• Define and apply information assurance principles during planning activities.• Identify system security requirements for new or migrating platforms.• Support enforcement of cybersecurity standards and best practices.