> Markdown version of [/jobs/ext/2166996-cybersecurity-operations-analyst-cyber-threat-intelligence-lead](https://www.wearedevelopers.com/jobs/ext/2166996-cybersecurity-operations-analyst-cyber-threat-intelligence-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Operations Analyst & Cyber Threat Intelligence Lead - **Company:** The Aerospace Corporation - **Location:** Colorado Springs, CO, United States (Remote available) - **Experience:** Expert - **Salary:** $107,000.0 - $160,500.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Bash Shell, Cloud Computing Security, Cyber Security, Information Systems, Computer Telephony Integration, Linux, Monitoring of Systems, Intelligence Analysis, Intrusion Detection Systems, Network Packet, Python (Programming Language), Network Security, Log Analysis, Network Protocols, Open Source Intelligence, Windows PowerShell, ArcSight SIEM Tool, Red Team (Cyber Security), Reverse Engineering, Security Information and Event Management, Tcpdump, Traffic Analysis, Wireshark, Snort (Software), Scripting, Google Cloud, Mitre Att&ck, QRadar, Malware, Cyber Threat Analysis, SC Clearance, Information Technology, Cybercrime, Purple Team (Cyber Security), ArcSight Event Correlation, Cyber Warfare - **Published:** August 21, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88095776/1 ## About the Role * Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Intelligence Studies, or equivalent experience * 3-5 years in security operations, threat analysis, incident response, or SOC environments * 3+ years in cyber threat intelligence analysis, production, and program management * Proven experience building or managing a CTI program * Strong background in intelligence analysis methodologies, intelligence cycle (collection, processing, analysis, dissemination) & structured analytic techniques * Experience as Tier 2/3 SOC analyst handling complex security incidents * Experience producing intelligence products for various audiences (technical, operational, executive) and briefing stakeholders * Ability to analyze threat actors, track campaigns, and assess adversary capabilities * Advanced proficiency with SIEM platforms (Google SecOps, QRadar, LogRhythm, ArcSight, or similar) including custom query development * Hands-on experience with threat intelligence platforms (TIP) and OSINT tools * Deep understanding of network protocols, traffic analysis, and advanced attack techniques * Extensive log analysis and event correlation experience * Strong knowledge of Windows/Linux systems, forensic artifacts, and attacker techniques * Expertise with EDR platforms and advanced endpoint analysis * Expert-level understanding of MITRE ATT&CK framework * Experience with threat intelligence frameworks (Diamond Model, Cyber Kill Chain) * Advanced network packet analysis skills (Wireshark, tcpdump) * Ability to analyze malicious scripts, PowerShell commands, and malware behavior * Ability to work under pressure and manage multiple complex investigations * Ability to obtain and maintain US Secret clearance (US citizenship required) Additional Requirements for Information Security Staff IV: * 5-7 years in security operations, threat analysis, incident response, or SOC environments * 5+ years in cyber threat intelligence analysis, production, and program management How You Can Stand Out * Certifications: GCTI, CTIA, GCIA, GCIH, GCFA, GNFA, GMON, CySA+, CISSP, etc. * Prior experience as CTI Lead, Manager, or Program Owner * Government, military, or defense intelligence background with formal training * Experience developing intelligence requirements and collection strategies * Advanced proficiency with ThreatConnect, Anomali, MISP, Recorded Future * OSINT research, dark web monitoring, and underground forum analysis experience * Malware analysis and reverse engineering skills * Published threat intelligence research or conference presentations * Scripting proficiency (Python, PowerShell, Bash) for automation and analysis * Experience with SOAR platforms * Cloud security operations experience (AWS, Azure, GCP) * Experience in classified or high-security environments * Network security monitoring tools experience (Zeek, Suricata, Snort) * Red team/purple team exercise participation * Analyst mentoring and training experience * Knowledge of compliance frameworks (NIST 800-53, 800-171, CMMC) * Familiarity with IC standards (ICD 203, ICD 206) ## Description The Aerospace Corporation is the trusted partner to the nation's space programs, solving the hardest problems and providing unmatched technical expertise. As the operator of a federally funded research and development center (FFRDC), we are broadly engaged across all aspects of space- delivering innovative solutions that span satellite, launch, ground, and cyber systems for defense, civil and commercial customers. When you join our team, you'll be part of a special collection of problem solvers, thought leaders, and innovators. Join us and take your place in space., The Aerospace Corporation seeks an experienced cybersecurity professional to serve as a Tier 2/3 Cyber Operations Analyst and Lead our Cyber Threat Intelligence (CTI) program. You'll handle escalated security events, conduct advanced threat analysis, lead complex investigations, and own all aspects of threat intelligence collection, analysis, production, and dissemination. As a SOC subject matter expert, you'll leverage cutting-edge security tools and deep technical expertise to identify, analyze, and mitigate advanced cyber threats while mentoring junior analysts. Work Model The selected candidate will be required to work full-time, on-site at our facility in Colorado Springs, CO. What You'll Be Doing Cyber Threat Intelligence Program Leadership: * Lead Aerospace's CTI program, establishing strategy, processes, and capabilities * Develop CTI roadmap, define intelligence requirements (PIRs/IRs), and align with organizational risk priorities * Manage relationships with external threat intelligence partners, ISACs/ISAOs, and government agencies * Produce strategic, operational, and tactical intelligence products including threat assessments, adversary profiles, and campaign analysis * Conduct all-source intelligence analysis on threat actors and emerging threats targeting aerospace/defense * Manage threat intelligence platforms (TIP) and establish intelligence workflows * Track and profile APT groups and adversaries relevant to Aerospace's threat landscape * Brief leadership on threat trends, emerging risks, and intelligence-driven recommendations * Establish metrics demonstrating CTI program value and effectiveness Security Operations & Incident Response: * Serve as Tier 2/3 escalation point for complex security alerts and incidents * Conduct deep-dive investigations into sophisticated threats and APTs * Perform advanced threat hunting leveraging intelligence to guide hypotheses * Analyze security alerts from SIEM, IDS, EDR, and other security technologies * Correlate data from multiple sources to reconstruct attack timelines and identify compromise scope * Lead incident response for escalated events, coordinating containment and remediation * Integrate threat intelligence into detection workflows and develop advanced detection rules * Analyze malware, scripts, and attacker tools to understand adversary TTPs * Mentor Tier 1 analysts and develop their analytical skills * Create advanced playbooks, investigation workflows, and technical documentation * Generate detailed technical reports and executive summaries on complex threats * Provide after-hours escalation support for critical incidents as needed ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)