DTIP Integrations SME

Leidos Inc

Whitehall (OH)

Hybrid

USD 87,000 - 157,000

Full time

6 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Leidos' Digital Modernization sector is seeking a Threat Intelligence Platform Integrations SME to act as mission owner for our CTI fusion and blocking capabilities. The role supports sustained platform integration across DISA solutions and DoWIN, with a focus on actionable threat intelligence analysis.

The position requires a TS/SCI clearance, a related bachelor's degree with 4+ years of experience, and hands-on work with TIPs, threat feeds, and security integrations such as CBII, Palo Alto,

Qualifications

  • Active TS/SCI clearance is required.
  • Bachelor's degree in a related discipline plus 4+ years of directly relevant experience; additional related years accepted in lieu of a degree.
  • 2+ years of experience with Threat Intelligence Platforms (TIPs) and configuring threat feed integrations.
  • Proficiency in Python programming.
  • Experience editing configurations with JSON and YAML.
  • Experience with version control systems such as Git.
  • Applied knowledge of security solutions and their integrations in enterprise environments (CBII, Palo Alto, ERS, Versa).
  • 8140 Cyber Defense Infrastructure Support Specialist 521 (CS) intermediate-level compliance with one of Security+, PenTest+, CySA+, GSEC, or GMON.

Responsibilities

  • Act as the mission owner for sustained Threat Intelligence Platform support.
  • Drive CTI fusion, low-regret model scoring, and integration of blocking capabilities.
  • Integrate threat feeds across DISA capabilities (CBII, Palo Alto, ERS, Versa).
  • Integrate block lists to support automated defensive solutions (Bladeguard).
  • Fuse multiple intelligence sources to develop comprehensive threat products and recommendations.
  • Research threats and map adversary activity using MITRE ATT&CK framework.
  • Produce papers and briefings for senior U.S. government officials.
  • Support IOC management, blocking, and troubleshooting for government and CSWOs.

Skills

Python
JSON
YAML
Git
TIPs
CTI fusion

Education

Bachelor's degree in related discipline

Tools

CBII
Palo Alto
ERS
Versa
Bladeguard

Job description

Description

Leidos' Digital Modernization sector has a current job opportunity for a Threat Intelligence Platform Integrations SME. We are seeking an experienced Cyber Threat Intelligence (CTI) professional to act as a mission owner for our Threat Intelligence Platform. As a Threat Intelligence Platform Integrations SME at DISA Global, you will provide sustained support for CTI fusion, low-regret model scoring, and the implementation of blocking actions to create advanced defensive capabilities. You will play a critical role in maintaining this capability, optimizing its performance, and integrating it across various DISA security solutions to enhance the overall defense of the Department of War Information Network (DoWIN).

You will use your technical expertise to enable the fusion of intelligence, inform threat investigations, and drive automated defense mechanisms. Additionally, you will continue to strengthen your skills while supporting the sustainment and development of critical platforms in support of the DoW and COCOMs.

This position can be based out of any of our three core sites - Scott AFB, IL; Hill AFB, UT; or Columbus, OH. Partial/hybrid telework may be allowed, but a consistent on-site presence is required.

