Cybersecurity Operations Analyst & Cyber Threat Intelligence Lead

The Aerospace Corporation
Colorado Springs, CO, United States
1 day ago
Apply on jobs.localjobnetwork.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Compensation
$107,000.0 - $160,500.0
Working hours
Regular working hours

Tech stack

Amazon Web Services Microsoft Azure Bash Shell Cloud Computing Security Cyber Security Information Systems Computer Telephony Integration Linux Monitoring of Systems Intelligence Analysis Intrusion Detection Systems Network Packet
+26 more
Python (Programming Language) Network Security Log Analysis Network Protocols Open Source Intelligence Windows PowerShell ArcSight SIEM Tool Red Team (Cyber Security) Reverse Engineering Security Information and Event Management Tcpdump Traffic Analysis Wireshark Snort (Software) Scripting Google Cloud Mitre Att&ck QRadar Malware Cyber Threat Analysis SC Clearance Information Technology Cybercrime Purple Team (Cyber Security) ArcSight Event Correlation Cyber Warfare

Job description

The Aerospace Corporation is the trusted partner to the nation’s space programs, solving the hardest problems and providing unmatched technical expertise. As the operator of a federally funded research and development center (FFRDC), we are broadly engaged across all aspects of space- delivering innovative solutions that span satellite, launch, ground, and cyber systems for defense, civil and commercial customers. When you join our team, you’ll be part of a special collection of problem solvers, thought leaders, and innovators. Join us and take your place in space., The Aerospace Corporation seeks an experienced cybersecurity professional to serve as a Tier 2/3 Cyber Operations Analyst and Lead our Cyber Threat Intelligence (CTI) program. You’ll handle escalated security events, conduct advanced threat analysis, lead complex investigations, and own all aspects of threat intelligence collection, analysis, production, and dissemination. As a SOC subject matter expert, you’ll leverage cutting-edge security tools and deep technical expertise to identify, analyze, and mitigate advanced cyber threats while mentoring junior analysts.

Work Model

The selected candidate will be required to work full-time, on-site at our facility in Colorado Springs, CO.

What You’ll Be Doing

Cyber Threat Intelligence Program Leadership:

  • Lead Aerospace’s CTI program, establishing strategy, processes, and capabilities
  • Develop CTI roadmap, define intelligence requirements (PIRs/IRs), and align with organizational risk priorities
  • Manage relationships with external threat intelligence partners, ISACs/ISAOs, and government agencies
  • Produce strategic, operational, and tactical intelligence products including threat assessments, adversary profiles, and campaign analysis
  • Conduct all-source intelligence analysis on threat actors and emerging threats targeting aerospace/defense
  • Manage threat intelligence platforms (TIP) and establish intelligence workflows
  • Track and profile APT groups and adversaries relevant to Aerospace’s threat landscape
  • Brief leadership on threat trends, emerging risks, and intelligence-driven recommendations
  • Establish metrics demonstrating CTI program value and effectiveness

Security Operations & Incident Response:

  • Serve as Tier 2/3 escalation point for complex security alerts and incidents
  • Conduct deep-dive investigations into sophisticated threats and APTs
  • Perform advanced threat hunting leveraging intelligence to guide hypotheses
  • Analyze security alerts from SIEM, IDS, EDR, and other security technologies
  • Correlate data from multiple sources to reconstruct attack timelines and identify compromise scope
  • Lead incident response for escalated events, coordinating containment and remediation
  • Integrate threat intelligence into detection workflows and develop advanced detection rules
  • Analyze malware, scripts, and attacker tools to understand adversary TTPs
  • Mentor Tier 1 analysts and develop their analytical skills
  • Create advanced playbooks, investigation workflows, and technical documentation
  • Generate detailed technical reports and executive summaries on complex threats
  • Provide after-hours escalation support for critical incidents as needed

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Intelligence Studies, or equivalent experience
  • 3-5 years in security operations, threat analysis, incident response, or SOC environments
  • 3+ years in cyber threat intelligence analysis, production, and program management
  • Proven experience building or managing a CTI program
  • Strong background in intelligence analysis methodologies, intelligence cycle (collection, processing, analysis, dissemination) & structured analytic techniques
  • Experience as Tier 2/3 SOC analyst handling complex security incidents
  • Experience producing intelligence products for various audiences (technical, operational, executive) and briefing stakeholders
  • Ability to analyze threat actors, track campaigns, and assess adversary capabilities
  • Advanced proficiency with SIEM platforms (Google SecOps, QRadar, LogRhythm, ArcSight, or similar) including custom query development
  • Hands-on experience with threat intelligence platforms (TIP) and OSINT tools
  • Deep understanding of network protocols, traffic analysis, and advanced attack techniques
  • Extensive log analysis and event correlation experience
  • Strong knowledge of Windows/Linux systems, forensic artifacts, and attacker techniques
  • Expertise with EDR platforms and advanced endpoint analysis
  • Expert-level understanding of MITRE ATT&CK framework
  • Experience with threat intelligence frameworks (Diamond Model, Cyber Kill Chain)
  • Advanced network packet analysis skills (Wireshark, tcpdump)
  • Ability to analyze malicious scripts, PowerShell commands, and malware behavior
  • Ability to work under pressure and manage multiple complex investigations
  • Ability to obtain and maintain US Secret clearance (US citizenship required)

Additional Requirements for Information Security Staff IV:

  • 5-7 years in security operations, threat analysis, incident response, or SOC environments
  • 5+ years in cyber threat intelligence analysis, production, and program management

How You Can Stand Out

  • Certifications: GCTI, CTIA, GCIA, GCIH, GCFA, GNFA, GMON, CySA+, CISSP, etc.
  • Prior experience as CTI Lead, Manager, or Program Owner
  • Government, military, or defense intelligence background with formal training
  • Experience developing intelligence requirements and collection strategies
  • Advanced proficiency with ThreatConnect, Anomali, MISP, Recorded Future
  • OSINT research, dark web monitoring, and underground forum analysis experience
  • Malware analysis and reverse engineering skills
  • Published threat intelligence research or conference presentations
  • Scripting proficiency (Python, PowerShell, Bash) for automation and analysis
  • Experience with SOAR platforms
  • Cloud security operations experience (AWS, Azure, GCP)
  • Experience in classified or high-security environments
  • Network security monitoring tools experience (Zeek, Suricata, Snort)
  • Red team/purple team exercise participation
  • Analyst mentoring and training experience
  • Knowledge of compliance frameworks (NIST 800-53, 800-171, CMMC)
  • Familiarity with IC standards (ICD 203, ICD 206)

Benefits & conditions

We offer a competitive compensation package where you’ll be rewarded based on your performance and recognized for the value you bring to our business. The grade-based pay range for this job is listed below. Individual salaries within that range are determined through a wide variety of factors including but not limited to education, experience, knowledge and skills.

(Min - Max) $107,000.00 - $160,500.00

Pay Basis: Annual

Leadership Competencies

Our leadership philosophy is simple: every employee, regardless of level and role, can demonstrate leadership. At Aerospace, our commitment is our people. To cultivate our talent and ensure that we have a strong pipeline of future leaders, we want individuals who:

  • Operate Strategically
  • Lead Change
  • Engage with Impact
  • Foster Innovation
  • Deliver Results

Ways We Reward Our Employees

During your interview process, our team will provide details of our industry-leading benefits.

Benefits vary and are applicable based on Job Type. A few highlights include:

  • Comprehensive health care and wellness plans
  • Paid holidays, sick time, and vacation
  • Standard and alternate work schedules, including telework options
  • 401(k) Plan - Employees receive a total company-paid benefit of 8%, 10%, or 12% of eligible compensation based on years of service and matching contributions; employees are immediately eligible and vested in the plan upon hire
  • Flexible spending accounts
  • Variable pay program for exceptional contributions
  • Relocation assistance
  • Professional growth and development programs to help advance your career
  • Education assistance programs
  • An inclusive work environment built on teamwork, flexibility, and respect

About the company

We are all unique, from various backgrounds and all walks of life, yet one thing bonds all of us to each other-the belief that we can make a difference. This core belief empowers us to do our best work at The Aerospace Corporation.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.localjobnetwork.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Introduction to eBPF as a secure virtual machine

Ayesha Kaleem · World Congress 2023

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

1:23 min

Understanding the complexity of cybersecurity domains

Jennifer Reif · LIVE

8:22 min

Simulating a Linux terminal and running Spring Boot

Jakov Semenski · LIVE

Videos

See all

Related articles

See all