Lead Cyber Threat Intelligence Analyst

Revolutional

Suitland (MD)

On-site

USD 130,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical insurance
Dental and vision insurance
401(k) matching
Flexible schedules and teleworking
Paid holidays and PTO

Job summary

Revolutional seeks a Lead Cyber Threat Intelligence Analyst to oversee the CTI function for a federal enterprise cybersecurity program. You will identify threats across classified and unclassified streams, craft risk mitigation guidance, and deliver classified briefings to government leadership and operational teams.

You will set analytical standards, manage a CTI team, and ensure finished products reflect tradecraft rigor.

Qualifications

  • Bachelor’s degree or equivalent experience in a related field.
  • 7–10 years of intelligence experience focusing on cyber threat analysis and finished intelligence production.
  • Experience with Threat/Warning Analysis and All‑Source Analysis competency areas.
  • Experience leading or managing a CTI team or intelligence production function.
  • Active Top Secret/SCI clearance (Final) required.
  • Must work onsite within a government‑controlled secure facility.

Responsibilities

  • Lead the Cyber Threat Intelligence function; set analytical standards and manage team workload.
  • Identify threats to enterprise computing infrastructure across classified and unclassified streams.
  • Develop risk mitigation strategies from current threat intelligence for security operations and leadership.
  • Review PIRs and align production efforts to critical information needs.
  • Produce and disseminate classified cyber threat briefings and reports to government leadership and operators.
  • Integrate classified, open‑source, and technical intelligence into comprehensive threat assessments.

Skills

Threat/Warning Analysis
All‑Source Analysis
Leadership
CTI team management
Active TS/SCI clearance

Education

Bachelor’s degree in Intelligence Studies, Political Science, Computer Science, Information Security, or related field

Tools

MITRE ATT&CK
D3FEND
NICE AN-TWA-001
NICE AN-ASA-001

Job description

Revolutional delivers advanced technology solutions and mission support to federal agencies across civilian, health, and national security environments. We apply modern capabilities, including AI/ML, cloud, cybersecurity, and IT modernization to solve complex challenges, enable faster and more secure operations, and drive measurable mission outcomes.

We are redefining how federal technology gets built and delivered by operating with a product mindset, prioritizing speed, ownership, and execution over bureaucracy.

Lead Cyber Threat Intelligence Analyst

Location: Onsite – Government-controlled secure facility

Terms: Full-time

Salary: $130-$180k DOE

Clearance: Active Top Secret/SCI required

Travel: 0-10%

Project Description

This position leads the Cyber Threat Intelligence function for a federal enterprise cybersecurity program operating within government-controlled secure facilities. The CTI function is the program’s strategic intelligence capability—identifying real and potential threats to computing infrastructure, reviewing and responding to Prioritized Intelligence Requirements (PIRs), and disseminating classified threat briefings and reports that drive both operational response and long‑range risk management decisions.

The core challenge: producing actionable, finished all‑source intelligence at the classified level that keeps pace with an evolving threat landscape—and leading a CTI team that delivers that intelligence with analytical rigor, tradecraft discipline, and the speed the mission demands.

Position Description

As Lead Cyber Threat Intelligence Analyst at Revolutional, you are the senior intelligence practitioner and functional lead for the CTI team. You identify potential and real threats to enterprise computing infrastructure, develop risk mitigation strategies, and produce and disseminate classified cyber threat briefings and reports to government leadership and operational teams.

You set the analytical standard for the team, own the PIR review process, and ensure every finished product reflects sound tradecraft and current threat awareness.

You bring 7 to 10 years of intelligence experience—with deep grounding in both Threat/Warning Analysis (NICE: AN‑TWA‑001) and All‑Source Analysis (NICE: AN‑ASA‑001)—and the leadership credibility to run a classified CTI function within a government secure facility. You operate with analytical rigor, produce intelligence that drives decisions, and build a team that does the same.

