Threat Hunter/Detection Engineer - Tier 3
Title
Threat Hunter/Detection Engineer - Tier 3
ID
10000267
Department
Information Technology
Evans & Chambers partners with the US national defense community to create fully integrated, resilient, and innovative digital solutions that enable them to make smart decisions in real-time. We work with our customers on everything from conquering their data to improving and safeguarding IT infrastructure. Our ultimate goal? To enhance our nation's ability to identify, address, and act – no matter what challenges arise.
Position Summary: The Tier 3 Threat Hunter / Detection Engineer performs proactive threat hunting against current adversary tactics, techniques, and procedures (TTPs), develops and tunes detection content, and provides senior technical leadership for advanced or persistent threat investigations, consistent with the SOC operating model.
Clearance: TS/SCI with CI Poly
Location: Ft. Meade, MD (Onsite)
Work Schedule and Conditions: Primary shift assignment within the 24/7/365 coverage model. Serve as a senior on-call escalation point for advanced incidents.
Duties and Responsibilities: Duties include the following.
· Conduct proactive, hypothesis-driven threat hunts informed by current cyber threat intelligence and adversary TTP frameworks.
· Develop, tune, and maintain SIEM and SOAR detection content and automated response playbooks, incorporating findings from incident after-action reviews.
· Lead technical investigation of advanced, persistent, or previously undetected threats, including advanced malware analysis and forensics beyond the scope of Tier 2 investigation.
· Provide senior technical mentorship to Tier 1 and Tier 2 staff, and support recurring tabletop, red-team, and purple-team exercises.
· Participate in design-time control mapping and threat modeling activities, providing SOC-informed input to architecture and platform engineering decisions.
Required Education and Experience: Bachelor's degree in Cybersecurity, Computer Science, or a related field required; Master's degree preferred. Typically five to eight or more years of progressive cybersecurity experience, including threat hunting, detection engineering, or advanced incident response.
Required Certifications: DoD 8570/8140 IAT Level III required, plus at least one advanced certification such as GCTI, GCFA, OSCP, or CISSP; demonstrated proficiency in SIEM/SOAR content development and scripting/automation.
Salary Range: $130k - $150k Depending on Experience and Shift
All employment opportunities are made without regard to age, race, creed, color, religion, sex national origin, ancestry, disability status, veteran status, sexual orientation, gender identity or expression, genetic information, marital status or any other basis protected by law.

