> Markdown version of [/jobs/ext/2295645-ics-threat-hunt-analyst-active-top-secret](https://www.wearedevelopers.com/jobs/ext/2295645-ics-threat-hunt-analyst-active-top-secret). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # ICS Threat Hunt Analyst / Active Top Secret - **Company:** Peraton Inc - **Location:** Arlington, VA, United States - **Experience:** Experienced - **Salary:** $86,000.0 - $138,000.0 - **Contract:** Permanent contract - **Skills:** Communications Protocols, CompTIA Network+, CompTIA Security+, Cyber Security, Computer Networks, Ethernet, Supervisory Control and Data Acquisition (SCADA), Virtual Private Networks (VPN), Log Analysis, Modbus, Networking Basics, Network Forensics, Routing, Nmap, Open Source Technology, Open Source Intelligence, OPC Unified Architecture, Security Information and Event Management, Systems Architecture, TCP/IP, Wireshark, Mitre Att&ck, Cyber Threat Analysis, Firewalls (Computer Science), Bacnet, Cybercrime, Process Control Systems, Operational Systems, Vulnerability Analysis - **Published:** August 29, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88185634/1 ## About the Role * Bachelor's degree and 2 years of experience, or an Associate's degree and 4 years of relevant experience; or HS and 6+ years in lieu of a bachelors degree. * Demonstrated experience conducting threat hunting, network reconnaissance, or vulnerability assessment in IT or OT environments. * Familiarity with ICS/SCADA systems, protocols (e.g., Modbus, DNP3, BACnet, OPC UA, Ethernet/IP), and their associated security risks. * Hands-on experience with internet-facing asset discovery tools such as Shodan, Censys, or similar platforms for identifying exposed infrastructure. * Experience performing open-source intelligence (OSINT) collection and analysis to support cyber threat assessments. * Understanding of networking fundamentals (TCP/IP, routing, switching, firewalls, VPNs) and how they apply to IT/OT convergence environments. * Experience researching and analyzing cyber threats across either a) multiple industries or b) multiple timeframes, including but not limited to critical infrastructure sectors. * Familiarity with common cyber threat intelligence tools such as DomainTools, VirusTotal, Maltego, exploit-db, etc.. * Experience producing and completing all-source (unclassified and classified) finished intelligence assessments that adhere to ICD203 analytic tradecraft standards. * Proven ability to collaborate and establish key threat intelligence partnerships to bolster information sharing and defenses. * U.S. citizenship required. * An Active Top Secret Security Clearance with SCI eligibility. + Additionally, have the ability to obtain/maintain DHS EOD agency clearance prior to starting Preferred Qualifications: Certifications (any of the following): * SANS GIAC Global Industrial Cyber Security Professional (GICSP) * SANS GIAC Response and Industrial Defense (GRID) * SANS GIAC Cyber Threat Intelligence (GCTI) * SANS GIAC Certified Enterprise Defender (GCED) * SANS GIAC Network Forensic Analyst (GNFA) * SANS GIAC Certified Incident Handler (GCIH) * CompTIA CySA+ * CompTIA Network+ * CompTIA Security+ * Certified Ethical Hacker (CEH) * ISA/IEC 62443 Cybersecurity Certificate Program (ICSCP) * Dragos Platform Certified Analyst * Offensive Security Certified Professional (OSCP) Preferred/Nice-to-Have Skills (not required): * Experience with network traffic analysis tools (e.g., Wireshark, Zeek, NetworkMiner) * Experience with network scanning and enumeration tools (e.g., Nmap, Masscan) * Familiarity with ICS-specific threat intelligence platforms (e.g., Dragos WorldView, Claroty, Nozomi Networks) * Knowledge of NIST SP 800-82 (Guide to ICS Security) and IEC 62443 standards * Experience with SIEM platforms and log analysis in OT environments * Sector-specific experience in Energy, Water/Wastewater, Transportation, or Manufacturing * Understanding of PLC, HMI, RTU, and DCS architectures ## Description Peraton is currently hiring Industrial Control System Cyber Threat Intelligence Analyst for its Federal Strategic Cyber programs., Conduct proactive threat hunting across operational technology (OT) and industrial control system (ICS) environments to identify adversary presence, misconfigurations, and indicators of compromise. * Leverage internet-facing asset discovery and reconnaissance platforms (e.g., Shodan, Censys) to identify exposed ICS/SCADA assets, assess attack surface, and inform threat assessments. * Perform open-source intelligence (OSINT) research and analysis to identify current and emerging threats targeting critical infrastructure sectors. * Analyze network traffic patterns, ICS communication protocols (e.g., Modbus, DNP3, BACnet, OPC UA, Ethernet/IP, S7comm), and system architectures to identify anomalous or malicious activity. * Fuse multiple intelligence sources to develop products, recommendations, and inform priorities for the organization. * Research and investigate current threats in operational technology, specific critical infrastructure sectors, and mission areas to inform senior leaders and drive priorities for operational teams, including forward-deployed incident response and threat hunting functions. * Prepare assessments and cyber threat profiles of current events and trends within ICS/SCADA environments. * Escalate new or high-priority threats to the Cyber Physical Forensics Section as required. * Map ICS threat activity using the MITRE ATT&CK for ICS Framework. * Seamlessly work alongside a team of host, network, and cloud forensic analysts to meet mission requirements for both incident response and threat hunting engagements. * Identify potential open-source vulnerabilities existing within ICS/SCADA systems and assess exploitability in the context of real-world threat actor capabilities. * Identify classified threat intelligence reporting related to ICS/SCADA and analyze for adversary intent and capability. * Contribute to Pre-Deployment Readiness Packages and campaign tracking. * Produce high-quality papers, presentations, recommendations, and findings for senior U.S. government intelligence and operations officials. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [Debunking the Top 10 Myths about Web 3](https://www.wearedevelopers.com/videos/634-debunking-the-top-10-myths-about-web-3) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)