Cyber Operations, Cyber Threat Analysis, Cyber Threat Modeling, Team Management Certifications: None Experience: 10 + years of related experience US Citizenship Required: Yes The Threat Hunt Lead is ...
Cyber Operations, Cyber Threat Analysis, Cyber Threat Modeling, Team Management Certifications: None Experience: 10 + years of related experience US Citizenship Required: Yes The Threat Hunt Lead is ...
The role translates threat modeling outputs into reusable security patterns aligned with established enterprise standards and embeds them into the organization's threat modeling and certification ...
The role translates threat modeling outputs into reusable security patterns aligned with established enterprise standards and embeds them into the organization's threat modeling and certification ...
This exciting career opportunity at the TMC is responsible for the development and delivery of high-fidelity threat modeling products in support of the Missile Defense Agency (MDA) and MDA ...
This exciting career opportunity at the TMC is responsible for the development and delivery of high-fidelity threat modeling products in support of the Missile Defense Agency (MDA) and MDA ...
Strong knowledge of MITRE ATT&CK, Cyber Kill Chain, and threat modeling methodologies. * Hands-on experience with cloud threat analysis (AWS, Azure, Google Cloud Platform) and container security.
Strong knowledge of MITRE ATT&CK, Cyber Kill Chain, and threat modeling methodologies. * Hands-on experience with cloud threat analysis (AWS, Azure, Google Cloud Platform) and container security.
Lead Cyber Threat Analyst
Washington, DC · On-site
$165K - $200K/yr
Strong knowledge of MITRE ATT&CK, Cyber Kill Chain, and threat modeling methodologies. * Hands-on experience with cloud threat analysis (AWS, Azure, GCP) and container security. * Ability to lead ...
Quick apply
Lead Cyber Threat Analyst
Washington, DC · On-site
$165K - $200K/yr
Strong knowledge of MITRE ATT&CK, Cyber Kill Chain, and threat modeling methodologies. * Hands-on experience with cloud threat analysis (AWS, Azure, GCP) and container security. * Ability to lead ...
Lead Cyber Threat Analyst
Washington, DC · On-site
$165K - $200K/yr
Strong knowledge of MITRE ATT&CK, Cyber Kill Chain, and threat modeling methodologies. * Hands-on experience with cloud threat analysis (AWS, Azure, GCP) and container security. * Ability to lead ...
Lead Cyber Threat Analyst
Washington, DC · On-site
$165K - $200K/yr
Strong knowledge of MITRE ATT&CK, Cyber Kill Chain, and threat modeling methodologies. * Hands-on experience with cloud threat analysis (AWS, Azure, GCP) and container security. * Ability to lead ...
Senior Threat Detection Engineer
$103K - $142K/yr
Threat Modeling & Hunting: Proactively analyze attacker tactics, techniques, and procedures (TTPs) and execute hypothesis-driven threat hunting campaigns. * Automation & AI Integration: Implement ...
Senior Threat Detection Engineer
$103K - $142K/yr
Threat Modeling & Hunting: Proactively analyze attacker tactics, techniques, and procedures (TTPs) and execute hypothesis-driven threat hunting campaigns. * Automation & AI Integration: Implement ...
Our business model focuses on integrity, loyalty, and trust. Position Overview Contractor will ... Threat Identification: Identify and analyze enemy cyber threats aimed at disrupting AFSOC ...
Quick apply
Our business model focuses on integrity, loyalty, and trust. Position Overview Contractor will ... Threat Identification: Identify and analyze enemy cyber threats aimed at disrupting AFSOC ...
R0233927 Digital Threat Modeling Engineer, Lead The Opportunity: Are you looking for an opportunity to combine your technical skills with big picture thinking to make an impact on national security?
R0233927 Digital Threat Modeling Engineer, Lead The Opportunity: Are you looking for an opportunity to combine your technical skills with big picture thinking to make an impact on national security?
Senior Threat Detection Engineer
Austin, TX · On-site +1
$103K - $142K/yr
Threat Modeling & Hunting: Proactively analyze attacker tactics, techniques, and procedures (TTPs) and execute hypothesis-driven threat hunting campaigns. * Automation & AI Integration: Implement ...
Senior Threat Detection Engineer
Austin, TX · On-site +1
$103K - $142K/yr
Threat Modeling & Hunting: Proactively analyze attacker tactics, techniques, and procedures (TTPs) and execute hypothesis-driven threat hunting campaigns. * Automation & AI Integration: Implement ...
Strong knowledge of MITRE ATT&CK, Cyber Kill Chain, and threat modeling methodologies. * Hands-on experience with cloud threat analysis (AWS, Azure, GCP) and container security. * Ability to lead ...
