Cyber Threat Intelligence III

AV

Germantown (MD)

On-site

USD 75,000 - 114,000

Full time

3 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Medical, dental, vision
401K with company matching
9/80 work schedule
Holiday shutdown

Job summary

AV is seeking a Cyber Threat Intelligence Analyst to identify, analyze, and communicate cyber threats that affect the organization. The role blends traditional threat intelligence with strong technical cybersecurity skills to create actionable intelligence for detections, investigations, vulnerability prioritization, and defensive improvements.

The analyst will work with SOC and security teams to translate findings into secure detections, watchlists, and incident response support in a fast-paced

Qualifications

  • Bachelor-level degree or equivalent experience in cybersecurity or related field.
  • 3+ years in cybersecurity, threat intel, SOC, IR, or threat hunting.
  • Strong understanding of threat intel principles and lifecycle.
  • Hands-on ability to investigate security data beyond reports.
  • Working knowledge of SIEM/XDR, EDR, networks, OS, identity, cloud security.
  • Familiarity with MITRE ATT&CK, TTPs, and attack methods.
  • Ability to analyze indicators like domains, IPs, hashes, URLs, processes.

Responsibilities

  • Monitor and analyze threat intel from multiple sources and produce assessments.
  • Identify threat actors, campaigns, malware, vulnerabilities, and TTPs relevant to the org.
  • Create executive and technical threat reports, alerts, and briefings.
  • Maintain threat actor profiles, IOCs, and intelligence requirements.
  • Translate intelligence into detections and security improvements.
  • Collaborate with SOC to translate intel into detections and controls.
  • Support incident scoping and attribution when appropriate.
  • Develop and execute threat hunting queries using known languages.
  • Keep threat intel platform feeds accurate and integrated with security tech.

Skills

Cyber Threat Intelligence
Threat Analysis
MITRE ATT&CK
SIEM/XDR
Threat Hunting
Executive Communication
Analytical Thinking

Education

Bachelor's degree in Cybersecurity/IT/CS or related field
Equivalent professional experience

Tools

EDR
KQL/XQL/SPL
Incident Response tooling

Job description

Job Description The Cyber Threat Intelligence (CTI) Analyst is responsible for identifying, analyzing, and communicating cyber threats that may impact the organization, its employees, systems, data, and business operations. This role combines traditional threat intelligence analysis with strong technical cybersecurity aptitude to ensure intelligence is actionable and can be translated into detections, investigations, vulnerability prioritization, and defensive security improvements.

Worker Type Regular

Summary The Cyber Threat Intelligence (CTI) Analyst is responsible for identifying, analyzing, and communicating cyber threats that may impact the organization, its employees, systems, data, and business operations. This role combines traditional threat intelligence analysis with strong technical cybersecurity aptitude to ensure intelligence is actionable and can be translated into detections, investigations, vulnerability prioritization, and defensive security improvements.

