Cyber Threat Intelligence Analyst

Leidos, Inc.
Washington, DC, United States
28 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Compensation
$107,900.0 - $195,050.0
Working hours
Shift work

Tech stack

Amazon Web Services Microsoft Azure Big Data Cloud Computing CompTIA Security+ Cyber Security Intrusion Detection Systems Python (Programming Language) Open Source Technology Windows PowerShell Kusto Query Language Security Information and Event Management
+8 more
Scripting Office365 Mitre Att&ck Cyber Threat Analysis Firewalls (Computer Science) Containerization Cybercrime Cyber Warfare

Job description

The Leidos Digital Modernization sector is looking for a to support a Defensive Cyber Operations (DCO) team in Washington, DC.

Our team provides mission critical, 24/7 operational support to the customer’s mission of protecting federal networked systems and services from cyber threats impacting national security. We are looking for a self-starter who is capable of independently performing their daily tasks but also works well within a team that requires significant coordination and communication.

While this position will primarily work during core hours (0600 - 1600), this position will be supporting a team of analysts working 24/7 rotating shifts (days, swings, nights). As such,

  • Lead the production of strategic, operational, and tactical intelligence reports to inform stakeholders of emerging threats, actor motivations, and potential impacts.
  • Analyze adversary tactics, techniques, and procedures (TTPs) using frameworks like MITRE ATT&CK to develop comprehensive profiles of Advanced Persistent Threats (APTs) relevant to the enterprise.
  • Drive the end-to-end intelligence cycle, including developing Priority Intelligence Requirements (PIRs), managing collection plans, and disseminating actionable intelligence to defensive teams.
  • Maintain proactive situational awareness by evaluating DoD, IC, and open-source reporting to forecast shifts in the threat landscape and identify systemic vulnerabilities before they are exploited.
  • Evaluate the fidelity of Indicators of Compromise (IOCs) and Indicators of Behavior (IOBs); manage the ingestion, enrichment, and expiration of threat data within a Threat Intelligence Platform (TIP).
  • Provide the intelligence foundation for Hunt missions and Defensive Cyber Operations (DCO) by delivering ā€œIndications & Warningsā€ and actionable pivot points for internal investigations.
  • Design solutions to automate the delivery of threat data to security controls (SIEM/SOAR/Firewalls) and develop scripts to streamline data collection and correlation.
  • Provide recommendations for executive-level decision-making regarding risk management, security architecture improvements, and intelligence-driven defense strategies.

Requirements

  • Bachelor’s Degree with 8+ yrs of experience or Master’s Degree with 6+ yrs of relevant experience; additional years of experience may be substituted in lieu of degrees.
  • Must hold an IAT Level II or higher certification (or obtain within 180 days). (e.g., CompTIA Security +, CySA+, GSEC and SSCP) or (CASP+ CE, CCNP Security, CISA, GCED, and GCIH)
  • Must hold a CSSP Analyst certification (or obtain within 180 days). (e.g., CompTIA CySA+, Cloud+, GIAC Global Information Assurance Certification (GCIA))
  • Must hold a CSSP Infrastructure Support certification (or obtain within 180 days). (e.g., CompTIA CySA+, Cloud+, EC-Council CEH, CND, CHFI, GIAC GICSP, and ISC2 SSCP)
  • Technical Proficiency: Strong knowledge of networking protocols, computing security elements (IDS/IPS, Firewalls), and experience with data correlation and analysis.
  • and ability to passprior to start and maintain throughout employment

  • Advanced Threat Analysis: Demonstrated expertise in analyzing malware reports, forensic data, and packet captures to extract actionable intelligence.
  • Framework Proficiency: Expert-level understanding of the Cyber Kill Chain and Diamond Model of Intrusion Analysis.
  • Intelligence Platforms: Experience utilizing Threat Intelligence Platforms (TIPs) such as Anomali, ThreatConnect, or MISP.
  • Analytical Writing: Strong ability to translate technical findings into concise, non-technical briefings for senior leadership.
  • Scripting & Querying: Proficiency with Python or PowerShell for data scraping/automation; familiarity with SPL, KQL, or Elastic DSL for querying large datasets.
  • Cloud & Infrastructure: Experience analyzing threats targeting AWS, Azure, O365, and containerized environments.
  • Global Landscape Knowledge: Deep understanding of geopolitical trends and how they influence cyber-adversary activity.

ms

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders Ā· LIVE

3:28 min

Defining big data and machine learning fundamentals

Ayon Roy Ā· LIVE

1:23 min

Understanding the complexity of cybersecurity domains

Jennifer Reif Ā· LIVE

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper Ā· Europe 2026 Virtual

2:10 min

Why organizations combine big data and machine learning

Ayon Roy Ā· LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin Ā· WWC 2022

Videos

See all

Related articles

See all