PRIMARY RESPONSIBILITIES
  • Act as the mission owner for sustained Threat Intelligence Platform support, driving CTI fusion, low-regret model scoring, and the integration of blocking capabilities.
  • Maintain and enhance capability performance by integrating threat feeds across various DISA capabilities, including Cloud Based Internet Isolation (CBII), Palo Alto, Enterprise Recursive Services (ERS), and Versa.
  • Integrate block lists to support automated defensive solutions, specifically leveraging the Bladeguard solution.
  • Fuse multiple intelligence sources to develop comprehensive products, provide strategic recommendations, and prioritize organizational focus.
  • Research and investigate current threats; map adversary activities using the MITRE ATT&CK Framework.
  • Analyze data and threat intelligence reports to evaluate adversary capabilities, intentions, tactics, and behaviors.
  • Produce high-quality papers, presentations, and recommendations for senior U.S. government intelligence and operations officials.
  • Support government and CSWOs in the areas of IOC management, blocking, and overall troubleshooting
BASIC QUALIFICATIONS
  • Must have an active TS/SCI due to classified intelligence analysis.
  • Bachelor's degree in a related discipline and 4+ years of directly relevant experience; additional related years of experience is accepted in lieu of a degree.
  • 2+ years of experienceworking with Threat Intelligence Platforms (TIPs) and configuring threat feed integrations.
  • Proficiency in programming usingPython.
  • Proven experience with configuration editing using bothJSON and YAML.
  • Experience with leveraging version control systems such asGit.
  • Applied knowledge of various security solutions and their integrations as employed in enterprise environments, specifically CBII, Palo Alto, ERS, and Versa.
  • Requires 8140 Cyber Defense Infrastructure Support Specialist 521 (CS) Intermediate-level compliance, to include one of the following certifications: Security+, PenTest+, CySA+, GSEC, or GMON.
PREFERRED SKILLS
  • Deep understanding of defensive tactics, techniques, and procedures (TTPs) for threat detection and response.
  • Experience with automated block list integrations and solutions.
  • Experience with integration of systems as well as assessing, scoring, and operationalizing new CTI feeds
  • Knowledge utilizing STIX and TAXII standards to develop, configure, and automate threat intelligence solutions across enterprise security platforms
  • Experience with Integrated Adaptive Cyber Defense: \"Low-Regret\" Methodology for CTI Triage
  • Advanced experience assessing emerging threats and vulnerabilities and the CTI lifecycle.
  • Skills building and reading data dictionaries
  • Exceptional written and verbal communication skills tailored for senior intelligence and operational leadership.
  • Prior experience functioning as a capability or mission owner within a DoW or Intelligence Community environment.

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares.

Pay and Benefits

Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits.

About Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com.

Pay Range $87,100.00 - $157,450.00

The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Commitment to Non-Discrimination

All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

DTIP Integrations SME
DTIP Integrations SME

Leidos • Whitehall (OH)

On-site
USD 87,000 - 157,000
DTIP Integrations SME
DTIP Integrations SME

Leidos LLC • Whitehall (OH)

Hybrid
USD 87,000 - 157,000
DTIP Integrations SME
DTIP Integrations SME

Via Logic LLC • Whitehall (OH)

On-site
USD 87,000 - 157,000
Cyber Intelligence Fusion Analyst
Cyber Intelligence Fusion Analyst

Leidos Inc • Alexandria (VA)

On-site
USD 108,000 - 195,000
Staff Cyber Security Engineer
Staff Cyber Security Engineer

Leidos • Bethesda (MD)

Hybrid
USD 108,000 - 195,000
11 paid holidays
401(k) with 6% match
Paid Time Off
Staff Cyber Security Engineer
Staff Cyber Security Engineer

Leidos Inc • Bethesda (MD)

On-site
USD 108,000 - 195,000
Paid Time Off
11 paid holidays
401K with 6% match
Cyber Intel Analyst
Cyber Intel Analyst

Via Logic LLC • Washington

On-site
USD 87,000 - 157,000
Health and Wellness programs
Competitive compensation
Paid Leave
+1
Cyber Intelligence Fusion Analyst
Cyber Intelligence Fusion Analyst

Leidos • Alexandria (VA)

On-site
USD 108,000 - 195,000
Tier 3 Cyber Threat Intelligence Analyst
Tier 3 Cyber Threat Intelligence Analyst

Leidos Inc • Washington

On-site
USD 120,000 - 180,000
Tier 3 Cyber Threat Intelligence Analyst
Tier 3 Cyber Threat Intelligence Analyst

Leidos Inc • Mississippi

On-site
USD 120,000 - 160,000