> Markdown version of [/jobs/ext/3546808-cyber-fusion-analyst](https://www.wearedevelopers.com/jobs/ext/3546808-cyber-fusion-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber-Fusion Analyst - **Company:** Leidos, Inc. - **Location:** Scott Air Force Base, IL, United States - **Experience:** Experienced - **Salary:** $87,100.0 - $157,450.0 - **Contract:** Permanent contract - **Skills:** Signals Intelligence, Cyber Security, Information Systems, Geospatial Intelligence, Intelligence Analysis, OSI Models, Network Architecture, Network Protocols, Open Source Technology, Open Source Intelligence, Pattern Recognition, Program Analysis, Mitre Att&ck, Malware, Cyber Threat Analysis, SC Clearance, Cybercrime, Cyber Warfare - **Published:** September 30, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9202983/cyber-fusion-analyst ## About the Role * Active Top-Secret clearance * Current DoD 8570 IAT Level II baseline certification (Security+ CE or higher) Strong understanding of: * Network protocols, operating systems, and the OSI model * Security technologies deployed in classified environments * Classified network architectures and security requirements Exceptional written and verbal communication skills, including: * Ability to produce clear, concise intelligence reports and briefings for senior leadership * Experience presenting complex threat information to diverse audiences including flag officers and SES-level officials Advanced analytical skills: * Pattern recognition and anomaly detection in complex, multi-source datasets * Logical reasoning and intelligence-driven analysis * Critical thinking applied to ambiguous threat scenarios * Experience gathering and analyzing intelligence from open-source, commercial, and classified sources * Proven ability to collaborate effectively with Intelligence Community partners and joint cyber teams Highly Desired Qualifications: * 4+ years of experience in cyber threat intelligence analysis, threat hunting, or incident response within classified environments * Experience working with Intelligence Community partners on threat intelligence sharing and fusion initiatives * Hands-on experience with malware analysis tools and techniques (static and dynamic analysis) * Proficiency with Threat Intelligence Platforms (ThreatConnect, Anomali, MISP, or similar) Deep knowledge of intelligence-driven frameworks: * MITRE ATT&CK (Enterprise, ICS, Mobile) * Cyber Kill Chain * Diamond Model of Intrusion Analysis * F3EAD targeting methodology * Experience analyzing nation-state threat actors and Advanced Persistent Threats (APTs) * Understanding of Intelligence Community Directives (ICDs) and intelligence oversight requirements * Familiarity with SIGINT, HUMINT, or GEOINT integration with cyber threat intelligence * Advanced certifications: GCTI, GCIA, GCFA, CISSP, or GIAC ## Description Join the cyber-fusion team defending the nation's classified networks and Top-Secret mission systems. As a Cyber-Fusion Analyst, you'll operate at the intersection of cyber operations and intelligence, providing critical threat intelligence and incident response support to protect DoD, Intelligence Community, and Combatant Command networks at the highest classification levels. Your Mission Classified Threat Intelligence Operations: * Monitor and analyze the global cyber threat landscape using classified Intelligence Community reporting, DoD intelligence products, and open-source intelligence to identify threats targeting TS/SCI networks and mission systems * Synthesize complex, multi-source intelligence into actionable products for senior leadership and operational teams defending classified infrastructure Develop comprehensive threat intelligence products including: * Nation-state and APT threat profiles with classified attribution and capability assessments * Monthly and quarterly intelligence assessments on threats to classified networks * Strategic intelligence reports on adversary campaigns targeting sensitive DoD and IC systems * Leverage classified intelligence sources to provide early warning of threats to Top Secret mission operations Operational Cyber Defense: * Provide real-time threat intelligence support during active incidents on classified networks * Support continuous threat hunting operations to proactively identify adversary presence in TS/SCI environments * Conduct threat and vulnerability analysis specific to classified network architectures and mission systems * Develop security advisories and tactical recommendations for protecting sensitive, compartmented information systems * Disseminate time-sensitive threat intelligence to DISA, mission partners, and Intelligence Community stakeholders through classified channels Intelligence Community Collaboration: * Serve as a liaison between cyber operations and Intelligence Community partners * Participate in classified threat intelligence sharing initiatives and working groups * Contribute to all-source intelligence fusion efforts combining SIGINT, HUMINT, and cyber threat data * Apply advanced analytical frameworks (MITRE ATT&CK for ICS, Cyber Kill Chain, Diamond Model) to classified threat analysis Platform & Capability Development: * Contribute to the development and enhancement of classified Threat Intelligence Platforms * Identify patterns and anomalies in complex, multi-source datasets from classified networks * Develop new analytical methods and intelligence products tailored to TS/SCI mission requirements ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [What Makes Open Source Work: Licensing and Beyond](https://www.wearedevelopers.com/videos/1416-what-makes-open-source-work-licensing-and-beyond) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)