> Markdown version of [/jobs/ext/3229844-senior-threat-warning-analyst-with-secret-clearance](https://www.wearedevelopers.com/jobs/ext/3229844-senior-threat-warning-analyst-with-secret-clearance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Threat-Warning Analyst with Secret Clearance - **Company:** CALNET INC - **Location:** Fort Liberty, NC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Computer Telephony Integration, Apache POI, Intrusion Detection Systems, NIPRNet, Open Source Technology, Open Source Intelligence, Security Information and Event Management, Snort (Software), Malware, Cyber Threat Analysis, SC Clearance, Information Technology - **Published:** September 9, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9150903/senior-threat-warning-analyst-with-secret-clearance ## About the Role * Bachelor's Degree in an IT field preferred * U.S Citizenship and Secret Clearance is required. * 5+ years' IT Infrastructure experience ## Description * Conduct open-source research to identify commercial exploits, zero-day vulnerabilities, and adversary TTPs requiring DCO action, and integrate findings into the supported environment's detection capability (host-based security, IPS/IDS, SIEM). * Develop, test, and recommend host-based and network-based signatures (YARA, Snort, Suricata, Elastic detection logic, custom host-based policies) based on identified adversary tradecraft, and coordinate signature submissions with the ARCYBER signature working group portal for global standardization. * Correlate internal sensor data and incident reports against classified and open-source threat reporting to identify campaign patterns and persistent adversary activity, and conduct hypothesis-driven and indicator-based threat hunt missions. * Provide tactical DCO integration support when directed, integrating tactical network sensor events and signature analysis into the supported RCC's DCO processes and enabling tactical units to detect, identify, and respond to threats on their networks. * Develop and maintain a DCO test lab using a Government-approved commercially leased connection (isolated from NIPRNet) for malware analysis and OSINT collection. * Produce and disseminate Threat Intelligence Reports (TIR), Indicator of Compromise (IOC) packages, Request for Information (RFI) responses, and trend analyses; maintain a current intelligence requirements (IR) management process aligned to the supported command's requirements and higher Army echelons. * Document and conduct annual test plans for the CTI signature-development pipeline (or as signatures are developed/updated) and conduct monthly DCO-specific internal training, maintaining a Program of Instruction (POI), attendee list, and After-Action Reports (AAR).