Mid Cyber Threat Intelligence (CTI) Analyst

Everforth Ecs
Arlington, VA, United States
1 day ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$140,000.0 - $160,000.0
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Microsoft Azure Cloud Computing Security Cyber Security Computer Telephony Integration Intelligence Analysis Open Source Technology Open Source Intelligence Phishing Security Information and Event Management Software Vulnerability Management Google Cloud
+5 more
Mitre Att&ck Cyber Threat Analysis Information Technology Cybercrime Cyber Warfare

Job description

Everforth ECS is seeking a Mid Cyber Threat Intelligence (CTI) Analyst to join our team in Arlington, VA (Hybrid) . This position is contingent upon award.

We are seeking a skilled and analytical Mid Cyber Threat Intelligence (CTI) SME to support the organization’s cyber defense program through the collection, analysis, and dissemination of actionable threat intelligence. This role will identify emerging cyber threats, analyze adversary tactics and techniques, and provide intelligence that strengthens threat detection, incident response, and overall security posture.

The ideal candidate combines technical cybersecurity expertise with strong research and analytical skills to translate complex threat information into meaningful insights for both technical and business stakeholders., Threat Intelligence Analysis

  • Collect, analyze, and evaluate cyber threat intelligence from open-source, commercial, and government intelligence sources.
  • Identify and assess emerging cyber threats, vulnerabilities, malware campaigns, and threat actor activities.
  • Develop actionable intelligence reports, threat assessments, and security advisories.
  • Track adversary tactics, techniques, and procedures (TTPs) using frameworks such as MITRE ATT&CK.
  • Support infrastructure tracking efforts related to obfuscation-network discovery, fingerprinting, and clustering.

Security Operations Support

  • Partner with Security Operations Center (SOC) and Incident Response teams to provide threat context and intelligence support.
  • Assist in identifying Indicators of Compromise (IOCs) and Indicators of Attack (IOAs).
  • Support threat hunting initiatives through intelligence-driven analysis.
  • Contribute to the development of detection rules, use cases, and monitoring strategies.

Threat Monitoring & Research

  • Monitor cyber threat trends affecting the organization’s industry and technology landscape.
  • Research threat actor groups, attack campaigns, and emerging cybersecurity risks.
  • Analyze vulnerabilities and assess potential impacts to organizational assets.
  • Support intelligence requirements and collection efforts aligned with business priorities.

Reporting & Communication

  • Produce clear, concise intelligence reports for technical and non-technical audiences.
  • Communicate threat findings and recommendations to cybersecurity teams and management.
  • Participate in intelligence briefings and security reviews.
  • Contribute to dashboards and intelligence metrics reporting.

Program Support

  • Support the maintenance and improvement of cyber threat intelligence processes and methodologies.
  • Assist with intelligence sharing initiatives and external partner engagement.
  • Maintain intelligence repositories and threat documentation.
  • Stay current on industry trends, threat actor activities, and cybersecurity best practices.

Salary Range: $140,000 - $160,000

Requirements

  • Top Secret Clearance
  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Intelligence Studies, or related field, or equivalent experience.
  • 5+ years of cybersecurity experience with at least 2 years supporting Cyber Threat Intelligence functions.
  • Understanding of the cyber threat intelligence lifecycle and intelligence analysis methodologies.
  • Knowledge of common attack techniques, malware types, phishing campaigns, and threat actor behaviors.
  • Familiarity with cybersecurity frameworks including MITRE ATT&CK and Cyber Kill Chain.
  • Experience supporting SOC, Incident Response, Vulnerability Management, or Threat Hunting functions.
  • Strong analytical and critical-thinking skills.
  • Excellent written and verbal communication abilities.

Desired Skills

  • Experience with SIEM, EDR/XDR, and Threat Intelligence Platform (TIP) technologies.
  • Knowledge of cloud security environments such as Azure, AWS, or Google Cloud.
  • Familiarity with infrastructure tracking / obfuscation-network discovery, fingerprinting, and clustering.
  • Familiarity with OSINT, STIX/TAXII, MISP, YARA, and Sigma.
  • Experience developing intelligence reports for operational and leadership stakeholders.
  • Military, intelligence community, government, or critical infrastructure experience.

About the company

Everforth ECS is the federal segment of Everforth , a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies.

Our work powers mission-critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:11 min

Securing heterogeneous legacy payment infrastructure against AI

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

1:23 min

Understanding the complexity of cybersecurity domains

Jennifer Reif · LIVE

Videos

See all

Related articles

See all