Home › Companies › Shorepointinc › Threat Hunter
Threat Hunter
Shorepointinc · Remote · Active · BambooHR
Job facts
| Field | Value |
|---|---|
| Company | Shorepointinc |
| Title | Threat Hunter |
| Normalized title | - |
| Department / team | Staff |
| Location | Herndon, VA, United States |
| Work model | Remote / Remote |
| Employment type | Full Time |
| Salary | - |
| Status | active |
| ATS provider | BambooHR |
| Posted / first seen | 2026-04-17 / 2026-05-30 |
| Changed / last seen | 2026-05-30 / 2026-06-06 |
Related slices
| Page | What it contains | Open |
|---|---|---|
| Company jobs | Active postings from Shorepointinc. | Open |
| Company breakdowns | Role, location, ATS, and work model facets for this company. | Open |
| ATS provider jobs | Active postings observed through BambooHR. | Open |
| Provider filtered search | The same provider as a filtered job collection. | Open |
| City jobs | Active postings in Herndon. | Open |
| Department jobs | Active postings in Staff. | Open |
| Work model jobs | Active Remote postings. | Open |
| Lifecycle events | Open, update, close, and reopen events for this posting. | Open |
| Original posting | Canonical source or apply URL captured from the ATS. | Open |
Linked records
| Company | Shorepointinc |
| Source | 8f3b3eb9-ce20-4a59-8d89-dc4f1c2bfd80 |
| ATS provider | BambooHR |
Description
Who we are:
ShorePoint is a fast-growing, industry recognized and award-winning cybersecurity services firm with a focus on high-profile, high-threat, private and public-sector customers who demand experience and proven security models to protect their data. ShorePoint subscribes to a “work hard, play hard” mentality and celebrates individual and company successes. We are passionate about our mission and going above and beyond to deliver for our customers. We are equally passionate about an environment that supports creativity, accountability, diversity, inclusion and a focus on giving back to our community.
The Perks:
As recognized members of the Cyber Elite, we work together in partnership to defend our nation’s critical infrastructure while building meaningful and exciting career development opportunities in a culture tailored to the individuals technical and professional growth. We are committed to the belief that our team members do their best work when they are happy and well cared for. In support of this philosophy, we offer a comprehensive benefits package, including major carriers for health care providers. Highlighted benefits offered: 144 hours of PTO, 11 holidays, 85% of insurance premium covered, 401k, continued education, certifications maintenance and reimbursement and more.
Who we’re looking for:
We are seeking a Threat Hunter to support and enhance our 24/7 Security Operations Center. This role combines advanced threat detection, incident investigation and threat hunting with hands-on development of SIEM use cases, automation and analytics to identify and respond to sophisticated threats, including lateral movement. The ideal Threat Hunter brings strong investigative expertise and a builder mindset to continuously improve detection capabilities and strengthen overall SOC effectiveness. This is a unique opportunity to shape the growth, development and culture of an exciting and fast-growing company in the cybersecurity market.
What you’ll be doing:
Provide first-line SOC support, including alert monitoring, triage, routing, escalation and response across 24x7x365 operations.
Monitor, analyze and investigate security events, network traffic and host-based detections, distinguishing malicious activity from false positives.
Perform proactive and creative threat hunting and anomaly detection across SIEM and security tools, identifying patterns, lateral movement and emerging threats.
Conduct incident investigation, Cyber Threat Assessment and Remediation Analysis, including processing and correlating incident indicators with threat intelligence.
Tune and develop SIEM correlation rules and detection logic and rapidly build detection use cases in collaboration with incident response (IR) teams.
Develop and maintain scripts and tools (Python, Bash) to automate SOC and IR functions, including Indicator of compromise (IoC) ingestion, log processing and SIEM integrations via APIs.
Research, develop and maintain dashboards, visualizations and analytics to support detection, reporting and SOC performance monitoring.
Produce, review and maintain documentation and reporting, including cybersecurity briefings, metrics, incident reports and deliverables for stakeholders at all levels, ensuring alignment with editorial standards and government specifications.
Support threat intelligence operations, including reviewing and actioning IoCs and translating intelligence into actionable detections.
Coordinate with internal teams and stakeholders to support engagements such as Insider Threat, Rule of Engagement (ROE), threat hunting, testing activities and after-action reporting.
Support SOC operations processes, including ticket tracking, customer security assessments, ad hoc investigations, tabletop exercises and lessons learned activities.
Contribute to continuous SOC improvement by enhancing detection capabilities, processes, communication and overall operational effectiveness; participate in on-call rotation.
What you need to know:
Deep understanding of cyber threat TTPs, threat hunting methodologies and application of the MITRE ATT&CK framework.
