Independent job-search site. Not affiliated with the U.S. government. Applications happen on the official USAJOBS.gov. Learn more
Home/Jobs/Cybersecurity Principal Specialist - Hunt Network #5302
Announcement #879044300

Cybersecurity Principal Specialist - Hunt Network #5302

Senate · Washington, District of Columbia
Open to the publicTelework eligible

What you'd do

The Senate Sergeant at Arms is seeking a Cybersecurity Principal Specialist - Hunt Network #5302. The complete vacancy announcement and application can be found on the United States Senate Career Page at https://sen.gov/1VNZQ. This vacancy announcement closes at 7pm EST on the closing date. Late applications will not be accepted.

Major duties

Provides functional and/or technical skills for the assigned cybersecurity unit. Supports the unit’s work effort as required in preparing materials for collaborating with other sections, divisions, departments, and vendors to gather and disseminate information. Contributes to the unit’s work effort as required in preparing analysis and materials for providing expert-level support in the assigned area of cybersecurity to SAA IT security branch staff, other SAA technical staff, SAA procurement staff, and other divisions or departments, and for identifying and resolving critical and complex issues in the assigned unit. Supports the unit’s work effort as directed in providing leadership to the unit’s project teams and contractors. Work includes helping to develop plans, assignments, and coordination of work efforts. Supports the unit’s work effort to develop governing policies, standards, and procedures. Other duties as assigned.

What you need to qualify

Required Work Experience Seven to ten years of progressively responsible experience in cybersecurity, with a track record of leading initiatives to resolve highly complex cybersecurity issues. Subject matter expertise in one or more cybersecurity domains. Strong leadership skills, including experience managing project teams and coordinating efforts across multiple departments. Demonstrated ability to develop and implement strategic cybersecurity policies, standards, and frameworks that align with organizational goals. Required Special Skills/ Knowledge As part of our hiring process, we may conduct a skills assessment to better understand an applicant’s proficiency in key areas relevant to the role. Desired Qualifications: We are seeking an experienced, senior-level cybersecurity professional ready to operate at the forefront of US Senate’s cyber defense. The ideal candidate should have: Cybersecurity Experience: 7–10 years of progressively responsible experience in cybersecurity, with a demonstrated track record of leading initiatives to resolve highly complex cybersecurity issues. At least 5 years of that experience should be in threat hunting, network forensics, or incident response, with hands-on expertise in network-layer analysis and adversary pursuit. Domain Expertise: Subject matter expertise in one or more cybersecurity domains, with particular depth in network forensics, threat hunting, or digital forensics and incident response (DFIR). Experience operating in high-tempo, enterprise-scale environments is strongly preferred. Leadership & Collaboration: Strong leadership skills, including experience managing project teams and coordinating efforts across multiple departments. Proven ability to serve as a technical authority and mentor to junior team members while maintaining hands-on operational proficiency. Communication Skills: The ability to communicate complex technical findings clearly and concisely both verbally and in writing to audiences ranging from technical practitioners to executive leadership and legislative stakeholders. Self-Directed Learning: The ability to rapidly learn highly technical concepts with minimal instruction, stay current with the evolving threat landscape, and apply new knowledge operationally without formal training. Security Clearance: Must be able to obtain and maintain a security clearance. Skills and Abilities: The ideal candidate will demonstrate a diverse range of skills and abilities vital for effective performance. Network Forensics & Analysis Packet Analysis: Advanced experience using Wireshark for deep packet inspection, traffic reconstruction, and forensic analysis of network-layer evidence during incident response and threat hunting operations. Network Protocol Analysis: Deep understanding of TCP/IP networking, including protocol behavior, packet structures, and common application-layer protocols (HTTP/S, DNS, SMB, FTP, Kerberos, etc.). Ability to identify anomalous or malicious protocol usage indicative of attacker activity. Network Log Analysis: Strong proficiency with Zeek for developing and executing threat hunting hypotheses, analyzing connection logs, and identifying anomalous behavioral patterns across the enterprise. Network Intrusion Detection: Hands-on experience with network security monitoring platforms and intrusion detection systems such as Suricata or Snort, including rule writing, tuning, and alert triage. Network Rule Formats: Proficiency with network-focused detection rule formats including Snort and Suricata rules. (Preferred: Sigma and YARA for cross-platform detection coverage.) Threat Hunting & Detection Engineering Hypothesis-Driven Hunting: Demonstrated ability to develop, execute, and document structured threat hunting hypotheses across large, complex datasets to identify stealthy, undetected, or low-and-slow adversary activity. Adversary Frameworks: Strong working knowledge of MITRE ATT&CK and other adversary behavior frameworks to map observed activity to known TTPs, identify coverage gaps, and prioritize hunting efforts. Custom Detection Development: Demonstrated ability to design, develop, and maintain custom security detections targeting advanced attack techniques, including living-off-the-land activity, lateral movement, privilege escalation, and data exfiltration across SIEM, EDR, and log analytics platforms. Data Correlation & Pivoting: Ability to pivot fluidly across multiple data sources — network, endpoint, cloud, and logs — to validate findings, establish timelines, and build a complete adversary narrative. Adversary Emulation: Ability to conduct adversary emulation and basic red team activities to validate detection coverage and ensure detections are correctly tuned and operationally effective. Incident Response & Forensics Host Forensics: Deep familiarity with major host artifact locations across Windows, Linux, and MacOS, and proficiency with major host forensic toolsets for evidence collection, triage, and analysis. Operating System Internals: Deep understanding of the internal functionality of all major operating systems (Windows, Linux, MacOS). (Preferred: familiarity with less common operating systems such as Cisco IOS, Solaris, and mobile operating systems.) General Technical Skills Scripting & Automation: Proficiency in at least one scripting language (Python, PowerShell, Bash, Ruby, or Perl) for automating investigative tasks, parsing large datasets, and accelerating hunt and response workflows. Documentation: Ability to capture the results of complex, long-running technical investigations in a manner that is clear, precise, and actionable suitable for both technical peers and executive audiences. Certifications: Network forensics and incident response certifications are strongly preferred, including GCIA (GIAC Certified Intrusion Analyst), GNFA (GIAC Network Forensic Analyst), GCIH, GCFA, or GCED. (Preferred: CISSP for candidates in or approaching leadership tracks.) Working Conditions This position directly supports essential services of the U.S. Senate. As such, this position requires the employee to be available and prepared to work during a lapse in appropriations, in inclement weather, on holidays, weekends, and during late nights to ensure essential services to the Senate continue without interruption. In the context of government furloughs, this position is considered excepted. The U.S. Senate network cannot be taken offline for maintenance during the workday or while the Senate is in session. As such, maintenance windows may only occur at night, on weekends, and occasionally on holidays. Employees who perform systems upgrades, maintenance, wiring, backups, and support for our alternate data centers will have schedules that include working nights, weekends, and holidays. Sedentary. Security Clearance This position requires that the applicant obtain and maintain a Secret U.S. Government security clearance. Applicants must be U.S. citizens in order for the SAA to submit your application for a security clearance.

Before you apply

Federal applications are different: your resume should be 3–5 pages and mirror the language of this announcement. Read our federal resume guide first — it's the #1 reason qualified people get screened out.

Don't miss the next one.

Get an email the moment a similar federal job opens — postings can close in as little as 5 days.

Free forever. One click to unsubscribe.