Federal - Cyber Threat Hunter



Organization: Accenture Federal Services

Location: Arlington, VA

Accenture Federal Services, a wholly owned subsidiary of Accenture LLP, is a U.S. company with offices in Arlington, Virginia. Accenture's federal business has served every cabinet-level department and 30 of the largest federal organizations. Accenture Federal Services transforms bold ideas into breakthrough outcomes for clients at defense, intelligence, public safety, civilian and military health organizations.

We believe that great outcomes are everything. It's what drives us to turn bold ideas into breakthrough solutions. By combining digital technologies with what works across the world's leading businesses, we use agile approaches to help clients solve their toughest problems fast-the first time. So, you can deliver what matters most.

Count on us to help you embrace new ways of working, building for change and put customers at the core. A wholly owned subsidiary of Accenture, we bring over 30 years of experience serving the federal government, including every cabinet-level department. Our 7,200 dedicated colleagues and change makers work with our clients at the heart of the nation's priorities in defense, intel, public safety, health and civilian to help you make a difference for the people you employ, serve and protect.

This is an extraordinary opportunity to build a rewarding career - with excellent benefits - at Accenture Federal Services. Working in highly collaborative teams for world-leading clients, we'll nurture your talent in an inclusive culture that values diversity. While fast-tracking your career, you'll have the flexibility to pursue your specialist passions. So, whatever your work and life goals, we'll help you achieve them. Sooner.

The Cyber Threat Hunter will take all the latest attacks and map them to the adversary technique models. Document what data points and tools are needed to detect it, as well as document the what , when, why and how for the analyst to get further background information. You will also work with the content team to develop triggers for each attack.
Qualified Threat Hunter should possess the skills and attributes necessary to perform in-depth analytics on data identified as outliers within large-scale organizations. Some keys to successful threat hunting involves knowledge of network and endpoint indicators, familiarization with adversary technique models such as Mitre ATT&CK and Lockheed Martin's Killchain, TTPs involving incident response and live-box forensics, and the ability to automate mundane analytical procedures through the use of scripting. The perfect candidate meets the above statement as well as brings a pro-active eagerness to discover an adversary within a network. You should be able to perform as well on a team as you do on your own.

THE WORK...

  • Documenting, t uning alerts and implementing threat detection analytics
  • Monitor & triage alerts generated from sensors
  • Utilize scripting to automate tasks
  • Review cyber threat intelligence feeds to convert intelligence into useful detections
  • Identify incident root cause and develop proactive mitigation steps
  • Create and brief customer reports
  • Detect patterns/outliers within data sets that match TTPs of known threat actors, malware and otherwise unusual behaviors.
  • Provide expert analytic investigative support of large scale and complex security incidents.
  • Conduct dynamic and static malware analysis on samples obtained during incident handling or hunt operations in order to identify IOCs.


Qualifications

Threat Hunter Job Qualifications:

  • U.S. Citizenship
  • 5+ years of experience in an offensive and/or defensive cyber operations role (eg., Red Team, Threat Hunting, Incident Response, Tier 3 SOC/NOC Analyst)
  • 1 - 3 years of experience with Endpoint Detection and Response (EDR) tool suites
  • Skill in performing analysis of PCAP files
  • 1 - 3 years of experience in static and dynamic analysis of malicious code
  • Expert level understanding of Mitre ATT&CK and Lockheed Martin's Killchain

Preferred Job Qualifications:

  • Excellent communication and writing skills
  • Bachelor's Degree preferred
  • A team player capable of high performance, flexibility in a dynamic working environment and the ability to lead
  • Experience with automated tools (Phantom, Dimesto, etc)
  • Skill in writing scripts (e. g., PowerShell, Python)
  • Skill in interacting with various platform APIs to retrieve and manipulate data
  • Experience with Github


An active security clearance or the ability to obtain one may be required for this role.

Candidates who are currently employed by a client of Accenture or an affiliated Accenture business may not be eligible for consideration.

Applicants for employment in the US must have work authorization that does not now or in the future require sponsorship of a visa for employment authorization in the United States and with Accenture (i.e., H1-B visa, F-1 visa (OPT), TN visa or any other non-immigrant status).

Accenture is a Federal Contractor and an EEO and Affirmative Action Employer of Females/Minorities/Veterans/Individuals with Disabilities.

Equal Employment Opportunity

All employment decisions shall be made without regard to age, race, creed, color, religion, sex, national origin, ancestry, disability status, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, citizenship status or any other basis as protected by federal, state, or local law.

Job candidates will not be obligated to disclose sealed or expunged records of conviction or arrest as part of the hiring process.

Accenture is committed to providing veteran employment opportunities to our service men and women.

Equal Employment Opportunity Statement, Requesting an Accommodation, and Other Employment Statements

Equal Employment Opportunity Statement

All employment decisions shall be made without regard to age, race, creed, color, religion, sex, national origin, ancestry, disability status, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, citizenship status or any other basis as protected by federal, state, or local law.

Accenture is committed to providing veteran employment opportunities to our service men and women.

For details, view a copy of the Accenture Equal Opportunity and Affirmative Action Policy Statement

Requesting An Accommodation

Accenture is committed to providing equal employment opportunities for persons with disabilities or religious observances, including reasonable accommodation when needed. If you are hired by Accenture and require accommodation to perform the essential functions of your role, you will be asked to participate in our reasonable accommodation process. Accommodations made to facilitate the recruiting process are not a guarantee of future or continued accommodations once hired.

If you would like to be considered for employment opportunities with Accenture and have accommodation needs such as for a disability or religious observance, please call us toll free at 1 (877) 889-9009 or send us an email .

Other Employment Statements

Job candidates will not be obligated to disclose sealed or expunged records of conviction or arrest as part of the hiring process.

The Company will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. Additionally, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the Company's legal duty to furnish information.


Back to top