Experience supporting 24x7x365 SOC operations, including alert monitoring, triage, analysis, response and review/action of threat intelligence and reported incidents.
Ability to manage multiple alerts and tickets in parallel, perform end-to-end triage through resolution and appropriately prioritize response actions including coordination with end-users.
Strong experience analyzing and correlating security events across multi-source ecosystem, including endpoint, network, email security tools, SIEM platforms and federal threat intelligence (e.g., CISA).
Demonstrated proficiency with enterprise security tools and platforms, including but not limited to FireEye, Elastic, Sourcefire, Malwarebytes, Carbon Black/Bit9, Splunk, Prisma Cloud, Cisco IronPort, Bluecoat, Palo Alto, Cylance and OSSEC.
Hands-on experience with enterprise SIEM or security analytics platforms (e.g., Elastic Stack, Splunk), including log analysis, event correlation and detection support.
Experience with malware analysis and understanding of attack vectors involving malware, data exposure, phishing and social engineering techniques.
Experience developing and maintaining SOPs, performing event timeline analysis and investigating logs across Windows/Linux environments and network security devices.
Must have’s:
5+ years of technical experience.
Ability to support working hours: 8:45 AM - 5:15 PM Eastern Time
Ability to participate in a rotating SOC on-call; rotation is based on number of team members.
Demonstrated proficiencies with one or more toolsets such as Bit9/CarbonBlack, CrowdStrike, FireEye ETP, Elastic Kibana.
Solid understanding and experience analyzing security events generated from security tools and devices such as: Carbon Black, CrowdStrike, FireEye, Palo Alto, Cylance and OSSEC.
Proven ability to analyze complex requirements and translate them into clear, actionable tasks and processes through critical thinking.
Applicants must currently be a U.S. citizen in compliance with federal contract requirements
Beneficial to have:
Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Mathematics, Engineering or a related field.
One or more of the following certifications: GIAC (GCIH, GCFE, GCFA, GREM, GNFA, GCTI, GPEN, GWAPT), CEPT, CASS, CWAPT or CREA.
Where it’s done:
Remote (Herndon, VA)
Full job record
| Job ID | 455402ed77086141b3a5bec0fbfadde02c4ddd4e |
| Org ID | ba8a0b6d-b2b7-4f57-98e0-20909e905a41 |
| Source ID | 8f3b3eb9-ce20-4a59-8d89-dc4f1c2bfd80 |
| Board ID | 8f3b3eb9-ce20-4a59-8d89-dc4f1c2bfd80 |
| Provider | bamboohr |
| Provider Job Key | 887 |
| Title | Threat Hunter |
| Normalized Title | — |
| Status | active |
| Active | yes |
| Location Text | — |
| Department | Staff |
| Team | — |
| Employment Type | full_time |
| Workplace Type | remote |
| Remote Policy | remote |
| Country | United States |
| Region | VA |
| City | Herndon |
| Salary Raw | — |
| Salary Min | — |
| Salary Max | — |
| Salary Currency | — |
| Salary Period | — |
| Source URL | https://shorepointinc.bamboohr.com/careers/887 |
| Apply URL | https://shorepointinc.bamboohr.com/careers/887 |
| First Seen At | 2026-05-30 05:58:08Z |
| Last Seen At | 2026-06-06 09:45:56Z |
| Last Checked At | 2026-06-06 09:45:56Z |
| Last Changed At | 2026-05-30 05:58:08Z |
| Inactive At | — |
| Source Posted At | 2026-04-17 00:00:00Z |
| Source Updated At | — |
| Raw Payload Uri | s3://job-postings-prod-raw-590183727216/raw/provider=bamboohr/board=shorepointinc/date=2026-06-06/2026-06-06T09-45-55-272Z-6b2ecd4669f1a82076effded4764d1b93f1b3cd79f1ba1db0544865275727ce3.json |
Event Fields
{
"content_hash": "4e7963dc5b1f08041f1d4a89c722eeedb567fc1e92f9a6fd9e144fa3f6d9a236",
"source_hash": "50a576102056e05bf0c72d7f1b89786469b057b0bcefc8b3689d57544eadc603",
"last_changed_at": "2026-05-30T05:58:08.457Z",
"active_status": "active"
}Parsed Structured
{
"language": "en",
"location": {
"raw": "Herndon, Virginia, United States",
"city": "Herndon",
"region": "VA",
"country": "United States",
"is_remote": true,
"confidence": 0.8
},
"salary_max": null,
"salary_min": null,
"inferred_at": "2026-06-06T09:45:56.183Z",
"launch_scope": {
"reason": "bamboohr_production_catalog",
"included": true,
"location": {
"raw": "Herndon, Virginia, United States",
"city": "Herndon",
"region": "VA",
"country": "United States",
"is_remote": true,
"confidence": 0.8
},
"countries": [
"United States"
]
},
"remote_policy": "remote",
"salary_period": null,
"workplace_type": "remote",
"salary_currency": null
}Extensions