Strong knowledge of MITRE ATT&CK, Cyber Kill Chain, and threat modeling methodologies. * Hands-on experience with cloud threat analysis (AWS, Azure, GCP) and container security. * Ability to lead ...
... modeling, vulnerability management, and risk assessment. * 4+ years of experience gathering and analyzing intelligence from multiple sources, including OSINT, commercial threat intelligence platforms ...
... modeling, vulnerability management, and risk assessment. * 4+ years of experience gathering and analyzing intelligence from multiple sources, including OSINT, commercial threat intelligence platforms ...
... modeling, vulnerability management, and risk assessment. * 4+ years of experience gathering and analyzing intelligence from multiple sources, including OSINT, commercial threat intelligence platforms ...
... modeling, vulnerability management, and risk assessment. * 4+ years of experience gathering and analyzing intelligence from multiple sources, including OSINT, commercial threat intelligence platforms ...
Knowledge of the MITRE ATT&CK framework and threat modeling methodologies. * Experience producing tactical, operational, and strategic threat assessments. * Strong written and verbal communication ...
Knowledge of the MITRE ATT&CK framework and threat modeling methodologies. * Experience producing tactical, operational, and strategic threat assessments. * Strong written and verbal communication ...
This exciting career opportunity at the TMC is responsible for the development and delivery of high-fidelity threat modeling products in support of the Missile Defense Agency (MDA) and MDA ...
This exciting career opportunity at the TMC is responsible for the development and delivery of high-fidelity threat modeling products in support of the Missile Defense Agency (MDA) and MDA ...
Familiarity with threat modeling frameworks like MITRE ATT&CK, Cyber Kill Chain, and STRIDE. Pay and Benefits At Goldbelt, we value and reward our team's dedication and hard work. We provide a ...
Familiarity with threat modeling frameworks like MITRE ATT&CK, Cyber Kill Chain, and STRIDE. Pay and Benefits At Goldbelt, we value and reward our team's dedication and hard work. We provide a ...
... modeling, vulnerability management, and risk assessment. * 4+ years of experience gathering and analyzing intelligence from multiple sources, including OSINT, commercial threat intelligence platforms ...
... modeling, vulnerability management, and risk assessment. * 4+ years of experience gathering and analyzing intelligence from multiple sources, including OSINT, commercial threat intelligence platforms ...
THE MISSION Threat Systems Engineers (TSE) develop and deliver high-fidelity threat modeling products in support of the Missile Defense Agency (MDA) and the Ballistic Missile Defense System (BMDS)
THE MISSION Threat Systems Engineers (TSE) develop and deliver high-fidelity threat modeling products in support of the Missile Defense Agency (MDA) and the Ballistic Missile Defense System (BMDS)
You are accountable for threat modeling, detection strategy, identity-centric security, data governance, privacy engineering, audit-aligned control assurance, and adversarial validation. While ...
You are accountable for threat modeling, detection strategy, identity-centric security, data governance, privacy engineering, audit-aligned control assurance, and adversarial validation. While ...
This exciting career opportunity at the TMC is responsible for the development and delivery of high-fidelity threat modeling products in support of the Missile Defense Agency (MDA) and MDA ...
This exciting career opportunity at the TMC is responsible for the development and delivery of high-fidelity threat modeling products in support of the Missile Defense Agency (MDA) and MDA ...
Threat Modeling information
See salary details
$47.12 - $49.39
6% of jobs
$49.39 - $51.66
9% of jobs
$51.66 - $53.93
4% of jobs
$55.56 is the 25th percentile. Wages below this are outliers.
$53.93 - $56.21
7% of jobs
$56.21 - $58.48
20% of jobs
The median wage is $59.24 / hr.
$58.48 - $60.75
9% of jobs
$60.75 - $63.02
11% of jobs
$64.62 is the 75th percentile. Wages above this are outliers.
$63.02 - $65.30
10% of jobs
$65.30 - $67.57
10% of jobs
$67.57 - $69.84
5% of jobs
$69.84 - $72.12
6% of jobs
$47
$60
$72
How much do threat modeling jobs pay per hour?
What are the key skills and qualifications needed to thrive as a Threat Modeler, and why are they important?
What is threat modeling?
What are some common challenges faced by professionals in threat modeling roles, and how can they be addressed?
What is the difference between Threat Modeling vs Security Analyst?
| Aspect | Threat Modeling | Security Analyst |
|---|---|---|
| Primary Focus | Identifying potential security threats during system design and development | Monitoring, analyzing, and responding to security incidents and vulnerabilities |
| Skills & Certifications | Knowledge of security frameworks, risk assessment, threat identification | Security certifications (e.g., CISSP, CompTIA Security+), incident response skills |
| Work Environment | Typically involved in early-stage design, often within development teams | Operational, monitoring security tools, and incident management teams |
Threat Modeling and Security Analysts both play vital roles in cybersecurity. Threat Modeling focuses on proactively identifying potential threats during system design, while Security Analysts respond to ongoing security incidents. Understanding their distinct responsibilities helps organizations strengthen their security posture effectively.
Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Posted 29 days ago
General Dynamics Information Technology rating
7.8
Based on 62 frontline employees who took The Breakroom Quiz
70th of 203 rated it services
Job description
Type of Requisition:
RegularClearance Level Must Currently Possess:
Top SecretClearance Level Must Be Able to Obtain:
Top SecretPublic Trust/Other Required:
NoneJob Family:
Cyber and IT Risk ManagementJob Qualifications:
Skills:
Cyber Operations, Cyber Threat Analysis, Cyber Threat Modeling, Team ManagementCertifications:
NoneExperience:
10 + years of related experienceUS Citizenship Required:
YesJob Description:
The Threat Hunt Leadis responsible foroverseeing allcyberthreat hunt, adversary analysis, malware analysis, and digital forensics mission activities underan upcoming government contract.Hunts will include operations within sensitiveenvironmentssuch as Operation Technology (OT), Industrial Control Systems (ICS)and other CriticalInfrastructure(CI)networks.
The successful leader directs multidisciplinary hunt and forensic teams providingfull spectrumdetection, analysis, and response capabilities that enablefederal stakeholderstoidentify, understand, and counter sophisticated cyber threats across federal,State Local Tribal and Territorial (SLTT),commercial, critical infrastructure, and cloud environments.
The Threat Hunt Lead ensures continuous detection of adversary behavior, managessimultaneouslydeployedhunt operations, oversees advanced malware and forensics workflows, and delivershigh qualityanalytic products that inform national cyber defense actions.The rolemaintainsreadiness of personnel, tools, and flyaway kits to support rapid, remote, or onsite engagements.
Key Responsibilities
Adversary, Malware, and Forensics Analysis Oversight
Overseesimultaneously deployed hunt operationsteams performing adversary tool analysis, including dynamic and static malware analysis and full reverse engineering of binaries, scripts, malicious documents, and artifacts todeterminefunctionality, behavior, andcommand and controlmechanisms.
Overseesimultaneously deployedteams conducting digital forensic analysis of affected systems todeterminemalware impact, persistence mechanisms, and threat actor behavior.
Deep understanding ofall levels of threat actor tools,techniquesand procedures (TTPs) that actor(s) may deploy including advanced (AI/ML) modeling techniques.
Extensive knowledge of emerging,establishedand nation-state level threat actor behaviorsto include subversion and/or false flag operations techniques designed to circumvent establishedcyber inspections tools.
In-depth ability to adapt to diversecyber environments in which managed teams may not have access to on-site cyber tools(event correlation mechanisms)and manage teams that may need to "live off the land"withon-site-provided cyber tools.
Strong knowledge of air-gapped environments and how direct simultaneouslydeployed huntteamswithin themto ensure consistent reporting.
Ensuresimultaneously deployedteams develop custom scripts, tools, and analytic methods toidentify, characterize, and visualize adversary techniques across hunt, malware, and forensics workflowswithin both established and a-typicalcyber environments e.g., OT/ICSenvironments, commercialenvironments
Ensure production ofhigh qualityindicators of compromise, detection artifacts, and adversary capability assessments that support national cyber defense operations.
Thread Hunt Operations Management
Overseefull spectrumhunt and incident response engagements,onsiteand/or remote,ensuringsimultaneously deployedteamsidentifythreats, assess impact, and recommend remedial actionsto local stakeholders.
Direct continuous analysis ofestablished and a-typicalcyber defense sensor data, endpoint activity, network flows, cloud telemetry, and communications data to detect adversarial behavior and anomalous activity.
Ensuresimultaneously deployedhunt teamsmaintaincontinuous awareness of emerging attack techniques, threat actors, tools, and methodologies to remain effective and up to date.
Overseeboth classified and unclassifieddelivery offederalstakeholder brandedanalytic products, intelligence deliverables, threat assessments, and technical reports that contextualize adversary activity.
Determinethemechanisms for thetimelyandaccuraterelease ofindicatorstobest ensure a proactive threat posture against cyber threat actors.
Prepare, support the deliveryofand oversee the creation ofon-demand and formal reportingso as toensure thetimelyandaccuratereporting ofshifting threat actor TTPs regardless ofattribution.
Understand, direct, oversee and ensure adherence toestablishedframeworks of reporting mechanisms such as MITRE ATT&CK (Enterprise, Mobile, ICS, etc.)
Host Based, Network, Cloud, and OT/ICS Forensics Leadership
Overseesimultaneously deployedteams performing forensic examination across host systems and digital media (phones, hard drives, memory images, etc.)
