> Markdown version of [/jobs/ext/582932-senior-threat-intelligence-analyst-incident-response-day-shift](https://www.wearedevelopers.com/jobs/ext/582932-senior-threat-intelligence-analyst-incident-response-day-shift). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Threat Intelligence Analyst - Incident Response (Day Shift) - **Company:** Quasars Incorporated - **Location:** Arlington, VA, United States - **Experience:** Expert - **Salary:** $155,000.0 - $165,000.0 - **Contract:** Permanent contract - **Skills:** CompTIA Security+, Cyber Security, Digital Forensics, Issue Tracking Systems, Open Source Technology, Requirements Management, Wireshark, Software Vulnerability Management, Mitre Att&ck, Cyber Threat Analysis, Information Technology, Cybercrime, Encase, Cyber Warfare, Security Orchestration, Automation & Response, Servicenow, Vulnerability Analysis - **Published:** June 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=a855638b01b8f93f ## About the Role Do you have experience in Vulnerability management?, Do you have a Bachelor's degree?, Experience: · 10 years of hands-on cybersecurity experience focused on threat analysis, threat intelligence, incident detection, and incident response. · Demonstrated success in investigating complex cybersecurity incidents and designing solutions for large-scale environments. · Demonstrated subject matter expertise in providing cyber threat intelligence and cybersecurity analysis to incident response and vulnerability management operations. · Demonstrated ability to collect, process, analyze, and disseminate descriptive and predictive cybersecurity threat assessments and develop cybersecurity indicators to maintain awareness of the status of the highly dynamic operating environment. Certifications (at least one): · Certified Ethical Hacker (CEH) · Certified Threat Intelligence Analyst (CTIA) · CompTIA Security+ · GIAC Cyber Threat Intelligence (GCTI) or equivalent, · Bachelor's Degree in Cybersecurity, Computer Science, Information Technology, or a related field. Frameworks & Standards: · Familiarity with MITRE ATT&CK, NIST CSF, and NIST 800-61 (Computer Security Incident Handling Guide). Technical Skills & Tools: · Experience with security orchestration, automation, and response (SOAR) platforms. · Proficiency in network traffic analysis tools (e.g., Wireshark, Zeek) and digital forensics solutions (e.g., EnCase, FTK). · Familiarity with ServiceNow and similar platform-as-a-service tools used for incident tracking and management. Preference given to candidates with · Proven ability to establish, assess efficiency of existing information exchange and management systems, modify, and implement new methods of managing analytic production needs. · Demonstrated experience and Mitre ATT&CK and other analytic frameworks. · Knowledge in Information and Production Requirements Management. Demonstrated ability to coordinate with other work units to meet information needs, RFIs, and analytic gaps. ## Description We are seeking a Cyber Threat Intelligence Manager - Incident Response to support the Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) in designing and enhancing an improved incident response system. The ideal candidate will have deep expertise in cybersecurity, threat intelligence, and incident response, with a proven ability to develop and document repeatable SOPs and working instructions. This role plays a critical part in enabling CISA's cybersecurity reporting and response initiatives, ensuring seamless coordination across the Integrated Operations Division (IOD), Regional Offices (RO), and the Cybersecurity Division (CSD)., Incident Analysis & Enrichment · Analyze, enrich, and triage cybersecurity incident reports to add contextual detail. · Identify and assess changing patterns, trends, technologies, Tactics, Techniques, and Procedures (TTPs). · Correlate reported incidents to known threat campaigns, adversary groups, and vulnerabilities (e.g., zero-day exploits). Operational & Strategic Support · Assist in cyber analysis operations, ensuring adherence to CISA's standard operating procedures, quality control standards, and best practices. · Support federal employees in analyzing operational environments, identifying new threat activities, and providing key recommendations to IOD leadership and the larger CISA analytic community. · Collaborate with IOD, RO, and CSD teams (e.g., Threat Hunting, Vulnerability Management, Joint Cyber Defense Collaborative Sub-Divisions) to ensure cohesive incident response and situational awareness. Process & SOP Development · Develop and maintain comprehensive Standard Operating Procedures (SOPs) and Working Instructions (WIs) for incident handling and cybersecurity reporting. · Establish repeatable and effective processes for rapid threat identification, classification, and escalation. · Conduct regular reviews and audits of existing SOPs and WIs to ensure alignment with evolving threats and organizational priorities. Threat Intelligence Integration · Integrate diverse threat intelligence sources (open-source, commercial, and classified) to enrich incident reports and vulnerability assessments. · Leverage frameworks like MITRE ATT&CK and the NIST Cybersecurity Framework (CSF) to map threat behaviors and strengthen detection and response capabilities. · Provide operationally relevant analysis of CIRCIA reporting for alignment to CISA priorities. Communication & Coordination · Prepare and deliver briefings, reports, and presentations to senior leadership and stakeholders on emerging threats, significant incidents, and recommended mitigation strategies. · Foster a collaborative environment by sharing relevant threat intelligence and best practices across organizational lines. · Support outreach efforts to federal, state, local, and private-sector partners to enhance overall cybersecurity posture. ## Related Videos - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [How I saved 200K/yr in direct costs writing 0 code lines in K8s](https://www.wearedevelopers.com/videos/1055-how-i-saved-200k-yr-in-direct-costs-writing-0-code-lines-in-k8s) - [Let’s write an exploit using AI](https://www.wearedevelopers.com/videos/1004-let-s-write-an-exploit-using-ai) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)