Cybersecurity Principal Specialist - Hunt Network #5302 Job in Washington, DC

Vacancy No. req1060 Department Senate
Salary $143,516.00 to $195,704.00 Grade 00 to 00
Perm/Temp Permanent FT/PT Full-time
Open Date 8/3/2026 Close Date 8/17/2026
Job Link Apply Online Who may apply Public
Locations:
Washington, DC


Cybersecurity Principal Specialist - Hunt Network #5302

Legislative Branch
Senate

Summary

The Senate Sergeant at Arms is seeking a Cybersecurity Principal Specialist - Hunt Network #5302. The complete vacancy announcement and application can be found on the United States Senate Career Page at https://sen.gov/1VNZQ. This vacancy announcement closes at 7pm EST on the closing date. Late applications will not be accepted.

This job is open to

The public

U.S. Citizens, Nationals or those who owe allegiance to the U.S.

Duties

Provides functional and/or technical skills for the assigned cybersecurity unit. Supports the unit’s work effort as required in preparing materials for collaborating with other sections, divisions, departments, and vendors to gather and disseminate information. Contributes to the unit’s work effort as required in preparing analysis and materials for providing expert-level support in the assigned area of cybersecurity to SAA IT security branch staff, other SAA technical staff, SAA procurement staff, and other divisions or departments, and for identifying and resolving critical and complex issues in the assigned unit. Supports the unit’s work effort as directed in providing leadership to the unit’s project teams and contractors. Work includes helping to develop plans, assignments, and coordination of work efforts. Supports the unit’s work effort to develop governing policies, standards, and procedures. Other duties as assigned.

Requirements

Conditions of employment

  • For conditions of employment and citizenship requirements, please visit the job announcement on the United States Senate Career Page at https://sen.gov/YO0NL.

Qualifications

Required Work Experience

  • Seven to ten years of progressively responsible experience in cybersecurity, with a track record of leading initiatives to resolve highly complex cybersecurity issues. Subject matter expertise in one or more cybersecurity domains. Strong leadership skills, including experience managing project teams and coordinating efforts across multiple departments. Demonstrated ability to develop and implement strategic cybersecurity policies, standards, and frameworks that align with organizational goals.

Required Special Skills/ Knowledge

  • As part of our hiring process, we may conduct a skills assessment to better understand an applicant’s proficiency in key areas relevant to the role. 

Desired Qualifications:
We are seeking an experienced, senior-level cybersecurity professional ready to operate at the forefront of US Senate’s cyber defense. The ideal candidate should have:

  • Cybersecurity Experience: 7–10 years of progressively responsible experience in cybersecurity, with a demonstrated track record of leading initiatives to resolve highly complex cybersecurity issues. At least 5 years of that experience should be in threat hunting, network forensics, or incident response, with hands-on expertise in network-layer analysis and adversary pursuit.
  • Domain Expertise: Subject matter expertise in one or more cybersecurity domains, with particular depth in network forensics, threat hunting, or digital forensics and incident response (DFIR). Experience operating in high-tempo, enterprise-scale environments is strongly preferred.
  • Leadership & Collaboration: Strong leadership skills, including experience managing project teams and coordinating efforts across multiple departments. Proven ability to serve as a technical authority and mentor to junior team members while maintaining hands-on operational proficiency.
  • Communication Skills: The ability to communicate complex technical findings clearly and concisely both verbally and in writing to audiences ranging from technical practitioners to executive leadership and legislative stakeholders.
  • Self-Directed Learning: The ability to rapidly learn highly technical concepts with minimal instruction, stay current with the evolving threat landscape, and apply new knowledge operationally without formal training.
    Security Clearance: Must be able to obtain and maintain a security clearance.

Skills and Abilities:
The ideal candidate will demonstrate a diverse range of skills and abilities vital for effective performance.

Network Forensics & Analysis

  • Packet Analysis: Advanced experience using Wireshark for deep packet inspection, traffic reconstruction, and forensic analysis of network-layer evidence during incident response and threat hunting operations.
  • Network Protocol Analysis: Deep understanding of TCP/IP networking, including protocol behavior, packet structures, and common application-layer protocols (HTTP/S, DNS, SMB, FTP, Kerberos, etc.). Ability to identify anomalous or malicious protocol usage indicative of attacker activity.
  • Network Log Analysis: Strong proficiency with Zeek for developing and executing threat hunting hypotheses, analyzing connection logs, and identifying anomalous behavioral patterns across the enterprise.
  • Network Intrusion Detection: Hands-on experience with network security monitoring platforms and intrusion detection systems such as Suricata or Snort, including rule writing, tuning, and alert triage.
  • Network Rule Formats: Proficiency with network-focused detection rule formats including Snort and Suricata rules. (Preferred: Sigma and YARA for cross-platform detection coverage.)

Threat Hunting & Detection Engineering

  • Hypothesis-Driven Hunting: Demonstrated ability to develop, execute, and document structured threat hunting hypotheses across large, complex datasets to identify stealthy, undetected, or low-and-slow adversary activity.
  • Adversary Frameworks: Strong working knowledge of MITRE ATT&CK and other adversary behavior frameworks to map observed activity to known TTPs, identify coverage gaps, and prioritize hunting efforts.
  • Custom Detection Development: Demonstrated ability to design, develop, and maintain custom security detections targeting advanced attack techniques, including living-off-the-land activity, lateral movement, privilege escalation, and data exfiltration across SIEM, EDR, and log analytics platforms.
  • Data Correlation & Pivoting: Ability to pivot fluidly across multiple data sources — network, endpoint, cloud, and logs — to validate findings, establish timelines, and build a complete adversary narrative.
  • Adversary Emulation: Ability to conduct adversary emulation and basic red team activities to validate detection coverage and ensure detections are correctly tuned and operationally effective.