{}Native Structured
{
"list_job": {
"id": "887",
"isRemote": null,
"location": {
"city": null,
"state": null
},
"atsLocation": {
"city": "Herndon",
"state": "Virginia",
"country": "United States",
"province": null
},
"departmentId": "18436",
"locationType": "1",
"jobOpeningName": "Threat Hunter ",
"departmentLabel": "Staff",
"employmentStatusLabel": "Full-Time"
},
"detail_errors": [],
"detail_job_opening": {
"location": {
"city": null,
"state": null,
"postalCode": null,
"addressCountry": null
},
"datePosted": "2026-04-17",
"atsLocation": {
"city": "Herndon",
"state": "Virginia",
"country": "United States",
"countryId": "1"
},
"description": "<p><span style=\"font-weight: bold\">Who we are:</span></p>\n<p><br></p>\n<p>ShorePoint is a fast-growing, industry recognized and award-winning cybersecurity services firm with a focus on high-profile, high-threat, private and public-sector customers who demand experience and proven security models to protect their data. ShorePoint subscribes to a “work hard, play hard” mentality and celebrates individual and company successes. We are passionate about our mission and going above and beyond to deliver for our customers. We are equally passionate about an environment that supports creativity, accountability, diversity, inclusion and a focus on giving back to our community. </p>\n<p><br></p>\n<p><span style=\"font-weight: bold\">The Perks:</span></p>\n<p><br></p>\n<p>As recognized members of the Cyber Elite, we work together in partnership to defend our nation’s critical infrastructure while building meaningful and exciting career development opportunities in a culture tailored to the individuals technical and professional growth. We are committed to the belief that our team members do their best work when they are happy and well cared for. In support of this philosophy, we offer a comprehensive benefits package, including major carriers for health care providers. Highlighted benefits offered: 144 hours of PTO, 11 holidays, 85% of insurance premium covered, 401k, continued education, certifications maintenance and reimbursement and more.</p>\n<p><br></p>\n<p><span style=\"font-weight: bold\">Who we’re looking for:</span></p>\n<p><br></p>\n<p>We are seeking a <span style=\"font-weight: bold\">Threat Hunter</span> to support and enhance our 24/7 Security Operations Center. This role combines advanced threat detection, incident investigation and threat hunting with hands-on development of SIEM use cases, automation and analytics to identify and respond to sophisticated threats, including lateral movement. The ideal <span style=\"font-weight: bold\">Threat Hunter</span> brings strong investigative expertise and a builder mindset to continuously improve detection capabilities and strengthen overall SOC effectiveness. This is a unique opportunity to shape the growth, development and culture of an exciting and fast-growing company in the cybersecurity market.</p>\n<p><br></p>\n<p><span style=\"font-weight: bold\">What you’ll be doing: </span></p>\n<p><br></p>\n<ul>\n<li>Provide first-line SOC support, including alert monitoring, triage, routing, escalation and response across 24x7x365 operations.</li>\n<li>Monitor, analyze and investigate security events, network traffic and host-based detections, distinguishing malicious activity from false positives.</li>\n<li>Perform proactive and creative threat hunting and anomaly detection across SIEM and security tools, identifying patterns, lateral movement and emerging threats.</li>\n<li>Conduct incident investigation, Cyber Threat Assessment and Remediation Analysis, including processing and correlating incident indicators with threat intelligence.</li>\n<li>Tune and develop SIEM correlation rules and detection logic and rapidly build detection use cases in collaboration with incident response (IR) teams.</li>\n<li>Develop and maintain scripts and tools (Python, Bash) to automate SOC and IR functions, including Indicator of compromise (IoC) ingestion, log processing and SIEM integrations via APIs.</li>\n<li>Research, develop and maintain dashboards, visualizations and analytics to support detection, reporting and SOC performance monitoring.</li>\n<li>Produce, review and maintain documentation and reporting, including cybersecurity briefings, metrics, incident reports and deliverables for stakeholders at all levels, ensuring alignment with editorial standards and government specifications.