> Markdown version of [/jobs/ext/625508-cyber-intelligence-analyst-iii](https://www.wearedevelopers.com/jobs/ext/625508-cyber-intelligence-analyst-iii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Intelligence Analyst III - **Company:** Revolutional, LLC - **Location:** Chandler, AZ, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software System Penetration Testing, CompTIA Network+, CompTIA Security+, Cyber Security, Data Stores, Data Intelligence, Intrusion Detection and Prevention, Link Analysis, Security Information and Event Management, Software Vulnerability Management, Mitre Att&ck, Cyber Threat Analysis, Information Technology, Cybercrime, Machine Learning Operations - **Published:** June 12, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=8febda39fac37234 ## About the Role Do you have experience in Vulnerability management?, Do you have a Bachelor's degree?, You bring deep experience in the Intelligence Community and know how to work under pressure against tight deadlines. You are fluent in adversary TTPs, proficient with structured analytic frameworks, and capable of briefing findings at both classified and unclassified levels to senior leadership and C-suite audiences. You don't just consume threat intelligence - you operationalize it., * Bachelor's degree in Intelligence Studies, Computer Science, Information Security, or related field (or equivalent experience) * 7 or more years of intelligence-related experience, including hands-on work within the Intelligence Community (IC) * Experience in management or supervision of an IC role, including managing projects and tasks against tight deadlines * Active Top Secret/SCI clearance, * Deep experience with the cyber intelligence lifecycle: collection, analysis, production, and dissemination of finished intelligence * Proficiency with MITRE ATT&CK and D3FEND frameworks applied to threat analysis and defensive recommendations * Experience with the Diamond Model of Intrusion Analysis and cyber intrusion kill-chain concepts and implementation * Hands-on experience with threat intelligence technologies including graphing tools, link analysis platforms, and intelligence management systems * Skill in generating queries and structured reports from intelligence data repositories and SIEM/TIP platforms * Experience enriching monitoring and detection capabilities with cyber threat intelligence data * Ability to conduct technical analysis of enterprise assets using threat intelligence to assess risk and exposure * Experience creating threat matrices to support Security Control Assessment Reporting * Knowledge of vulnerability management, threat hunting, penetration testing, security operations, and incident response processes as they intersect with intelligence functions * Current knowledge of cyber adversary tactics, trends, threat actor IOCs and IOAs, and the evolving federal threat landscape, * Analytically rigorous: you apply structured frameworks consistently and produce findings that hold up under scrutiny * Strong written communicator - your intelligence products are clear, concise, and written for the audience, not the analyst * Confident briefer: able to present classified and unclassified findings to senior leadership and C-suite audiences with authority * Operates effectively under pressure and manages multiple analytical workstreams against competing deadlines without loss of quality Certifications The following certifications are required: Group 1 - Primary (one required) * CISM (Certified Information Security Manager), CySA+ (CompTIA Cybersecurity Analyst), or GCIA (GIAC Certified Intrusion Analyst) Group 2 - Supplemental (one required) * CFR (CyberSec First Responder), CompTIA Network+, CompTIA Security+, or CEH (Certified Ethical Hacker) Nice to Have (Differentiators) * Advanced threat intelligence certifications: GCTI (GIAC Cyber Threat Intelligence), CTIA (Certified Threat Intelligence Analyst), or equivalent * Experience producing all-source intelligence products in a federal civilian or IC environment * Familiarity with classified intelligence sharing frameworks and interagency coordination processes * Background in strategic threat assessment reporting at the enterprise or national level * Experience applying AI/ML tools or automation to threat intelligence analysis workflows #DICE #LinkedIn ## Description As a Cyber Intelligence Analyst III at Revolutional, you turn raw threat data into decision-ready intelligence. You operate across the full cyber intelligence lifecycle - collection, analysis, production, and dissemination - and produce finished intelligence products that shape detection capabilities, inform leadership decisions, and drive strategic security posture across a large-scale federal environment., * Execute the full cyber intelligence lifecycle: collection, processing, analysis, production, and dissemination of finished threat intelligence products * Analyze adversary TTPs using MITRE ATT&CK and D3FEND frameworks; apply the Diamond Model of Intrusion Analysis and kill-chain concepts to structure and communicate findings * Produce high-quality cyber threat intelligence products, white papers, trend reports, and threat matrices to support Security Control Assessment Reporting and strategic decision-making * Brief finished intelligence products to senior leadership and C-suite audiences at both classified and unclassified levels with clarity and credibility * Develop and maintain threat actor profiles, tracking IOCs, IOAs, and evolving adversary TTPs relevant to the federal mission environment * Enrich SOC monitoring and detection capabilities by integrating cyber threat intelligence data into alerting, correlation rules, and detection logic * Leverage threat intelligence technologies including graphing and link analysis tools to identify relationships, patterns, and emerging threat vectors * Generate queries and reports from intelligence platforms and data repositories to support analytical workflows and ad hoc requests * Interpret and fuse data from multiple classified and unclassified sources into comprehensive threat briefings and long-range strategic threat assessments * Conduct technical analysis of enterprise assets using threat intelligence to assess exposure, prioritize risk, and recommend defensive actions * Coordinate with SOC, incident response, vulnerability management, and threat hunting teams to ensure intelligence drives operational outcomes * Manage intelligence tasks and projects against tight deadlines, maintaining quality and analytical rigor under operational tempo ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1520-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Giving the individual control of their data: Open Source Decentralized Web Nodes](https://www.wearedevelopers.com/videos/1100-giving-the-individual-control-of-their-data-open-source-decentralized-web-nodes) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 166: Sycophancy, Zip bombs and AI Native Development](https://www.wearedevelopers.com/magazine/585-dev-digest-166-sycophancy-zip-bombs-and-ai-native-development) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)