Lead Threat Hunter

U.S. Bancorp
Cincinnati, Ohio 45208 United States  View Map
Posted: Jun 07, 2026
  • Full Time
  • Federal Government
  • Summary

    Lead Threat Hunter

    U.S. Bank is looking for an experienced Lead Threat Hunter to join our existing security incident response program and help us ensure the security of the enterprise by finding and responding to advanced threats in our environment. The Lead Threat Hunter serves as an advisor and/or senior member leader across domain security initiatives to identify vulnerabilities in systems, controls, and standards gaps. This includes leading efforts, designing, implementing and executing processes and controls for security functional areas. Defines strategic objectives and supporting goals to enhance the security of systems, networks, and technical platforms and drives progress of team objectives and achievements.

    About You:

    • You have been a technical incident responder/threat hunter for several years and have the skills to operate across common networks, operating systems and multi-cloud environments.
    • You have a track record of developing strong collaborations across teams to help you meet your goals.
    • You have a thirst for knowledge and continually seek out new things to learn.
    • You communicate your hunting findings effectively. You organize and share your knowledge to help colleagues and partners learn.
    • You default to hunting once and automate things to make hunting time more effective.
    • If it's not mapped to MITRE ATT&CK yet, you are going figure out a way to map it!
    • You realize that everyone makes mistakes and seek out feedback to help you learn and adjust your focus.
    • You are well-versed in AI topics and thinking AI-first.
    • You are a PROACTIVE hunter of all things security.

    About Us:

    • We recognize that a diverse team is more effective and always strives to be inclusive of different cultures, backgrounds and experience.
    • We are clear in our mission and objectives and hold ourselves accountable to them.
    • We believe in hunting once. When we can't, we automate and/or create playbooks.
    • We build strong partnerships and work towards common goals.
    • We share knowledge and seek to level up our partner teams.
    • We talk about MITRE ATT&CK and Threat Informed Defense (a lot!) and how to best use them to focus on hunting.

    Basic qualifications:

    • Bachelor's degree, or equivalent work experience8+ years of relevant experience

    Responsibilities will include:

    • Collaborating with security engineering teams to create and test detection rules.
    • Investigating potential cybersecurity incidents.
    • Developing response processes and training security operations staff.
    • Reviewing and tracking detected events to identify new exploits, threats and mitigation strategies, and enforce incident reporting standards.
    • Leading in-depth technical analysis of new and emerging information security threats.
    • Analyzing threats and vulnerabilities to determine their impact to the bank's operations
    • Assisting with investigations and eDiscovery efforts involving court-proven forensic processes and technologies.

    Required skills/experience:

    • Expertise in AI automation tooling.
    • Hunting with Jupyter notebooks, Python, automation and APIs.
    • Expertise hunting with security logging, monitoring, and event management tools.
    • Expertise in log analysis, packet analysis.
    • Knowledge of threat hunting frameworks.
    • Experience with incident response or threat hunting in major cloud environments such as AWS, Azure and GCP.
    • Demonstrable proficiency in threat intelligence platforms, security automation and orchestration and red/blue/purple team activities.
    • Excellent communication and reporting skills.
    • 8 or more years' experience in information security.
    • 4 or more years' experience with incident response/incident handling.
    • 2 or more years' experience as a threat hunter.
    • Thorough understanding of the applicable information security systems, policies, and procedures.
    • Effective communication, presentation skills, leadership, problem-solving and analytical skills.
    • Proven collaboration and influencing skills.

    Preferred skills/experience:

    • Malware reverse engineering skills.
    • Expertise with incident response frameworks.
    • Experience in the financial sector.
    • SANS, CHFI, OSCP or similar certification.

    Benefits:

    • Healthcare (medical, dental, vision)
    • Basic term and optional term life insurance
    • Short-term and long-term disability
    • Pregnancy disability and parental leave
    • 401(k) and employer-funded retirement plan
    • Paid vacation (from two to five weeks depending on salary grade and tenure)
    • Up to 11 paid holiday opportunities
    • Adoption assistance
    • Sick and Safe Leave accruals of one hour for every 30 worked, up to 80 hours per calendar year unless otherwise provided by law

    U.S. Bank is an equal opportunity employer. We consider all qualified applicants without regard to race, religion, color, sex, national origin, age, sexual orientation, gender identity, disability or veteran status, and other factors protected under applicable law.

  • Job Description

    Lead Threat Hunter

    U.S. Bank is looking for an experienced Lead Threat Hunter to join our existing security incident response program and help us ensure the security of the enterprise by finding and responding to advanced threats in our environment. The Lead Threat Hunter serves as an advisor and/or senior member leader across domain security initiatives to identify vulnerabilities in systems, controls, and standards gaps. This includes leading efforts, designing, implementing and executing processes and controls for security functional areas. Defines strategic objectives and supporting goals to enhance the security of systems, networks, and technical platforms and drives progress of team objectives and achievements.