Directsimultaneously deployednetwork forensics operations toidentifythreatattacker behavior, develop network signatures, analyze network traffic and configurations, and produce authoritative forensic reports.
Overseesimultaneously deployedcloud forensic teams
Managesimultaneously deployedOT/ICS forensic teams conducting analysis across industrial control systems
Support, lead, direct and overseeappropriateremediationsuggestions and work withappropriate localstakeholdersincluding OT/ICS engineers.
Malware Analysis and Operations Oversight
Overseesimultaneously deployedmalware operations teams responsible for evaluating complex malicious code, performing static/dynamic analysis, triaging samples, and generatinghigh qualitytechnical reports.
Ensure development of custom detection signatures (YARA, SIGMA) and automated cleanup tools to enhance detection and remediation activities.
Overseeteam's simultaneously deployedworkflowsfor themanagementofmalware submissionsto pre-approved stakeholders onlyand where/when applicable,includetriage, prioritization, and status tracking.
Ensure teams develop metrics to evaluate analysis throughput, accuracy, timeliness, and mission impact.
Operational Processes, Procedures, and Performance Metrics
Overseethestakeholder approveddevelopment, maintenance, and improvement ofStandard Operating Procedures (SOPs), playbooks, analytic processes, workflows,robotic process automations (RPAs)and procedures supporting hunt, malware, and forensic operations.
Ensuresimultaneously deployedteams contribute to performance metrics measuring forensic effectiveness, response quality, hunt mission impact, and operational readiness.
Overseethe threat hunt team'sparticipation inclassified and unclassifiedinteragency technical exchanges and communities of interest to strengthen national cyber defense integration.
Deployable Hunt and Forensic Capability Management (Flyaway Kits)
Oversee readiness of all deployable hunt and forensics resources;includingfullcapacityandreducedcapacityflyaway kits, storage media, imaging systems, and tools.
Ensure kits are provisioned, tested, updated, sanitized, and securedin accordance withchainofcustodyand data handling requirements.
Oversee rapid deployment capabilities supportingsimultaneously deployedremote or onsite incident response, exercises, and surge support events.
Required Qualifications
Experience leadingsimultaneously deployedhunt, malware analysis, digital forensics, or incident response teams within largescale, enterprise, commercial and OT/ICScyber defense programs.
Deep knowledge ofnation state, emerging and establishedadversary TTP analysis, reverse engineering, forensic acquisition, and threat detection methodologies.
Deep understanding and experiencewithhostbased, network, cloud, and OT/ICS forensics.
Strong understanding of malware analysis, dynamic/static analysis tools, and detection signature developmentacross multiple operatingenvironmentsincluding OT/ICS
Ability to oversee multidisciplinary teams and coordinate multiple concurrent engagements.
Strong communication, reporting, and analytic leadership skills.
10 years of overall cybersecurity experience with 5 years ofmanagement of cybersecurity teams
Preferred Qualifications
Experience supportingfederal stakeholderssuch as theDHS,DoW,the Intelligence Community (IC), the FBIand/or other national security cyber missions.
Experience supporting commercial threat hunting operations.
Experience supporting, leading and or directing threat hunt teams withinOT/ICS environments.
Experience supporting, leading and or directing cyber protection teams.
Significant hands-on experience with advanced threat huntingtechniques in air-gapped and or otherwise sensitive operating environments.
Certifications such as GREM,Certified Threat Hunter (MTH),Offensive Security Certified Professional Plus (OCSP+),GIAC Penetration Tester (GPEN),GCTI, GNFA,GRID, CRTOor similar advanced technical credentials.
Experience with ATT&CK frameworks across Enterprise, Cloud, and ICS.
Experience managing deployable cyber hunt kits orrapid responseteams.
GDIT IS YOUR PLACE
At GDIT, the mission is our purpose, and our people are at the center of everything we do.
Growth: AI-powered career tool that identifies career steps and learning opportunities
Support: An internal mobility team focused on helping you achieve your career goals
Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off
Community: Award-winning culture of innovation and a military-friendly workplace
Scheduled Weekly Hours:
40Travel Required:
Less than 10%Telecommuting Options:
HybridWork Location:
USA VA HerndonAdditional Work Locations:
Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.We are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology.Join our Talent Community to stay up to date on our career opportunities and events atgdit.com/tc.
Equal Opportunity Employer / Individuals with Disabilities / Protected VeteransWhat General Dynamics Information Technology employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About General Dynamics Information Technology
Sourced by ZipRecruiter
GDIT is a global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense, and intelligence community. Its 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. The company operates across 50+ countries worldwide, offering leading capabilities in digital modernization, AI/ML, cloud, cyber, and application development.
Industry
It services
Company size
10,000+ Employees
Headquarters location
Falls Church, VA, US