Position Responsibilities
Cyber Threat Intelligence
  • Monitor and analyze cyber threat intelligence from commercial, government, open-source, and internal sources.
  • Identify emerging threat actors, campaigns, malware, vulnerabilities, tactics, techniques, and procedures (TTPs) relevant to the organization.
  • Develop intelligence assessments covering strategic, operational, and tactical cyber threats.
  • Maintain threat actor profiles, indicators of compromise (IOCs), TTPs, and intelligence requirements.
  • Analyze threats using frameworks such as MITRE ATT&CK and the Cyber Kill Chain.
  • Produce executive-level intelligence reports, technical threat reports, alerts, and briefings.
  • Evaluate the credibility, relevance, and confidence level of intelligence before dissemination.
  • Track threats targeting the organization's industry, technology stack, supply chain, and critical business operations.
Technical Threat Analysis
  • Analyze endpoint, network, identity, cloud, email, and security telemetry to validate threat intelligence.
  • Use SIEM/XDR platforms to investigate IOCs, suspicious activity, and threat actor behaviors.
  • Perform threat hunting based on intelligence-derived hypotheses and known adversary TTPs.
  • Develop and execute searches using technologies such as KQL, XQL, SPL, or similar query languages.
  • Analyze IP addresses, domains, URLs, file hashes, certificates, processes, command lines, and other technical indicators.
  • Understand common Windows, Linux, network, Active Directory/Entra ID, cloud, and endpoint attack techniques.
  • Work with SOC and security engineering teams to translate intelligence into actionable detections and security controls.
  • Assist with developing detection logic, watchlists, blocklists, threat-hunting queries, and alerting rules.
Vulnerability & Exposure Intelligence
  • Monitor emerging vulnerabilities, zero-day vulnerabilities, exploitation activity, and threat actor targeting.
  • Correlate vulnerability intelligence with the organization's technology and asset inventory.
  • Assist vulnerability management teams with risk-based vulnerability prioritization based on active exploitation, threat intelligence, asset criticality, and business impact.
  • Monitor sources such as CISA KEV, vendor advisories, security researchers, and commercial intelligence providers.
  • Evaluate whether newly disclosed vulnerabilities represent an immediate threat to the organization.
Incident Response Support
  • Provide threat intelligence support during cybersecurity incidents.
  • Research suspected threat actors, malware, infrastructure, and attack techniques during active investigations.
  • Enrich security alerts and incidents with relevant threat intelligence.
  • Identify related infrastructure, IOCs, TTPs, and historical activity.
  • Support incident scoping and attribution where appropriate.
  • Document intelligence findings and provide recommendations to incident commanders and security leadership.
Threat Intelligence Platform & Data Management
  • Maintain and improve threat intelligence platforms, feeds, integrations, and intelligence repositories.
  • Evaluate intelligence feeds for accuracy, duplication, relevance, and operational value.
  • Integrate threat intelligence with SIEM, XDR, SOAR, EDR, vulnerability management, and other security platforms.
  • Support automation of IOC ingestion, enrichment, correlation, and response workflows.
  • Continuously improve the organization's intelligence collection requirements and processes.
Basic Qualifications (Required Skills & Experience)
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Intelligence Studies, or a related discipline, or equivalent professional experience.
  • 3+ years of cybersecurity, threat intelligence, SOC, incident response, threat hunting, or related experience.
  • Strong understanding of cyber threat intelligence principles and intelligence lifecycle processes.
  • Strong technical aptitude and ability to investigate security data rather than relying solely on intelligence reports.
  • Working knowledge of SIEM/XDR platforms, EDR technologies, network security, Windows and Linux operating systems, identity and authentication, vulnerability management, and cloud/SaaS security.
  • Understanding of MITRE ATT&CK, adversary TTPs, and common attack methodologies.
  • Ability to analyze technical indicators including domains, IP addresses, hashes, URLs, processes, and network activity.
  • Ability to communicate complex technical threats to both technical teams and executive leadership.
  • Strong analytical, research, documentation, and critical‑thinking skills.
Other Qualifications & Desired Competencies
  • Microsoft Sentinel / Defender XDR
  • Palo Alto Networks
  • Tanium
  • VirusTotal
  • CISA and government intelligence sources
  • Threat intelligence platforms (TIPs)
  • SOAR technologies
  • Vulnerability management platforms

Experience with KQL, XQL, SPL, Python, PowerShell, APIs, JSON, or other scripting/query technologies is highly desirable.

Experience supporting aerospace, defense, manufacturing, government, or other regulated environments is also desirable.

Certifications
  • GIAC Cyber Threat Intelligence (GCTI)
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Forensic Analyst (GCFA)
  • CompTIA CySA+
  • CompTIA Security+
  • CISSP or equivalent cybersecurity certifications
Key Competencies
  • Cyber Threat Intelligence
  • Technical Threat Analysis
  • Threat Hunting
  • Threat Actor & Campaign Analysis
  • MITRE ATT&CK
  • SIEM/XDR Investigation
  • Vulnerability Intelligence
  • IOC/TTP Analysis
  • Incident Response
  • Security Data Analysis
  • Intelligence Reporting
  • Executive Communication
  • Cross‑Functional Collaboration
What Success Looks Like

The successful Cyber Threat Intelligence Analyst does more than distribute threat reports. This individual can determine which threats actually matter to the organization, validate those threats against internal security data, and work with security teams to turn intelligence into measurable defensive action.

The role serves as the bridge between external threat intelligence and internal security operations, helping the organization move from simply knowing about threats to actively detecting, prioritizing, and defending against them.