    About You:

    • You have been a technical incident responder/threat hunter for several years and have the skills to operate across common networks, operating systems and multi-cloud environments.
    • You have a track record of developing strong collaborations across teams to help you meet your goals.
    • You have a thirst for knowledge and continually seek out new things to learn.
    • You communicate your hunting findings effectively. You organize and share your knowledge to help colleagues and partners learn.
    • You default to hunting once and automate things to make hunting time more effective.
    • If it's not mapped to MITRE ATT&CK yet, you are going figure out a way to map it!
    • You realize that everyone makes mistakes and seek out feedback to help you learn and adjust your focus.
    • You are well-versed in AI topics and thinking AI-first.
    • You are a PROACTIVE hunter of all things security.

    About Us:

    • We recognize that a diverse team is more effective and always strives to be inclusive of different cultures, backgrounds and experience.
    • We are clear in our mission and objectives and hold ourselves accountable to them.
    • We believe in hunting once. When we can't, we automate and/or create playbooks.
    • We build strong partnerships and work towards common goals.
    • We share knowledge and seek to level up our partner teams.
    • We talk about MITRE ATT&CK and Threat Informed Defense (a lot!) and how to best use them to focus on hunting.

    Basic qualifications:

    • Bachelor's degree, or equivalent work experience8+ years of relevant experience

    Responsibilities will include:

    • Collaborating with security engineering teams to create and test detection rules.
    • Investigating potential cybersecurity incidents.
    • Developing response processes and training security operations staff.
    • Reviewing and tracking detected events to identify new exploits, threats and mitigation strategies, and enforce incident reporting standards.
    • Leading in-depth technical analysis of new and emerging information security threats.
    • Analyzing threats and vulnerabilities to determine their impact to the bank's operations
    • Assisting with investigations and eDiscovery efforts involving court-proven forensic processes and technologies.

    Required skills/experience:

    • Expertise in AI automation tooling.
    • Hunting with Jupyter notebooks, Python, automation and APIs.
    • Expertise hunting with security logging, monitoring, and event management tools.
    • Expertise in log analysis, packet analysis.
    • Knowledge of threat hunting frameworks.
    • Experience with incident response or threat hunting in major cloud environments such as AWS, Azure and GCP.
    • Demonstrable proficiency in threat intelligence platforms, security automation and orchestration and red/blue/purple team activities.
    • Excellent communication and reporting skills.
    • 8 or more years' experience in information security.
    • 4 or more years' experience with incident response/incident handling.
    • 2 or more years' experience as a threat hunter.
    • Thorough understanding of the applicable information security systems, policies, and procedures.
    • Effective communication, presentation skills, leadership, problem-solving and analytical skills.
    • Proven collaboration and influencing skills.

    Preferred skills/experience:

    • Malware reverse engineering skills.
    • Expertise with incident response frameworks.
    • Experience in the financial sector.
    • SANS, CHFI, OSCP or similar certification.

    Benefits:

    • Healthcare (medical, dental, vision)
    • Basic term and optional term life insurance
    • Short-term and long-term disability
    • Pregnancy disability and parental leave
    • 401(k) and employer-funded retirement plan
    • Paid vacation (from two to five weeks depending on salary grade and tenure)
    • Up to 11 paid holiday opportunities
    • Adoption assistance
    • Sick and Safe Leave accruals of one hour for every 30 worked, up to 80 hours per calendar year unless otherwise provided by law

    U.S. Bank is an equal opportunity employer. We consider all qualified applicants without regard to race, religion, color, sex, national origin, age, sexual orientation, gender identity, disability or veteran status, and other factors protected under applicable law.

  • ABOUT THE COMPANY

    • Government Careers
    • Government Careers

    Government jobs offer stability, competitive benefits, and the chance to make a meaningful impact on your community and country.

    Whether you’re starting your career or seeking new opportunities, these roles provide pathways for growth, security, and service.

    Explore positions across a wide range of fields and take the first step toward a rewarding future in public service.

    Show more

MORE JOBS

  • Customs and Border Protection Officer

    • Detroit, Michigan
    • U.S. Customs and Border Protection
    • Jun 07, 2026
    • Full Time
    • Education and Training
    • Federal Government
  • Senior Relativity SME

    • New York, New York
    • Contact Government Services, LLC
    • Jun 07, 2026
    • Full Time
    • Federal Government
  • Customs and Border Protection Officer

    • Aurora, Illinois
    • U.S. Customs and Border Protection
    • Jun 07, 2026
    • Full Time
    • Education and Training
    • Federal Government
  • Customs and Border Protection Officer (CBPO) Entry Level New Hire Sign-On and Retention Incentives

    • Mount Vernon, New York
    • U.S. Customs and Border Protection
    • Jun 07, 2026
    • Full Time
    • Education and Training
    • Federal Government
  • Aircrew Rescue Swimmer & Navy Diver

    • Painesville, Ohio
    • U.S. Navy
    • Jun 07, 2026
    • Full Time
    • Federal Government
  • GenAI Outcome Engineer with Security Clearance

    • Falls Church, Virginia
    • Kavaliro
    • Jun 07, 2026
    • Full Time
    • Federal Government
Show More
Apply Now Please mention you found this employment opportunity on the CareersInGovernment.com Job Board.
Please mention you found this employment opportunity on the CareersInGovernment.com Job Board.