Cybersecurity Principal Specialist Hunt Network #5302
Washington, AR - USA
Job Summary
The Senate Sergeant at Arms is seeking a Cybersecurity Principal Specialist - Hunt Network #5302. The complete vacancy announcement and application can be found on the United States Senate Career Page at This vacancy announcement closes at 7pm EST on the closing date. Late applications will not be accepted.
Provides functional and/or technical skills for the assigned cybersecurity the units work effort as required in preparing materials for collaborating with other sections divisions departments and vendors to gather and disseminate to the units work effort as required in preparing analysis and materials for providing expert-level support in the assigned area of cybersecurity to SAA IT security branch staff other SAA technical staff SAA procurement staff and other divisions or departments and for identifying and resolving critical and complex issues in the assigned the units work effort as directed in providing leadership to the units project teams and contractors. Work includes helping to develop plans assignments and coordination of work the units work effort to develop governing policies standards and duties as assigned.
- For conditions of employment and citizenship requirements please visit the job announcement on the United States Senate Career Page at Work Experience
- Seven to ten years of progressively responsible experience in cybersecurity with a track record of leading initiatives to resolve highly complex cybersecurity issues. Subject matter expertise in one or more cybersecurity domains. Strong leadership skills including experience managing project teams and coordinating efforts across multiple departments. Demonstrated ability to develop and implement strategic cybersecurity policies standards and frameworks that align with organizational goals.
Required Special Skills/ Knowledge
- As part of our hiring process we may conduct a skills assessment to better understand an applicants proficiency in key areas relevant to the role.
DesiredQualifications:
We areseeking an experienced senior-level cybersecurity professional ready tooperate at the forefront of US Senates cyber defense. The ideal candidate should have:- Cybersecurity Experience: 710 years of progressively responsible experience in cybersecurity with a demonstrated track record of leading initiatives to resolve highly complex cybersecurity issues. At least 5 years of that experience should be in threat hunting network forensics or incident response with hands-on expertise in network-layer analysis and adversary pursuit.
- Domain Expertise: Subject matter expertise in one or more cybersecurity domains with particular depth in network forensics threat hunting or digital forensics and incident response (DFIR). Experience operating in high-tempo enterprise-scale environments is strongly preferred.
- Leadership & Collaboration: Strong leadership skills including experience managing project teams and coordinating efforts across multiple departments. Proven ability to serve as a technical authority and mentor to junior team members while maintaining hands-on operational proficiency.
- Communication Skills: The ability to communicate complex technical findings clearly and concisely both verbally and in writing to audiences ranging from technical practitioners to executive leadership and legislative stakeholders.
- Self-Directed Learning: The ability to rapidly learn highly technical concepts with minimal instruction stay current with the evolving threat landscape and apply new knowledge operationally without formal training.
Security Clearance: Must be able to obtain and maintain a security clearance.
Skillsand Abilities:
The ideal candidate will demonstrate a diverse range ofskills and abilities vital for effective performance.NetworkForensics & Analysis
- Packet Analysis: Advanced experience using Wireshark for deep packet inspection traffic reconstruction and forensic analysis of network-layer evidence during incident response and threat hunting operations.
- Network Protocol Analysis: Deep understanding of TCP/IP networking including protocol behavior packet structures and common application-layer protocols (HTTP/S DNS SMB FTP Kerberos etc.). Ability to identify anomalous or malicious protocol usage indicative of attacker activity.
- Network Log Analysis: Strong proficiency with Zeek for developing and executing threat hunting hypotheses analyzing connection logs and identifying anomalous behavioral patterns across the enterprise.
- Network Intrusion Detection: Hands-on experience with network security monitoring platforms and intrusion detection systems such as Suricata or Snort including rule writing tuning and alert triage.
- Network Rule Formats: Proficiency with network-focused detection rule formats including Snort and Suricata rules. (Preferred: Sigma and YARA for cross-platform detection coverage.)
ThreatHunting & Detection Engineering
- Hypothesis-Driven Hunting: Demonstrated ability to develop execute and document structured threat hunting hypotheses across large complex datasets to identify stealthy undetected or low-and-slow adversary activity.
- Adversary Frameworks: Strong working knowledge of MITRE ATT&CK and other adversary behavior frameworks to map observed activity to known TTPs identify coverage gaps and prioritize hunting efforts.
- Custom Detection Development: Demonstrated ability to design develop and maintain custom security detections targeting advanced attack techniques including living-off-the-land activity lateral movement privilege escalation and data exfiltration across SIEM EDR and log analytics platforms.
- Data Correlation & Pivoting: Ability to pivot fluidly across multiple data sources network endpoint cloud and logs to validate findings establish timelines and build a complete adversary narrative.
- Adversary Emulation: Ability to conduct adversary emulation and basic red team activities to validate detection coverage and ensure detections are correctly tuned and operationally effective.
IncidentResponse & Forensics
- Host Forensics: Deep familiarity with major host artifact locations across Windows Linux and MacOS and proficiency with major host forensic toolsets for evidence collection triage and analysis.
- Operating System Internals: Deep understanding of the internal functionality of all major operating systems (Windows Linux MacOS). (Preferred: familiarity with less common operating systems such as Cisco IOS Solaris and mobile operating systems.)
GeneralTechnical Skills
- Scripting & Automation: Proficiency in at least one scripting language (Python PowerShell Bash Ruby or Perl) for automating investigative tasks parsing large datasets and accelerating hunt and response workflows.
- Documentation: Ability to capture the results of complex long-running technical investigations in a manner that is clear precise and actionable suitable for both technical peers and executive audiences.
- Certifications: Network forensics and incident response certifications are strongly preferred including GCIA (GIAC Certified Intrusion Analyst) GNFA (GIAC Network Forensic Analyst) GCIH GCFA or GCED. (Preferred: CISSP for candidates in or approaching leadership tracks.)
Working Conditions
- This position directly supports essential services of the U.S. Senate. As such this position requires the employee to be available and prepared to work during a lapse in appropriations in inclement weather on holidays weekends and during late nights to ensure essential services to the Senate continue without the context of government furloughs this position is considered excepted.
- The U.S. Senate network cannot be taken offline for maintenance during the workday or while the Senate is in session. As such maintenance windows may only occur at night on weekends and occasionally on holidays. Employees who perform systems upgrades maintenance wiring backups and support for our alternate data centers will have schedules that include working nights weekends and holidays.
- Sedentary.
Security Clearance
- This position requires that the applicant obtain and maintain a SecretU.S. Government security clearance.
- Applicants must be U.S. citizens in order for the SAA to submit your application for a security clearance.
EducationHigh School Diploma/GED.
Additional informationThe Sergeant at Arms is an equal opportunity employer in accordance with the requirements of Senate rules regulations and applicable Federal Laws. This agency provides reasonable accommodations to applicants with disabilities. If you need a reasonable accommodation for any part of the application and hiring process please notify the agency. Decisions to grant reasonable accommodations will be determined on a case-by-case basis. Please email with Applicant Accommodation in the subject line. No moving relocation or pre-employment travel expenses will be paid for this position or while in application for this position.
Candidates should be committed to improving the efficiency of the Federal government passionate about the ideals of our American republic and committed to upholding the rule of law and the United States Constitution.
A career with the U.S. government provides employees with a comprehensive benefits package. As a federal employee you and your family will have access to a range of benefits that are designed to make your federal career very rewarding. Opens in a new windowLearn more about federal benefits.
Eligibility for benefits depends on the type of position you hold and whether your position is full-time part-time or intermittent. Contact the hiring agency for more information on the specific benefits offered.
Required Experience:
Staff IC