> Markdown version of [/jobs/ext/2987575-cyber-threat-intelligence-analyst](https://www.wearedevelopers.com/jobs/ext/2987575-cyber-threat-intelligence-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Threat Intelligence Analyst - **Company:** Mantech International Corporation - **Location:** Lorton, VA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Data Analysis, Software System Penetration Testing, Microsoft Azure, C Sharp (Programming Language), Cloud Computing, Cyber Security, Digital Forensics, Python (Programming Language), Regular Expressions, Phishing, Kusto Query Language, Reverse Engineering, SQL Databases, Scripting, Cloud Platform System, Azure Data Factory, Mitre Att&ck, Malware, Cyber Threat Analysis, SC Clearance, Cybercrime - **Published:** September 18, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9169368/cyber-threat-intelligence-analyst ## About the Role * Bachelor's degree and at least 5 years of experience in the areas of Security Operations, Malware analysis, Threat Intelligences, Cyber Incident Response, and / or Penetration Testing. Additional 1 year of experience may be substituted in lieu of a degree. * Current DoD 8570 IAT Level 2 certification or the ability to obtain one within 3 months of starting on contract. * 3+ years of data analysis and scripting experience (SQL, Python, C#, Regex, Azure Data Explorer - KQL, etc.) * Possess the ability to immediately take ownership of the role and operate with minimal guidance. * Experience with the MITRE ATT&CK Framework, the Cyber Kill Chain and/or other tools used for threat intelligence or hunting. * Proficient in research and writing (e.g. SOPs, threat intelligence reports, etc.) * Awareness of modern security related subjects and trends such as threat hunting and modeling, digital forensics, reverse engineering, phishing, and penetration testing., * Experience with Cyber Threat Intelligence in Cloud environments. * CISSP, CISA, CISM, SANS, GCIA, GCIH, MITRE ATT&CK and/or OSCP certifications * Desire to acquire Microsoft SC-200 * Experience with Azure Sentinel, Defender for Cloud and/or Microsoft Defender Threat Intelligence is desired. * Familiarity with Common Vulnerabilities and Exposures (CVE) tracking and remediation. Clearance Requirements: * Must have an current/active Top-Secret Clearance with SCI Eligibility. ## Description The core responsibility of the Cyber Threat Intelligence Analyst is to conduct deep research into social engineering and cyber-attack campaigns and collaborate closely with data scientists, researchers, investigators, engineers, and internal & external partners to counter these threats. This person will own the Cyber Threat Operations Center (CTOC) Threat Intelligence processes and procedures. This role may include the need to work outside of core hours on high priority investigations and may also include on-call responsibilities., * Identify and analyze techniques that are relevant to our protection systems, being proactive to bring awareness to the activity prior to any compromise. * Produce intelligence on the attack landscape that drives actionable protection enhancements into our product, services, and infrastructure. * Prototype new detection methods and experiment with new data sources, tools, and methods for proactively identifying and monitoring attacker campaigns and changes in the attack landscape. * Collaborate effectively and share actionable curated intelligence with internal and external stakeholders to help them drive impact and disruption through their workflows. * Recommend and make appropriate updates to CTOC Threat Intelligence processes, procedures, and tools; publish intelligence on novel social engineering techniques and campaigns. * Mentor others and contribute to an inclusive and collaborative team culture. ## Related Videos - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) - [The AI Security Survival Guide: Practical Advice for Stressed-Out Developers](https://www.wearedevelopers.com/videos/1015-the-ai-security-survival-guide-practical-advice-for-stressed-out-developers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)