</li>\n<li>Support threat intelligence operations, including reviewing and actioning IoCs and translating intelligence into actionable detections.</li>\n<li>Coordinate with internal teams and stakeholders to support engagements such as Insider Threat, Rule of Engagement (ROE), threat hunting, testing activities and after-action reporting.</li>\n<li>Support SOC operations processes, including ticket tracking, customer security assessments, ad hoc investigations, tabletop exercises and lessons learned activities.</li>\n<li>Contribute to continuous SOC improvement by enhancing detection capabilities, processes, communication and overall operational effectiveness; participate in on-call rotation.<br></li>\n</ul>\n<p><br></p>\n<p><span style=\"font-weight: bold\">What you need to know: </span><br></p>\n<p><br></p>\n<ul>\n<li>Deep understanding of cyber threat TTPs, threat hunting methodologies and application of the MITRE ATT&CK framework.</li>\n<li>Experience supporting 24x7x365 SOC operations, including alert monitoring, triage, analysis, response and review/action of threat intelligence and reported incidents.</li>\n<li>Ability to manage multiple alerts and tickets in parallel, perform end-to-end triage through resolution and appropriately prioritize response actions including coordination with end-users.</li>\n<li>Strong experience analyzing and correlating security events across multi-source ecosystem, including endpoint, network, email security tools, SIEM platforms and federal threat intelligence (e.g., CISA).</li>\n<li>Demonstrated proficiency with enterprise security tools and platforms, including but not limited to FireEye, Elastic, Sourcefire, Malwarebytes, Carbon Black/Bit9, Splunk, Prisma Cloud, Cisco IronPort, Bluecoat, Palo Alto, Cylance and OSSEC.</li>\n<li>Hands-on experience with enterprise SIEM or security analytics platforms (e.g., Elastic Stack, Splunk), including log analysis, event correlation and detection support.</li>\n<li>Experience with malware analysis and understanding of attack vectors involving malware, data exposure, phishing and social engineering techniques.</li>\n<li>Experience developing and maintaining SOPs, performing event timeline analysis and investigating logs across Windows/Linux environments and network security devices.</li>\n</ul>\n<p><br></p>\n<p><span style=\"font-weight: bold\">Must have’s: </span></p>\n<p><br></p>\n<ul>\n<li>5+ years of technical experience.</li>\n<li>Ability to support working hours: 8:45 AM - 5:15 PM Eastern Time</li>\n<li>Ability to participate in a rotating SOC on-call; rotation is based on number of team members.</li>\n<li>Demonstrated proficiencies with one or more toolsets such as Bit9/CarbonBlack, CrowdStrike, FireEye ETP, Elastic Kibana.</li>\n<li>Solid understanding and experience analyzing security events generated from security tools and devices such as: Carbon Black, CrowdStrike, FireEye, Palo Alto, Cylance and OSSEC.</li>\n<li>Proven ability to analyze complex requirements and translate them into clear, actionable tasks and processes through critical thinking.</li>\n<li>Applicants must currently be a U.S. citizen in compliance with federal contract requirements </li>\n</ul>\n<p><br></p>\n<p><span style=\"font-weight: bold\">Beneficial to have:</span></p>\n<p><br></p>\n<ul>\n<li>Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Mathematics, Engineering or a related field.</li>\n<li>One or more of the following certifications: GIAC (GCIH, GCFE, GCFA, GREM, GNFA, GCTI, GPEN, GWAPT), CEPT, CASS, CWAPT or CREA.<br></li>\n</ul>\n<p><br></p>\n<p><span style=\"font-weight: bold\">Where it’s done: </span><br></p>\n<p><br></p>\n<ul>\n<li>Remote (Herndon, VA)</li>\n</ul>",
"compensation": null,
"departmentId": "18436",
"locationType": "1",
"seekPromoted": false,
"jobCategoryId": "18380",
"jobOpeningName": "Threat Hunter ",
"departmentLabel": "Staff",
"jobOpeningStatus": "Open",
"minimumExperience": "Experienced",
"jobOpeningShareUrl": "https://shorepointinc.bamboohr.com/careers/887",
"employmentStatusLabel": "Full-Time"
}
}Get this page with API
Rendered from the bluedoor Job Postings API. Reproduce it:
GET https://api.bluedoor.sh/job-postings/v1/jobs/455402ed77086141b3a5bec0fbfadde02c4ddd4e?include=descriptionJSONGET https://api.bluedoor.sh/job-postings/v1/orgs/ba8a0b6d-b2b7-4f57-98e0-20909e905a41JSONGET https://api.bluedoor.sh/job-postings/v1/sources/8f3b3eb9-ce20-4a59-8d89-dc4f1c2bfd80JSONGET https://api.bluedoor.sh/job-postings/v1/jobs/455402ed77086141b3a5bec0fbfadde02c4ddd4e/eventsJSON