Incident Response & Forensics

  • Host Forensics: Deep familiarity with major host artifact locations across Windows, Linux, and MacOS, and proficiency with major host forensic toolsets for evidence collection, triage, and analysis.
  • Operating System Internals: Deep understanding of the internal functionality of all major operating systems (Windows, Linux, MacOS). (Preferred: familiarity with less common operating systems such as Cisco IOS, Solaris, and mobile operating systems.)

General Technical Skills

  • Scripting & Automation: Proficiency in at least one scripting language (Python, PowerShell, Bash, Ruby, or Perl) for automating investigative tasks, parsing large datasets, and accelerating hunt and response workflows.
  • Documentation: Ability to capture the results of complex, long-running technical investigations in a manner that is clear, precise, and actionable suitable for both technical peers and executive audiences.
  • Certifications: Network forensics and incident response certifications are strongly preferred, including GCIA (GIAC Certified Intrusion Analyst), GNFA (GIAC Network Forensic Analyst), GCIH, GCFA, or GCED. (Preferred: CISSP for candidates in or approaching leadership tracks.)

Working Conditions

  • This position directly supports essential services of the U.S. Senate. As such, this position requires the employee to be available and prepared to work during a lapse in appropriations, in inclement weather, on holidays, weekends, and during late nights to ensure essential services to the Senate continue without interruption. In the context of government furloughs, this position is considered excepted.
  • The U.S. Senate network cannot be taken offline for maintenance during the workday or while the Senate is in session. As such, maintenance windows may only occur at night, on weekends, and occasionally on holidays. Employees who perform systems upgrades, maintenance, wiring, backups, and support for our alternate data centers will have schedules that include working nights, weekends, and holidays.
  • Sedentary.

Security Clearance

  • This position requires that the applicant obtain and maintain a Secret U.S. Government security clearance.
  • Applicants must be U.S. citizens in order for the SAA to submit your application for a security clearance.

Education

High School Diploma/GED.

Additional information

The Sergeant at Arms is an equal opportunity employer in accordance with the requirements of Senate rules, regulations, and applicable Federal Laws. This agency provides reasonable accommodations to applicants with disabilities. If you need a reasonable accommodation for any part of the application and hiring process, please notify the agency. Decisions to grant reasonable accommodations will be determined on a case-by-case basis. Please email SAARecruitment@saa.senate.gov with “Applicant Accommodation” in the subject line. No moving, relocation or pre-employment travel expenses will be paid for this position, or while in application for this position.

Candidates should be committed to improving the efficiency of the Federal government, passionate about the ideals of our American republic, and committed to upholding the rule of law and the United States Constitution.

A career with the U.S. government provides employees with a comprehensive benefits package. As a federal employee, you and your family will have access to a range of benefits that are designed to make your federal career very rewarding. Opens in a new windowLearn more about federal benefits.

Eligibility for benefits depends on the type of position you hold and whether your position is full-time, part-time or intermittent. Contact the hiring agency for more information on the specific benefits offered.

How you will be evaluated

You will be evaluated for this job based on how well you meet the qualifications above.

Your application will be evaluated by a panel on the quality and extent of your total accomplishments, experience, and education. Highly qualified candidates may be interviewed and a reference check conducted.

Required Documents

  • Your resume should include relevant work experience, applicable education and your contact information. For current or previous federal employees, include the pay plan, series and grade.

Subject to background/security investigation.

If you are relying on your education to meet qualification requirements:

Education must be accredited by an accrediting institution recognized by the U.S. Department of Education in order for it to be credited towards qualifications. Therefore, provide only the attendance and/or degrees from schools accredited by accrediting institutions recognized by the U.S. Department of Education.

Failure to provide all of the required information as stated in this vacancy announcement may result in an ineligible rating or may affect the overall rating.

How to Apply

All applicants must apply for jobs online using this link: https://sen.gov/YO0NL. Paper application materials, resumes and attachments that are sent via email, mail or brought in-person will not be considered or accepted. All applicants MUST attach their documents to the online employment application.

Agency contact information

Email
SAARecruitment@saa.senate.gov
Address
U.S. Senate Sergeant at Arms
US. Senate Capitol Office Building
Washington, DC, Washington, DC 20001

Next steps

Qualified candidates will be contacted directly.

Senate

The Office of the Sergeant at Arms (SAA) is the largest in size of staff and budget in the Senate. It is responsible for all Senate computers and technology support services, recording and photographic services, printing and graphics services, and telecommunications services. The SAA also provides assistance to all Senate offices with their staffing, mailing, purchasing, and financial needs. The offices of the SAA that are responsible for providing these and other services include Capitol Facilities, the Operations Division, Customer Relations, Financial Operations, Human Resources, and Information Security. The SAA also shares responsibility for the U.S. Capitol Police, the Senate Page Program, the Senate Office of Training and Development, and the Capitol Telephone Exchange. The Sergeant at Arms is an excepted service agency. Employment with the Sergeant at Arms does not confer the "Competitive Status" that generally results from selection and service in Competitive Service agencies.

Agency contact information

Email
SAARecruitment@saa.senate.gov
Address
U.S. Senate Sergeant at Arms
US. Senate Capitol Office Building
Washington, DC, Washington, DC 20001