Senior Threat Hunter
Leidos
- Location
- Sierra Vista, AZ
- Work model
- On-Site
- Level
- Senior
- H-1B history
- 26 approvals (FY2023)
- Posted
- Aug 25, 2026
Skills
About this role
The C5ISR Center Cyber Security Service Provider (CSSP) is a premier defensive cyber operations organization supporting the Department of War (DoW). Operating 24x7x365, our team provides continuous monitoring, threat detection, incident response, and vulnerability management across a diverse, multi-tenant subscriber environment. We protect cloud and on-premises environments—including AWS, Microsoft Azure, Google Cloud Platform (GCP), Oracle Cloud, and a broad range of SaaS platforms—supporting critical missions across multiple DoW services and agencies. Leidos has an exciting career opportunity for a Senior Threat Hunter to support a large Department of War (DoW) Cyber Security Service Provider at Fort Huachuca, AZ. In this role, you will proactively identify, investigate, and mitigate sophisticated cyber threats across subscriber networks. You will apply deep knowledge of the cyber threat landscape to develop advanced detection strategies, test threat-hunting hypotheses, and identify and neutralize adversary activity targeting the Department of Defense Information Network (DoDIN). If you are an experienced cyber professional who thrives on solving complex problems and staying ahead of emerging threats, we want to hear from you. Location: Hybrid 3 days on-site at Fort Huachuca Clearance: U.S. citizenship and an active TS/SCI clearance. As a senior member of the threat team, you will support and lead activities spanning threat hunting, host and network analysis, incident response, trend analysis, content development, and detection engineering.
Primary Responsibilities
Lead and support incident response during high-severity cyber incidents, providing expert analysis and recommending appropriate containment, remediation, and recovery actions. Conduct proactive threat hunting across cloud and on-premises subscriber environments to identify and investigate malicious or suspicious activity before it causes mission impact. Identify adversary tactics, techniques, and procedures (TTPs) and develop countermeasures, including custom signatures, detection rules, and correlation logic. Build, tune, and monitor AI-assisted detections, including machine learning capabilities, to identify adversary behavior and movement within customer environments. Apply advanced cybersecurity tools and methodologies to detect, analyze, and mitigate cyber threats while integrating threat intelligence into sensing and detection infrastructure. Develop and refine threat-hunting hypotheses based on intelligence, emerging threats, anomalous activity, and known adversary behavior. Produce clear, actionable reports documenting findings, risk, and recommended remediation actions for technical teams, stakeholders, and senior leadership. Collaborate across cybersecurity, IT, and network teams to strengthen the security posture of subscriber systems and environments. Stay current on emerging threats, attack techniques, technologies, and industry trends, translating new intelligence into improved detection and response capabilities. Develop and deliver cybersecurity training for threat hunters, network defenders, and other relevant personnel to strengthen technical knowledge and incident response capabilities. Mentor team members and help foster a culture of technical excellence, continuous learning, collaboration, and improvement. Brief senior leaders, including SES and Flag Officer-level stakeholders, on cyber threat activity, significant incidents, and cybersecurity trends as needed.
Basic Qualifications
Bachelor's degree and 8+ years of relevant cybersecurity experience. 7+ years of experience in cyber analysis, threat hunting, and/or purple-team or blue-team operations. Experience working for or with a U.S. Government Cyber Security Service Provider (CSSP). Demonstrated experience investigating sophisticated cyber threats and developing or improving threat detection capabilities. Working knowledge of adversary tactics, techniques, and procedures