Full-Time

Cyber Threat Hunter

Updated on 9/3/2026

cFocus Software

cFocus Software

11-50 employees

Federal cybersecurity, cross-domain, geospatial IT services

No salary listed

Washington, DC, USA

Hybrid

Four days per week on-site in Washington, DC; one day remote.

Category
Cybersecurity (2)
,
Required Skills
Malware Analysis
Microsoft Azure
Incident Response
Network Monitoring
Vulnerability Analysis
JIRA
Zscaler
Splunk

Get referred to cFocus Software

See people who can refer or advise you

Requirements
  • At least 5 years of experience performing threat hunts and incident response activities for cloud-based and non-cloud-based environments, including Microsoft Azure, Microsoft O365, Microsoft Active Directory, and Zscaler.
  • At least 5 years of experience performing hypothesis-based threat hunting and incident response using Splunk Enterprise Security.
  • At least 5 years of experience using Splunk to create queries and lookup tables.
  • At least 5 years of experience collecting and analyzing data from compromised systems using Endpoint Detection and Response agents, such as CrowdStrike, and custom scripts, such as Sysmon and Auditd.
  • At least 5 years of experience with Microsoft Sentinel for threat hunting within Microsoft Azure; Tenable Nessus and SYN/ACK for vulnerability management; NetScout for analyzing network traffic flow; SPUR.us for address enrichment; and Mandiant threat intelligence feeds.
  • Must be able to work 80% of the week, Monday through Thursday, on-site at the AOUSC office in Washington, DC.
Responsibilities
  • Provide incident response services after an incident is declared and proactively search for security incidents that would not normally be detected through automated alerting.
  • Explore datasets across the judicial fabric to identify unique anomalies that may indicate threat actor activity based on the assumption that the adversary is already present in the judicial fabric.
  • Accept and respond to government technical requests through the AOUSC ITSM ticket system, such as HEAT or ServiceNow, for threat hunt support.
  • Review and analyze risk-based Security Information and Event Management alerts when developing hunt hypotheses.
  • Review open-source intelligence about threat actors when developing hunt hypotheses.
  • Plan, conduct, and document iterative, hypothesis-based tactics, techniques, and procedures hunts using the agile scrum project management methodology.
  • Propose, discuss, and document custom searches for automated detection of threat actor activity based on each hunt hypothesis.
  • Configure, deploy, and troubleshoot Endpoint Detection and Response agents, such as CrowdStrike and Sysmon.
  • Collect and analyze data from compromised systems using Endpoint Detection and Response agents and custom scripts provided by the AOUSC.
  • Track and document cyber defense incidents from initial detection through final resolution.
  • Interface with court or vendor IT contacts to install or diagnose problems with Endpoint Detection and Response agents.
  • Participate in government-led after-action reviews of incidents.
  • Triage malware events to identify the root cause of specific activity.
  • Attend daily agile scrum standups and report progress on assigned Jira stories.
  • Prepare hunt hypotheses describing how an actor might operate in the network while remaining undetected, including expected outcomes when the hypothesis is true or false.
  • Prepare hunt reports describing the original hypothesis, all iterations, testing methods, and results.
  • Document and test detection logic for automated detection of threat actor activity using Splunk Enterprise Security searches, and document the logic in Jira stories.
  • Provide timely advanced subject-matter-expert incident response support for Priority 1 security events, actively participating in incident response activities within 4 hours of request on a 7x24x365 basis.
  • Document all incident details in an incident report, including the executive summary, incident details, security impact, incident timeline, and actions taken.
  • Provide weekly reports to the AOUSC Program Manager documenting activities, tasks, tickets, and documents worked on.
  • Document repeatable Standard Operating Procedures and playbooks for security use cases.
Desired Qualifications
  • One of the following certifications: GIAC Certified Intrusion Analyst, GIAC Certified Incident Handler, GIAC Continuous Monitoring, GIAC Defending Advanced Threats, or Splunk Core Power User.

cFocus Software provides cybersecurity, cross-domain, geospatial, and IT services to federal government agencies. It helps agencies design, implement, and manage security architectures, cross-domain data workflows, and geospatial solutions through consulting, implementation, and ongoing support. It differentiates itself with 18+ years of federal-focused experience and deep domain knowledge in government cybersecurity and geospatial work. Its goal is to help federal agencies protect operations, comply with regulations, and optimize IT and geospatial capabilities for secure, efficient government services.

Company Size

11-50

Company Stage

N/A

Total Funding

N/A

Headquarters

Largo, Florida

Founded

2006

Get referred to cFocus Software

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • DHS awarded $12.0 million geospatial support in September 2025, with $9.0 million backlog.
  • HHS denied a protest and upheld cFocus's emergency call center support award in July 2026.
  • Government contracts extend through 2028-2033, including GSA MAS and HUD O&M vehicles.

What critics are saying

  • Revenue concentration in federal BPAs leaves cFocus exposed to procurement delays after 2026.
  • ASET Partners challenged a DHS award, showing cFocus faces repeated bid protests.
  • One lost recompete at HUD or DHS would sharply shrink backlog and credibility.

What makes cFocus Software unique

  • cFocus won HHS cyber labor work in September 2025, beating 37 bidders.
  • Its federal stack spans HUD, DIA, DFC, HHS, and DHS contracts.
  • The company sells niche ATO, GIS, cybersecurity, and application O&M services.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Remote Work Options