> Markdown version of [/jobs/ext/2736453-cyber-threat-intelligence-cti-sme-team-lead](https://www.wearedevelopers.com/jobs/ext/2736453-cyber-threat-intelligence-cti-sme-team-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Threat Intelligence (CTI) SME (Team Lead) - **Company:** ECS Limited - **Location:** Arlington, VA, United States (Remote available) - **Experience:** Expert - **Salary:** $165,000.0 - $185,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Computer Telephony Integration, Information Systems Security Architecture Professional, Machine Learning, Mitre Att&ck, Cyber Threat Analysis, Cybercrime - **Published:** September 5, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9146063/cyber-threat-intelligence-cti-sme-team-lead ## About the Role We are seeking an accomplished, dynamic, and hands-on CTI leader with experience managing technical threat intelligence capabilities in a fast-paced environment. The role requires strong technical authority and leadership to establish a unified intake-to-execution workflow that gives stakeholders visibility into intelligence requests, analytics outputs, and service delivery validated against operational needs. Your ability to build high-confidence behavioral fingerprints, map procedure-level actor behaviors to MITRE ATT&CK, and correlate disparate telemetry datasets will be critical to your success., * 10+ years of progressive experience in Cyber Threat Intelligence (CTI), threat hunting, or threat analysis roles, including experience leading technical teams. * Active Top Secret Clearance with SCI eligibility. * Demonstrated expertise tracking priority threat actors (including PRC state-sponsored adversaries), victim-facing infrastructure, relay/proxy networks, and obfuscation setups. * Deep hands-on experience developing high-confidence signatures, fingerprints, and heuristics (e.g., TLS/HTTP behavioral fingerprints, domain/IP clustering). * Technical proficiency mapping adversary behaviors at the procedure level to the MITRE ATT&CK framework and producing clear hunt/detection guidance. * Proven capability correlating diverse external datasets (e.g., internet-wide scans, commercial decoy feeds) with internal telemetry and sensor data to drive high-value hunt leads. * Experience designing and implementing automation-first analytics pipelines, including integrating AI/ML models (e.g., clustering, anomaly detection) with human-in-the-loop validation workflows. * Experience establishing intake-to-execution workflows to align service models, budgets, and request tracking directly with user operational needs. Desired Skills * GIAC Cyber Threat Intelligence (GCTI), Certified Information Systems Security Professional (CISSP), or equivalent technical certifications. * Experience managing DHS or CISA cybersecurity programs (specifically supporting PHB, IRB, EOS, or Unified Persistent Hunt stakeholders). * Expertise in evaluating commercial threat feeds and external context providers (e.g., GreyNoise, residential proxy/TOR context feeds) to deliver signal-to-noise and cost-benefit assessments. * Proven track record of integrating CTI analytics outputs into enterprise target toolsets (e.g., "single pane of glass" dashboards). * In-depth knowledge of evolving threat actor tactics, techniques, and procedures (TTPs) and advanced data-driven correlation methodologies. ## Description ECS is seeking a CTI SME (Team Lead) to lead a specialized cyber threat collection and analytics capability within Threat Branch in support of our National Security client. The scope of the program includes designing, implementing, and operating a tailored collection and analytics framework to convert diverse external datasets into precise, actionable leads for Proactive Threat Hunting (PHB) and Incident Response (IRB) teams. This position is located in Ballston, VA (Arlington) with the option for routine remote work. In this role, you will lead a highly technical team of threat analysts and engineers delivering advanced threat intelligence, tracking priority PRC adversaries, and deploying automation-first analytics pipelines. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Introduction to Azure Machine Learning](https://www.wearedevelopers.com/videos/368-introduction-to-azure-machine-learning) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [What non-automotive Machine Learning projects can learn from automotive Machine Learning projects](https://www.wearedevelopers.com/videos/397-what-non-automotive-machine-learning-projects-can-learn-from-automotive-machine-learning-projects) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems)