Cyber Threat Hunter

Leidos

Confirmed live 2 days ago High trust
Hybrid

Quick summary

Work type
Hybrid
Location
Washington, DC
Salary
$107,900–$195,050 / yr
Posted
59 days ago
Freshness
Confirmed live 2 days ago

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $156k
This role $151k
$97k most similar roles pay here $206k

This role pays more than 51% of similar roles. Most pay $127,325–$184,950 — the shaded band above. At the midpoint, this role pays about $151k versus about $156k for comparable roles.

Based on 239 similar postings.

Employer

About Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations.

Leidos currently has 264 open roles on FindRole.

Listed pay typically runs $92,300–$166,850 across 245 roles with salary data.

Most-posted roles

View all roles at Leidos

At a glance

TL;DR · Cyber Threat Hunter

The Cyber Threat Hunter joins the Digital Modernization sector to support a Defensive Cyber Operations team protecting federal networked systems and services from threats impacting national security. This role involves executing hypothesis-driven hunt campaigns based on adversary TTPs, performing advanced telemetry analysis across cloud resources and network infrastructure, and developing automated detection rules for SIEM/EDR platforms. The individual will also design automation scripts to scale threat mitigation, utilize the MITRE ATT&CK framework to identify Advanced Persistent Threat activity, and provide technical reporting on security posture improvements. Required skills include expert knowledge of networking protocols like TCP/IP and DNS, proficiency in query languages such as SPL, KQL, or DSL, and advanced scripting in Python, PowerShell, or Bash. The role focuses on identifying "low and slow" attacks within complex hybrid-cloud environments.

What you'll do

  • Develop and execute structured hunt campaigns based on adversary tactics, techniques, and procedures.
  • Query and correlate large datasets across cloud, identity, and network infrastructure to find "low and slow" attacks.
  • Convert manual hunt discoveries into high-fidelity, automated detection rules for SIEM and EDR systems.
  • Design and maintain automation scripts to scale threat mitigation and isolate compromised assets.
  • Proactively search for Advanced Persistent Threat (APT) activity using the MITRE ATT&CK framework.
  • Analyze internal and external telemetry to identify early indicators of imminent or ongoing compromises.
  • Author technical hunt reports summarizing findings, operational gaps, and improvements to security posture.

What we're looking for

  • Must have a Bachelor's degree with 8+ years of experience or a Master's degree with 6+ years of relevant experience.
  • Must hold a current DoD TS/SCI security clearance and pass additional customer suitability screenings.
  • Must hold a DoD 8570 IAT Level II or III certification, such as CompTIA Security+, CySA+, GSEC, or SSCP.
  • Must hold a DoD 8570 CSSP Analyst certification, such as CompTIA CySA+ or Cloud+.
  • Must hold a DoD 8570 CSSP Infrastructure Support certification, such as CompTIA CySA+, Cloud+, CEH, CND, CHFI, GICSP, or SSCP.
  • Must possess expert knowledge of networking protocols (TCP/IP, DNS, HTTP/S) and security elements like IDS/IPS and next-gen firewalls.
  • Must have direct experience analyzing complex packet captures and endpoint logs to reconstruct attack timelines.
  • Preferred skills include proficiency in SPL, KQL, or DSL query languages and scripting with Python, PowerShell, or Bash.

More like this

Similar roles

Cyber Threat Intelligence Analyst

Leidos

Washington, DC 59 days ago $107,900$195,050
Cyber Threat Intelligence MITRE ATT&CK Threat Intelligence Platforms (TIP Python PowerShell SIEM SOAR Firewalls IDS/IPS AWS Azure O365 KQL Elastic DSL SPL Cyber Kill Chain Diamond Model Data Correlation
8+ yrs exp Hybrid

Cyber Threat Hunter

General Dynamics

Falls Church, VA 4 days ago $114,750$155,250
Cyber Threat Hunting MITRE ATT&CK Splunk Elastic ITIL Information Assurance Cyber Security Architecture threat-intelligence
6+ yrs exp

Mid Cyber Threat Hunter

Booz Allen Hamilton

Bethesda, MD 10 days ago $62,000$141,000
Splunk SPL MITRE ATT&CK Threat Intelligence Log Analysis Behavioral Analytics Forensic Triage Anomaly Detection Machine Learning Cybersecurity Operations Insider Threat Programs Network Defense SOC IR CTI
2+ yrs exp

Senior Threat Hunter

Leidos

Fort Huachuca, AZ 17 days ago $107,900$195,050
Threat Hunting Incident Response Detection Engineering Machine Learning AWS Microsoft Azure Google Cloud Platform Oracle Cloud SaaS TTPs Network Analysis Vulnerability Management Security+ CEH GCIH
8+ yrs exp Hybrid

Threat Hunter, FedCloud

CrowdStrike

Remote 28 days ago $85,000$120,000
Threat Hunting Python Go Windows MacOS Linux Splunk Kibana LogScale AWS Azure GCP Digital Forensics Malware Analysis Cyber Threat Intelligence Incident Response Cloud Security
Remote

Cyber Threat Intelligence Analyst III

Leidos

Washington, DC +2 2 days ago
Cyber Threat Intelligence Cyber Kill Chain Diamond Model Splunk Analyst1 Python Bash PowerShell C++ CrowdStrike Falcon Tanium Proofpoint TAP Zscaler Malware Analysis Incident Response Threat Hunting Forensics XML HTML
8+ yrs exp