Responsibilities
  • Lead the Cyber Threat Intelligence function; set analytical standards, manage team workload, and serve as the senior intelligence authority for all CTI products and assessments
  • Identify potential and real threats to enterprise computing infrastructure across classified and unclassified source streams; assess threat actor intent, capability, and opportunity
  • Develop and communicate risk mitigation strategies based on current threat intelligence; translate analytical findings into actionable defensive recommendations for security operations and program leadership
  • Review, manage, and respond to Prioritized Intelligence Requirements (PIRs); ensure the CTI team’s collection and production efforts are aligned with the most critical information needs
  • Produce and disseminate classified cyber threat briefings and reports; deliver finished intelligence to government leadership and operational teams at both strategic and tactical levels
  • Integrate all‑source intelligence—classified, open‑source, and technical—into comprehensive threat assessments that reflect the full intelligence picture
  • Apply Threat/Warning Analysis tradecraft to deliver early indications and warnings of emerging cyber threats, adversary campaigns, and shifts in threat actor behavior
  • Coordinate with SOC, incident response, and threat hunting teams to ensure CTI products are operationally relevant and drive detection and response improvements
  • Maintain classified access and handle all intelligence products in accordance with applicable security protocols within government-controlled secure facilities
  • Ensure CTI team compliance with NICE Cybersecurity Workforce Framework role‑based training requirements
  • Develop and maintain intelligence production standards, product templates, and analytical procedures that ensure consistency and quality across the CTI function
What You Bring (Requirements)
Baseline Requirements
  • Bachelor’s degree in Intelligence Studies, Political Science, Computer Science, Information Security, or related field (or equivalent experience)
  • 7 to 10 years of intelligence‑related experience with a focus on cyber threat analysis and finished intelligence production
  • Demonstrated experience in Threat/Warning Analysis (NICE: AN‑TWA‑001) and All‑Source Analysis (NICE: AN‑ASA‑001) competency areas
  • Experience leading or managing a CTI team or intelligence production function
  • Active Top Secret/SCI clearance (Final) required
  • Must work onsite within a government‑controlled secure facility
Technical & Domain Capabilities
  • Deep experience identifying and assessing real and potential cyber threats to enterprise computing infrastructure using structured analytic tradecraft
  • Proficiency producing finished all‑source intelligence products: threat assessments, warning products, PIR responses, and classified briefings at both strategic and tactical levels
  • Experience reviewing and managing Prioritized Intelligence Requirements (PIRs) and aligning production efforts to collection priorities
  • Demonstrated experience disseminating classified cyber threat briefings and reports to senior government and operational audiences
  • Hands‑on experience applying Threat/Warning Analysis tradecraft including Early Indications and Warnings methodologies
  • Experience integrating classified, open‑source, and technical intelligence streams into comprehensive finished products
  • Familiarity with MITRE ATT&CK and D3FEND frameworks applied to threat actor profiling and analytical product development
  • Working knowledge of the NICE Cybersecurity Workforce Framework AN‑TWA‑001 and AN‑ASA‑001 role definitions and associated training requirements
Core Strengths
  • Analytically authoritative: your assessments are grounded in evidence, structured in tradecraft, and defensible under peer and leadership review
  • Senior intelligence leader who sets the production standard, develops analyst capability, and ensures the team’s output is consistently mission‑quality
  • Audience‑calibrated communicator—your classified briefings land with senior government leadership and your tactical products are equally actionable for SOC operators
  • Operationally connected: you build CTI products that drive decisions and detection improvements, not just analytical archives
Certifications
  • GCTI (GIAC Cyber Threat Intelligence), CISM (Certified Information Security Manager), CISSP, CySA+, or equivalent senior intelligence or security credential
  • Role‑based training required per NICE Cybersecurity Workforce Framework AN‑TWA‑001 and AN‑ASA‑001—must be current or completed within required timeframes
Nice to Have (Differentiators)
  • Prior Intelligence Community (IC) experience in a cyber‑focused all‑source or warning analytical role
  • Experience managing PIR processes and collection management in a classified federal environment
  • Background in nation‑state adversary tracking, geopolitical threat analysis, or strategic threat assessment
  • Experience with threat intelligence platforms (TIPs) and structured data sharing frameworks at the classified level
  • Familiarity with FISMA and NIST SP 800 series as they apply to intelligence‑informed risk management
  • Experience building or maturing a CTI function from early capability to full production maturity
Benefits
  • Traditional and HSA‑eligible medical insurance plans
  • 100% employer‑paid dental and vision insurance options
  • 100% employer‑sponsored STD, LTD, and life insurance
  • 5% 401(k) company matching
  • Flexible‑schedules and teleworking options
  • Paid holidays and PTO Accrual Plans
  • Paid Parental Leave
  • Professional development and career growth opportunities
  • Team and company‑wide events, recognition, and appreciation—and so much more!

Revolutional is an Equal Opportunity Employer providing equal employment opportunity to all employees and applicants for employment without regard to race, color, religion, national origin, age, gender, gender identity, sexual orientation, disability, or genetics. Revolutional does and will take affirmative action to employ and advance in employment individuals with disabilities and protected veterans. To perform the above job successfully, an individual must possess the knowledge, skills, and abilities listed; meet the education and work experience required; and must be able to perform each essential duty and responsibility satisfactorily. Other duties in addition to those listed may be assigned as necessary to meet business needs. Reasonable accommodation will be made to enable an applicant with a disability to successfully apply for and/or perform the essential duties of the job. If you are in need of an accommodation, please contact HR@revolutional.com.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Intelligence Analyst
Cyber Intelligence Analyst

Harmonia Holdings Group, LLC • Fort Collins (CO)

Hybrid
USD 90,000 - 130,000
Senior Threat Hunter Analyst
Senior Threat Hunter Analyst

Revolutional • Kansas City (MO)

Hybrid
USD 125,000 - 150,000
Medical insurance
Dental insurance
Vision insurance
+3
Senior Threat Hunter
Senior Threat Hunter

Revolutional • Washington

On-site
USD 135,000 - 175,000
Medical insurance
Dental and vision insurance
401(k) matching
+2
Lead Cyber Defense Forensics Analyst
Lead Cyber Defense Forensics Analyst

Revolutional • Suitland (MD)

On-site
USD 110,000 - 150,000
Medical insurance
Dental and vision insurance
STD, LTD, and life insurance
+6
Security Operations Center (SOC) Chief
Security Operations Center (SOC) Chief

Revolutional • Suitland (MD)

On-site
USD 175,000 - 235,000
Medical insurance
Dental insurance
Vision insurance
+6
Technical Support Analyst (Tier II)
Technical Support Analyst (Tier II)

Revolutional • Washington

On-site
USD 75,000 - 95,000
Medical insurance
Dental and vision insurance
STD/LTD and life insurance
+3
Lead Penetration Tester
Lead Penetration Tester

Revolutional • Kansas City (MO)

On-site
USD 110,000 - 150,000
Medical insurance
Dental/vision insurance
STD/LTD/Life insurance
+5
SOC Operations Manager
SOC Operations Manager

Revolutional • Kansas City (MO)

Hybrid
USD 150,000 - 190,000
Medical insurance
Dental & Vision
STD/LTD/Life insurance
+6
Senior Forensic Analyst
Senior Forensic Analyst

Revolutional • Kansas City (MO)

Hybrid
USD 130,000 - 170,000
Flexible schedules
Telework options
Paid holidays & PTO
Program Manager
Program Manager

Revolutional • Kansas City (MO)

Hybrid
USD 165,000 - 220,000
Medical insurance
Dental and vision insurance
401(k) 5% match
+3