Senior Threat Intelligence Analyst - Incident Response (Day Shift)

Quasars Incorporated
Arlington, VA, United States
3 months ago
Apply on indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Compensation
$155,000.0 - $165,000.0
Working hours
Regular working hours
Job source

Tech stack

CompTIA Security+ Cyber Security Digital Forensics Issue Tracking Systems Open Source Technology Requirements Management Wireshark Software Vulnerability Management Mitre Att&ck Cyber Threat Analysis Information Technology Cybercrime
+5 more
Encase Cyber Warfare Security Orchestration, Automation & Response Servicenow Vulnerability Analysis

Job description

We are seeking a Cyber Threat Intelligence Manager - Incident Response to support the Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) in designing and enhancing an improved incident response system. The ideal candidate will have deep expertise in cybersecurity, threat intelligence, and incident response, with a proven ability to develop and document repeatable SOPs and working instructions. This role plays a critical part in enabling CISA’s cybersecurity reporting and response initiatives, ensuring seamless coordination across the Integrated Operations Division (IOD), Regional Offices (RO), and the Cybersecurity Division (CSD)., Incident Analysis & Enrichment

· Analyze, enrich, and triage cybersecurity incident reports to add contextual detail.

· Identify and assess changing patterns, trends, technologies, Tactics, Techniques, and Procedures (TTPs).

· Correlate reported incidents to known threat campaigns, adversary groups, and vulnerabilities (e.g., zero-day exploits).

Operational & Strategic Support

· Assist in cyber analysis operations, ensuring adherence to CISA’s standard operating procedures, quality control standards, and best practices.

· Support federal employees in analyzing operational environments, identifying new threat activities, and providing key recommendations to IOD leadership and the larger CISA analytic community.

· Collaborate with IOD, RO, and CSD teams (e.g., Threat Hunting, Vulnerability Management, Joint Cyber Defense Collaborative Sub-Divisions) to ensure cohesive incident response and situational awareness.

Process & SOP Development

· Develop and maintain comprehensive Standard Operating Procedures (SOPs) and Working Instructions (WIs) for incident handling and cybersecurity reporting.

· Establish repeatable and effective processes for rapid threat identification, classification, and escalation.

· Conduct regular reviews and audits of existing SOPs and WIs to ensure alignment with evolving threats and organizational priorities.

Threat Intelligence Integration

· Integrate diverse threat intelligence sources (open-source, commercial, and classified) to enrich incident reports and vulnerability assessments.

· Leverage frameworks like MITRE ATT&CK and the NIST Cybersecurity Framework (CSF) to map threat behaviors and strengthen detection and response capabilities.

· Provide operationally relevant analysis of CIRCIA reporting for alignment to CISA priorities.

Communication & Coordination

· Prepare and deliver briefings, reports, and presentations to senior leadership and stakeholders on emerging threats, significant incidents, and recommended mitigation strategies.

· Foster a collaborative environment by sharing relevant threat intelligence and best practices across organizational lines.

· Support outreach efforts to federal, state, local, and private-sector partners to enhance overall cybersecurity posture.

Requirements

Do you have experience in Vulnerability management?, Do you have a Bachelor’s degree?, Experience:

· 10 years of hands-on cybersecurity experience focused on threat analysis, threat intelligence, incident detection, and incident response.

· Demonstrated success in investigating complex cybersecurity incidents and designing solutions for large-scale environments.

· Demonstrated subject matter expertise in providing cyber threat intelligence and cybersecurity analysis to incident response and vulnerability management operations.

· Demonstrated ability to collect, process, analyze, and disseminate descriptive and predictive cybersecurity threat assessments and develop cybersecurity indicators to maintain awareness of the status of the highly dynamic operating environment.

Certifications (at least one):

· Certified Ethical Hacker (CEH)

· Certified Threat Intelligence Analyst (CTIA)

· CompTIA Security+

· GIAC Cyber Threat Intelligence (GCTI) or equivalent, · Bachelor’s Degree in Cybersecurity, Computer Science, Information Technology, or a related field.

Frameworks & Standards:

· Familiarity with MITRE ATT&CK, NIST CSF, and NIST 800-61 (Computer Security Incident Handling Guide).

Technical Skills & Tools:

· Experience with security orchestration, automation, and response (SOAR) platforms.

· Proficiency in network traffic analysis tools (e.g., Wireshark, Zeek) and digital forensics solutions (e.g., EnCase, FTK).

· Familiarity with ServiceNow and similar platform-as-a-service tools used for incident tracking and management.

Preference given to candidates with

· Proven ability to establish, assess efficiency of existing information exchange and management systems, modify, and implement new methods of managing analytic production needs.

· Demonstrated experience and Mitre ATT&CK and other analytic frameworks.

· Knowledge in Information and Production Requirements Management. Demonstrated ability to coordinate with other work units to meet information needs, RFIs, and analytic gaps.

Benefits & conditions

Pulled from the full job description

  • Tuition reimbursement
  • 401(k)
  • Health insurance
  • 401(k) matching
  • Paid time off
  • Vision insurance
  • Dental insurance, · 401(k) with matching

· Dental insurance

· Health insurance

· Vision insurance

· Paid time off

· Tuition reimbursement

Schedule: 40 hours per week. Core hours (Mon-Fri, 9 am - 5 pm ET)

Work Arrangement: 40 hours on-site at Arlington and Washington, DC locations.

Why Join Us?

· Impactful Mission: Contribute to the security and resilience of the nation’s critical infrastructure and key resources by innovating incident response capabilities for DHS CISA.

· Professional Growth: Leverage your expertise in a dynamic environment that values continuous learning, leadership, and initiative.

· Cutting-Edge Environment: Collaborate with experts in cybersecurity, threat intelligence, and national security to shape the future of cyber defense.

If you are passionate about national cybersecurity, excel in threat analysis, and have a desire to shape and improve incident response systems at the federal level, we invite you to apply. Join us and help protect critical infrastructure and citizens by driving cyber resilience at the highest levels.

Job Type: Full-time

Pay: $155,000.00 - $165,000.00 per year, * 401(k)

  • 401(k) matching
  • Dental insurance
  • Health insurance
  • Paid time off
  • Tuition reimbursement
  • Vision insurance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:53 min

Applying software development methodologies to incident response

Tobias Dunn-Krahn · LIVE

56 sec

Integrating automated approval workflows into the portal

Markus Eisele Markus Eisele · World Congress 2025

3:19 min

Setting up a vulnerable test application and monitoring environment

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2024

2:27 min

Establishing a simulated technical environment for the workflow demo

Tobias Dunn-Krahn · LIVE

1:48 min

Analyzing network packets with database protocol tools

Daniël van Eeden Daniël van Eeden · World Congress 2026 Europe

1:37 min

Leveraging continuous intelligence tracking for rapid vulnerability alerting

Matthew Brady Matthew Brady · World Congress 2026 Europe

Videos

See all

Related articles

See all