Cleared Threat Hunter & Detection Engineer

Justin McGee

Cleared cybersecurity professional with 7+ years across DoD network operations, ISSO work, and defensive cyber operations. I build practical threat hunting workflows, KQL detections, and analyst-ready security tools mapped to MITRE ATT&CK.

Current focus: Threat hunting workflows, KQL detection logic, local-first analyst tools, and practical AI-assisted security automation.
Proof of work Certifications, shipped tools, project writeups, and practical security operations experience.

Work

Experience timeline

Oct 2025 - Present

CPT Threat Hunter / DCO Analyst

Defense Contractor — DoD Defensive Cyber Operations Environment

Conducts threat hunting and defensive cyber operations analysis, translating adversary activity into detection opportunities and response actions.

Oct 2024 - Jun 2025

Information Systems Security Officer

Umyuaq (Brooke Army Medical Center)

Supported security compliance and risk management for healthcare information systems through controls documentation, coordination, and remediation.

May 2024 - Sep 2024

Cybersecurity Intern

InfoDefense

Built hands-on cybersecurity analysis experience across threat research, vulnerability review, and security documentation.

Oct 2019 - Oct 2024

Senior Network Communications Specialist

U.S. Army NOC

Led network communications operations in NOC environments, maintaining mission-critical connectivity and supporting DoD network operations.

Selected projects

Security Engineering Lab

MITRE ATT&CK Threat Hunting Playbook

A practical reference for SOC analysts and threat hunters.

A defensive playbook integrating KQL queries for Kibana, Sigma rules, and PowerShell tradecraft, mapped to common adversary attack chains and corresponding defensive actions across the MITRE ATT&CK framework. Designed to accelerate detection engineering and incident response workflows.

KQL Kibana Sigma PowerShell MITRE ATT&CK
View details

Statement Parser

AI-powered financial statement analysis.

Application that ingests credit card and bank statements, parses them through the Anthropic Claude API, and outputs spending statistics, visual graphs, frequency analysis, and category breakdowns. Demonstrates secure handling of sensitive data and third-party API integration.

Anthropic Claude API Python Budget AI-assisted development
View details

Credentials

Certifications and training

Verified cybersecurity, cloud, service management, and technical support credentials.

Resume

Resume

One page. Tailored on request.

Preview of Justin McGee resume page 1

Currently

Threat Hunter / DCO Analyst

Defense Contractor — DoD Defensive Cyber Operations Environment

Cleared

TS/SCI

With CI Polygraph

Stack

KQL daily

Python (intermediate), MITRE ATT&CK, AWS SAA-C03

Contact

Professional contact

Available for cybersecurity, automation, and practical AI tooling conversations.