DCOMSS - CTI Lead / Senior Threat-Warning Analyst
EOE Statement
Technology Automation & Management (TeAM), Inc.
TeAM is looking for highly motivated and highly skilled individuals who are ready for exciting opportunities with a growing company. For more than a quarter of a century, we've built our reputation as a premier solutions provider to the Federal Government, and eagerly seek creative problem solvers to join our TeAM.
We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, national origin, disability status, protected veteran status or any other characteristic protected by law.
Description
Pending Contract Award
Mission Objectives – Defensive Cyberspace Operations (DCO) are the passive and active measures taken to detect, characterize, and defeat adversary activity on Army networks and preserve the Army's ability to use its own cyberspace capabilities — a distinct, adversary-focused mission from routine IT infrastructure or help-desk support. This position leads the Cyber Threat Intelligence (CTI) task area of the USARC Defensive Cyberspace Operations Mission Support Services (DCOMSS) effort, informing Blue Team detection priorities, driving assessment scoping, and delivering finished intelligence products to supported commanders, the supported Regional Cyber Center, and ARCYBER. The CTI Lead is one of three Key Personnel positions on this task order.
Position Responsibility Summary
- Serve as Key Personnel and single point of accountability for the CTI pillar, directing persistent collection, aggregation, and analysis of OSINT, commercial threat feeds, ISAC reporting, and Government-Furnished Intelligence.
- Own production and dissemination of finished intelligence products: Threat Intelligence Reports (minimum 4 per month), Indicator of Compromise packages, and Request for Information responses (initial response within 24 hours, substantive response within 5 business days).
- Direct development, testing, and recommendation of host- and network-based detection signatures derived from threat intelligence, coordinating submissions with the ARCYBER signature working group; own the sub-72-hour report-to-sensor development cycle and =10% false-positive threshold.
- Lead adversary tactics, techniques, and procedures analysis mapped to the MITRE ATT&CK framework to inform Blue Team detection priorities and hunt tasking.
- Direct hypothesis-driven and indicator-based threat hunt missions in coordination with the Blue Team Lead.
- Manage the DCO test lab (isolated network) supporting malware analysis and OSINT collection.
- Serve as the CTI interface to the supported command's G2, the supported Regional Cyber Center, and ARCYBER for intelligence requirements management.
- Maintain DCWF 171 (Cyber Threat Intelligence Analyst, Advanced) qualification and oversee CTI team compliance with DoDM 8140.03, including oversight of analysts assigned to SCI/JWICS systems.
Position Requirements
- Minimum 5 years of documented, specialized cyber threat intelligence experience.
- U.S. citizenship.
Certifications and Qualification
- Certifications: Qualification for DCWF 171 (Cyber Threat Intelligence Analyst, Advanced) under DoDM 8140.03. Candidates qualify through one of three recognized pathways: (1) a certification recognized under the current DoD 8140.03 Qualification Matrix for this work role/proficiency — highly desired certifications include GIAC Cyber Threat Intelligence (GCTI), Certified Threat Intelligence Analyst (CTIA), or (ISC)² CISSP; (2) an approved degree plus DoD/commercial training combination; or (3) documented equivalent experience per Component-specific 8140.03 implementation guidance. No single certification is independently mandatory.
- Qualification Verification: TeAM verifies each candidate's qualifying certification, training, or degree/experience combination against the current DoD Cyber Workforce Framework Qualification Matrix at https://public.cyber.mil/wf/dcwf/ at proposal, at hire and throughout performance. Treat the certifications listed above as illustrative screening examples, not an exhaustive or exclusive list — the published matrix governs.
- Years of Experience: 5 years minimum.
TeAM Required Qualification: TeAM's recruiting requirement based on performance risk — not independently Government-mandated
- Demonstrated experience producing finished intelligence products (threat assessments, IOC packages, intelligence reports) for a DoD or Federal customer.
- Experience with MITRE ATT&CK-based adversary TTP analysis and OSINT/commercial threat-feed collection and correlation.
- Experience coordinating detection-signature development from intelligence findings with a Blue Team or SOC function.
- Personal, hands-on threat hunting experience — not solely intelligence production or reporting. Weighted heavily: CTI production combined with technical cyber analysis and threat hunting is valued well above purely strategic/reporting-only experience.
- Education: Bachelor's degree in Intelligence Studies, Cybersecurity, Computer Science, or a related field, or equivalent demonstrated experience in lieu of degree.
Highly Preferred / Discriminator: Improves candidate ranking — does not automatically eliminate
- Prior direct performance on USARC's current legacy NEC-aligned support contract, or on another Army Reserve, ARCYBER, or NETCOM-supported network.
- Currently resides in or near Fayetteville/Fort Bragg, NC, or able to report on-site within a short timeframe of award without relocation lead time.
- Existing TS/SCI clearance in place.
- Prior Army or Joint all-source intelligence fusion experience (DCWF 141).
- Experience supporting a Cyber Security Service Provider – Executor (CSSP-E) under DoDI 8530.01.
- Familiarity with ARCYBER signature working group coordination processes.
- Elastic SIEM detection-logic authoring experience specifically.
- Experience establishing or maintaining a formal Intelligence Requirements (IR) management process.
- All-source analytic experience on JWICS — distinct from JWICS system administration or infrastructure support.
- OCONUS deployment readiness, including current passport and no travel restrictions, to support tactical DCO integration support and conference travel.
Additional Credentials
- Education: Master's degree in Intelligence Studies, Cybersecurity, or a related field.
- Certifications/Training: SANS FOR578 (Cyber Threat Intelligence) training — advanced credential beyond the baseline 8140.03 qualification shown above.
- Other: Existing DoD CAC and Fort Bragg installation access; prior Army Reserve, ARCYBER, or NETCOM-aligned CTI experience.
Duty Location: USARC Headquarters, Fort Bragg, North Carolina (on-site — the default performance posture for this task order)
Work Arrangement: Onsite. Telework is authorized only with prior written COR approval and, when approved, is performed exclusively over Government-furnished equipment via the supported RCC-managed VPN — not a standard work arrangement for this role.
Travel Requirements: CONUS and OCONUS as required, including tactical DCO integration support when directed, and attendance at cybersecurity conferences (e.g., Black Hat, DEF CON, AFCEA) to maintain situational awareness of evolving threats and tradecraft.
Minimum Security Clearance Required: SECRET minimum; TS/SCI eligibility Preferred to support analysis on SCI/JWICS-assigned systems as directed.
Full-Time/Part-Time Full-Time
This position is currently accepting applications.