Cyber Threat Hunt Analyst - Intermediate (#1356974)

  • PeopleTec, Inc.
  • Huntsville, AL, USA 35805
  • Mar 06, 2020
Full time Professional Services

Job Description

PeopleTec is currently seeking a Cyber Threat Hunt Analyst - Intermediate to support our Huntsville, AL location.


The successful candidate will support the customer in cyber-threat hunting and associated investigations of systems under the supervision of a Team Lead. The investigations support protection of the customer's mission systems and the supply chain used to develop their products. The candidate will be part of a team that will perform cyber-threat hunting to identify potential cyber-threat activity within their networks/systems. The successful candidate will perform hands-on investigations that require critical thinking and a broad understanding of multiple technologies. The incumbent will support development of presentations and reports to document findings and will require good communication and interpersonal skills to convey findings in a tactful manner at the technical proficiency level of the audience.


Required Skills/Experience:

  • Hold an Information Assurance Management (IAM) Level II certification as identified in DoD 8570. These are either a Certified Information Systems Security Professional (CISSP), Certified Information Systems Manager (CISM), or GIAC Security Leadership Certificate (GSLC) certification in good standing or obtain one within 6 months of hire 
  • Assist in the development and execution of cyber threat-hunting tactics, techniques, and procedures (TTPs)
  • Serve as a data analysis expert for output from a wide variety of cyber assessment tools and Big Data Analytics
  • Assist in analysis tool development, configuration, implementation and use
  • Analyze cyber-threat intelligence (e.g. actors, tools, exploits, malware, etc.) and determine TTPs used by threat-actors
  • Analyze security events and data feeds for event detection, correlation from monitoring solutions, conduct triage and classify the output using automated systems for further investigation
  • Assist in the discovery of cyber vulnerabilities and the investigation of global cyber security incidents
  • Develop cyber protection improvement recommendations that support the remediation and protection of systems
  • Analyze and report on cyber-threats based on assessment and all-source intelligence
  • Translate analytical findings into security "use cases" that can be implemented within available surveillance capabilities
  • Provide detailed and accurate technical reporting of analysis results in the form of PowerPoint presentations and/or Word documents, as well as oral briefings on complex technical subjects attuned to senior management, technical, or non-technical audiences
  • Travel: Up to 25%
  • Must be a U.S. Citizen
  • An active DoD Secret clearance is required to perform this work. Candidates are required to have an active Secret clearance upon hire, and the ability to maintain this level of clearance during their employment.


Education Requirements:

Bachelor's Degree or 7+ years of experience in a cyber-related field is required.


Desired Skills:

  • One or more current certifications equivalent to the following: Offensive Security Certified Professional (OSCP), SANS GIAC Penetration Tester (GPEN), SANS GIAC Certified Incident Handler (GCIH), SANS GIAC Web Application Penetration Tester (GWAP), SANS GIAC Certified Intrusion Analyst (GCIA)
  • Practical knowledge of high-level scripting/programming language (e.g. Python, Pearl, PowerShell, etc.) to extract, de-obfuscate, or otherwise manipulate malware-related data
  • Proficient with forensic analysis tools and techniques to identify malware technical indicators of compromise and perform triage
  • Possess excellent oral and written communication skills and critical thinking abilities Capable of working independently and within teams to solve complex problems
  • Able to work across multiple organizations, cultures and service providers to pull together actionable information and management information
  • Practical knowledge of Splunk policies, filters and rules to improve event analysis and data correlation
  • Have 5+ years of penetration testing, incident response, malware analysis, reverse engineering, or other similar work experience
  • Knowledge of Windows and Unix/Linux Operating Systems
  • Ability to perform analysis of network traffic and protocols
  • Background or experience in digital forensics


People First. Technology Always.

PeopleTec, Inc. is an employee-owned small business founded in Huntsville, AL that provides exceptional customer support by employing and retaining a highly skilled workforce.

Culture: The name "PeopleTec" was deliberately chosen to remind us of our core value system - our people. Our company's foundation was built on placing our employees and customers first. With an award-winning atmosphere, we have matured into a company that boasts the best and brightest across multiple technical fields.

Career: At PeopleTec, we value your long-term goals. Whether it's through our continuing-education opportunities, our robust training programs, or our "People First" benefits package, PeopleTec truly believes that our best investments are our people.

Come Experience It.



PeopleTec, Inc. is an Equal Employment Opportunity employer and provides reasonable accommodation for qualified individuals with disabilities and disabled veterans in its job application procedures. If you have any difficulty using our online system and you need an accommodation due to a disability, you may use the following email address, and/or phone number (256.319.3800) to contact us about your interest in employment with PeopleTec, Inc.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, genetic information, citizenship, ancestry, marital status, protected veteran status, disability status or any other status protected by federal, state, or local law. PeopleTec, Inc. participates in E-Verify.

For more information, or to apply now, you must go to the website below. Please DO NOT email your resume to us as we only accept applications through our website.