> Markdown version of [/jobs/ext/1314114-lead-cyber-threat-intelligence-analyst](https://www.wearedevelopers.com/jobs/ext/1314114-lead-cyber-threat-intelligence-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Cyber Threat Intelligence Analyst - **Company:** Revolutional, LLC - **Location:** Suitland-Silver Hill, MD, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Computer Telephony Integration, Data Sharing, Open Source Technology, Enterprise Software Applications, Mitre Att&ck, Cyber Threat Analysis, Information Technology, Cybercrime - **Published:** July 17, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=d381c9a877c69534 ## About the Role You bring 7 to 10 years of intelligence experience - with deep grounding in both Threat/Warning Analysis (NICE: AN-TWA-001) and All-Source Analysis (NICE: AN-ASA-001) - and the leadership credibility to run a classified CTI function within a government secure facility. You operate with analytical rigor, produce intelligence that drives decisions, and build a team that does the same., * Bachelor's degree in Intelligence Studies, Political Science, Computer Science, Information Security, or related field (or equivalent experience) * 7 to 10 years of intelligence-related experience with a focus on cyber threat analysis and finished intelligence production * Demonstrated experience in Threat/Warning Analysis (NICE: AN-TWA-001) and All-Source Analysis (NICE: AN-ASA-001) competency areas * Experience leading or managing a CTI team or intelligence production function * Active Top Secret/SCI clearance (Final) required * Must work onsite within a government-controlled secure facility, * Deep experience identifying and assessing real and potential cyber threats to enterprise computing infrastructure using structured analytic tradecraft * Proficiency producing finished all-source intelligence products: threat assessments, warning products, PIR responses, and classified briefings at both strategic and tactical levels * Experience reviewing and managing Prioritized Intelligence Requirements (PIRs) and aligning production efforts to collection priorities * Demonstrated experience disseminating classified cyber threat briefings and reports to senior government and operational audiences * Hands-on experience applying Threat/Warning Analysis tradecraft including Early Indications and Warnings methodologies * Experience integrating classified, open-source, and technical intelligence streams into comprehensive finished products * Familiarity with MITRE ATT&CK and D3FEND frameworks applied to threat actor profiling and analytical product development * Working knowledge of the NICE Cybersecurity Workforce Framework AN-TWA-001 and AN-ASA-001 role definitions and associated training requirements, * Analytically authoritative: your assessments are grounded in evidence, structured in tradecraft, and defensible under peer and leadership review * Senior intelligence leader who sets the production standard, develops analyst capability, and ensures the team's output is consistently mission-quality * Audience-calibrated communicator - your classified briefings land with senior government leadership and your tactical products are equally actionable for SOC operators * Operationally connected: you build CTI products that drive decisions and detection improvements, not just analytical archives Certifications One or more of the following is required or strongly preferred: * GCTI (GIAC Cyber Threat Intelligence), CISM (Certified Information Security Manager), CISSP, CySA+, or equivalent senior intelligence or security credential * Role-based training required per NICE Cybersecurity Workforce Framework AN-TWA-001 and AN-ASA-001 - must be current or completed within required timeframes Nice to Have (Differentiators) * Prior Intelligence Community (IC) experience in a cyber-focused all-source or warning analytical role * Experience managing PIR processes and collection management in a classified federal environment * Background in nation-state adversary tracking, geopolitical threat analysis, or strategic threat assessment * Experience with threat intelligence platforms (TIPs) and structured data sharing frameworks at the classified level * Familiarity with FISMA and NIST SP 800 series as they apply to intelligence-informed risk management * Experience building or maturing a CTI function from early capability to full production maturity ## Description This position leads the Cyber Threat Intelligence function for a federal enterprise cybersecurity program operating within government-controlled secure facilities. The CTI function is the program's strategic intelligence capability - identifying real and potential threats to computing infrastructure, reviewing and responding to Prioritized Intelligence Requirements (PIRs), and disseminating classified threat briefings and reports that drive both operational response and long-range risk management decisions. The core challenge: producing actionable, finished all-source intelligence at the classified level that keeps pace with an evolving threat landscape - and leading a CTI team that delivers that intelligence with analytical rigor, tradecraft discipline, and the speed the mission demands., As Lead Cyber Threat Intelligence Analyst at Revolutional, you are the senior intelligence practitioner and functional lead for the CTI team. You identify potential and real threats to enterprise computing infrastructure, develop risk mitigation strategies, and produce and disseminate classified cyber threat briefings and reports to government leadership and operational teams. You set the analytical standard for the team, own the PIR review process, and ensure every finished product reflects sound tradecraft and current threat awareness., * Lead the Cyber Threat Intelligence function; set analytical standards, manage team workload, and serve as the senior intelligence authority for all CTI products and assessments * Identify potential and real threats to enterprise computing infrastructure across classified and unclassified source streams; assess threat actor intent, capability, and opportunity * Develop and communicate risk mitigation strategies based on current threat intelligence; translate analytical findings into actionable defensive recommendations for security operations and program leadership * Review, manage, and respond to Prioritized Intelligence Requirements (PIRs); ensure the CTI team's collection and production efforts are aligned with the most critical information needs * Produce and disseminate classified cyber threat briefings and reports; deliver finished intelligence to government leadership and operational teams at both strategic and tactical levels * Integrate all-source intelligence - classified, open-source, and technical - into comprehensive threat assessments that reflect the full intelligence picture * Apply Threat/Warning Analysis tradecraft to deliver early indications and warnings of emerging cyber threats, adversary campaigns, and shifts in threat actor behavior * Coordinate with SOC, incident response, and threat hunting teams to ensure CTI products are operationally relevant and drive detection and response improvements * Maintain classified access and handle all intelligence products in accordance with applicable security protocols within government-controlled secure facilities * Ensure CTI team compliance with NICE Cybersecurity Workforce Framework role-based training requirements * Develop and maintain intelligence production standards, product templates, and analytical procedures that ensure consistency and quality across the CTI function ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Smart City, Smart Mobility](https://www.wearedevelopers.com/videos/954-smart-city-smart-mobility) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Building Accountability in Agentic AI](https://www.wearedevelopers.com/videos/100046-building-accountability-in-agentic-ai) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production)