Physical Demands
  • Ability to work in an office environment (Constant)
  • Required to sit and stand for long periods; talk, hear, and use hands and fingers to operate a computer and telephone keyboard (Frequent)
Clearance Level

No Clearance

The Salary Range For This Role Is

$74,500 - $113,500

ITAR Requirement

This position requires access to information that is subject to compliance with the International Traffic Arms Regulations (“ITAR”) and/or the Export Administration Regulations (“EAR”). In order to comply with the requirements of the ITAR and/or the EAR, applicants must qualify as a U.S. person under the ITAR and the EAR, or a person to be approved for an export license by the governing agency whose technology comes under its jurisdiction. Please understand that any job offer that requires approval of an export license will be conditional on AeroVironment’s determination that it will be able to obtain an export license in a time frame consistent with AeroVironment’s business requirements. A “U.S. person” according to the ITAR definition is a U.S. citizen, U.S. lawful permanent resident (green card holder), or protected individual such as a refugee or asylee. See 22 CFR

  • 120.15. Some positions will require current U.S. Citizenship due to contract requirements.
Benefits

AV offers an excellent benefits package including medical, dental vision, 401K with company matching, a 9/80 work schedule and a paid holiday shutdown. For more information about our company benefit offerings please visit: http://www.avinc.com/myavbenefits.

We also encourage you to review our company website at http://www.avinc.com to learn more about us.

About AV

AV isn’t for everyone. We hire the curious, the relentless, the mission‑obsessed. The best of the best.

We don’t just build defense technology—we redefine what’s possible. As the premier autonomous systems company in the U.S., AV delivers breakthrough capabilities across air, land, sea, space, and cyber. From AI‑powered drones and loitering munitions to integrated autonomy and space resilience, our technologies shape the future of warfare and protect those who serve.

Founded by legendary innovator Dr. Paul MacCready, AV has spent over 50 years pushing the boundaries of what unmanned systems can do. Our heritage includes seven platforms in the Smithsonian—but we’re not building history, we’re building what’s next.

If you’re ready to build technology that matters—with speed, scale, and purpose—there’s no better place to do it than AV.

We are proud to be an EEO/AA Equal Opportunity Employer, including disability/veterans. AeroVironment, Inc. is an Equal Employment Opportunity (EEO) employer and welcomes all qualified applicants. Qualified applicants will receive fair and impartial consideration without regard to race, sex, color, religion, national origin, age, disability, protected veteran status, genetic data, sexual orientation, gender identity or other legally protected status.

ITAR

U.S. Citizenship is required. Secret or Top Secret clearance, or the ability obtain a clearance is desired.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Threat Intelligence III
Cyber Threat Intelligence III

AV • Town of Florida (NY)

On-site
USD 75,000 - 114,000
Medical, dental, vision
401K with company matching
9/80 work schedule
+1
Cyber Threat Intelligence III
Cyber Threat Intelligence III

AV • San Diego (CA)

On-site
USD 75,000 - 114,000
Medical, dental, vision
401K with company match
9/80 work schedule
+1
Cyber Threat Intelligence III
Cyber Threat Intelligence III

AeroVironment, Inc. • Albuquerque (NM)

On-site
USD 75,000 - 114,000
Cybersecurity/Anti-Tamper Engineering Subject Matter Expert
Cybersecurity/Anti-Tamper Engineering Subject Matter Expert

avav • Huntsville (AL)

On-site
USD 155,000 - 247,000
Medical benefits
Dental benefits
401K with company match
+1
IT Specialist
IT Specialist

AV • North Dakota

On-site
USD 75,000 - 114,000
Medical, dental, vision
401K with company matching
9/80 work schedule
Systems Administrator
Systems Administrator

avav • Albuquerque (NM)

On-site
USD 91,000 - 139,000
Software QA Automation Engineer, III
Software QA Automation Engineer, III

AV • Moorpark (CA)

On-site
USD 107,000 - 146,000
Medical, dental, vision benefits
401K with company match
9/80 work schedule
+1
Chief Engineer, Systems
Chief Engineer, Systems

AV • Lawrence (KS)

On-site
USD 155,000 - 247,000
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

AV • Town of Florida (NY)

On-site
USD 91,000 - 139,000
Medical, dental, vision
401(k) with company match
9/80 work schedule
+1
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

AV • Melbourne (FL)

On-site
USD 91,000 - 139,000
Medical benefits
Dental benefits
Vision benefits
+3