OpenSource Cyber Threat Intelligence Analyst

Peraton

Arlington (VA)

On-site

USD 104,000 - 166,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Peraton is seeking an OpenSource Cyber Threat Intelligence Analyst to join the I&W fusion cell in Northern VA. You will collect OSINT, track APT actors, and fuse findings with technical telemetry to produce high-quality assessments for diverse audiences.

Role involves frequent travel up to two weeks at a time, on-site work, and coordination with IC partners. Requires TS/SCI eligibility and U.S. citizenship.

Qualifications

  • Minimum 9 years experience with a Bachelor's degree (or 7 years with a Master's, 4 with a PhD).
  • Must possess or obtain one of the listed cyber security certifications.
  • Demonstrated TI/APT analysis and threat actor tracking experience.

Responsibilities

  • Serve as OSINT collector and analyst across multiple sources to support I&W mission.
  • Track APT actors, infrastructure, TTPs, and pivot from IOCs to related infrastructure.
  • Identify IOCs and triage using SIEM tools and external leads.
  • Produce written assessments, actor profiles, trend analyses, and briefings.

Skills

APT Analysis
Threat Intelligence
Analytical thinking
Independent work

Education

Bachelor's degree

Tools

SIEMs
Threat intel platforms
MITRE ATT&CK
Cyber Kill Chain
Diamond Model

Job description

OpenSource Cyber Threat Intelligence Analyst

Location: Northern VA. Full-time, on-site role.

Travel: For this role, you must be able to travel up to two weeks at a time, both foreign and domestically.

Description:

The OpenSource Cyber Threat Intelligence Analyst will serve as a dedicated OSINT specialist within the Indications & Warnings (I&W) branch, supporting proactive early warning of cyber threats targeting Department of State personnel, systems, and information assets. This role is ideal for an analyst who excels in opensource investigations, threat actor tracking, and fusing multisource intelligence into highvalue assessments.

In this role, you will:

  • Serve as the primary OSINT collector and analyst for the I&W mission, performing targeted opensource research across surface/deep/dark web environments, social media, threat forums, and global reporting sources.
  • Track advanced persistent threat (APT) actors, their infrastructure, exploitation methods, malware, development, targeting trends, and behavioral signatures using OSINT, vendor, and classified feeds.
  • Conduct pattern, trend, link, and behavioral analysis to identify malicious cyber activity aimed at Department personnel, networks, and mission equities.
  • Maintain structured analytic records and metadata to catalog active campaigns, actor infrastructure changes, and IOCs.
  • Identify and triage Indicators of Compromise (IOCs) using SIEM tools and other security platforms; pivot from IOCs to external opensource leads to identify additional malicious infrastructure.
  • Act as a core participant in I&W's fusion cell, integrating OSINT findings with technical telemetry and intelligence reporting to enhance situational awareness and inform mitigation recommendations.
  • Liaise with Intelligence Community (IC) partners, privatesector researchers, and internal CTAD teams to validate findings and close intelligence gaps.
  • Monitor geopolitical developments, emerging technologies, hacktivist activity, and cybercriminal ecosystems to anticipate cyber threat shifts affecting Department operations.
  • Produce highquality written and verbal assessments, including rapid-turn spot reports, actor profiles, trend analyses, and briefings tailored for both technical and nontechnical audiences.
  • Correlate external threat intelligence with internal events to identify vulnerabilities, preintrusion indicators, and opportunities for proactive defense.
  • Support I&W's mission to provide actionable analysis that informs Department cybersecurity policy, configuration changes, and mitigation actions.
  • Potential to travel to support cyber security briefings and consultations.

#DSCM

Qualifications
  • Bachelors degree and a minimum of 9 years of experience; 7 years with Masters degree; and 4 years with PhD.
    • An additional 4 years of experience may be substituted in lieu of the bachelor's degree requirement.
  • Must either possess and maintain, or obtain prior to start date, one of the following professional certifications:
    • CASP+ CE; CCNP Security; CEH; CFR; CHFI; CISA; CISSP (or Associate); Cloud+; CND; CySA+; GCED; GCIH; GICSP; SSCP
  • Cyber Threat Intelligence & APT Analysis: Demonstrated experience in cyber threat intelligence, including tracking and analyzing Advanced Persistent Threat (APT) actors, adversary operations, tactics, techniques, and procedures (TTPs), and pivoting from indicators of compromise (IOCs) to identify related infrastructure.
  • Threat Intelligence Tools & Methodologies: Experience with SIEMs, threat intelligence and threat detection platforms, and established threat modeling frameworks such as MITRE ATT&CK, Lockheed Martin Cyber Kill Chain, or Diamond Model.
  • Threat Analysis & Incident Support: Experience providing intelligence support before, during, and after cyber incidents, including attribution analysis, adversary profiling, correlating disparate events, conducting post-incident reviews, identifying lessons learned, and improving threat detection capabilities.
  • Cybersecurity & Predictive Analysis: Knowledge of cloud security and threats targeting cloud environments, network protocols and systems, and experience developing predictive models or assessments to anticipate emerging cyber threats and recommend preemptive mitigation measures.
  • Analytical & Communication Skills: Strong analytical, critical thinking, and problem-solving skills with demonstrated ability to work independently and collaboratively. Excellent written communication skills with the ability to convey highly technical information in an analytic format; familiarity with ICD-203 Intelligence Community tradecraft standards and finished intelligence products is desirable.
  • Environment, Clearance & Travel: Experience working in fast-paced classified environments supporting government, military, or Intelligence Community organizations.
  • U.S citizenship required.
  • An active Top Secret security clearance with SCI eligibility.
  • Active U.S. Passport and the ability to travel up to two weeks at a time, both foreign and domestically.
Peraton Overview

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can't be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we're keeping people around the world safe and secure.

Target Salary Range

$104,000 - $166,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual's experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

EEO

EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.

Job Locations

US-VA-Arlington

Requisition ID

2026-170037

Position Category

Intel and Threat Analysis

Clearance

Top Secret/SCI

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Open‑Source Cyber Threat Intelligence Analyst
Open‑Source Cyber Threat Intelligence Analyst

Peraton • Arlington (VA)

On-site
USD 104,000 - 166,000
Cyber Threat Analyst (I&W) with Splunk and Analyst1 / Active Top Secret
Cyber Threat Analyst (I&W) with Splunk and Analyst1 / Active Top Secret

Peraton • Arlington (VA)

On-site
USD 104,000 - 166,000
Cyber Intel Analyst – I&W
Cyber Intel Analyst – I&W

Peraton • Arlington (VA)

On-site
USD 104,000 - 166,000
Intelligence Management Specialist (Executive Support) - Mid
Intelligence Management Specialist (Executive Support) - Mid

Peraton • Fort Meade (MD)

On-site
USD 86,000 - 138,000
Intelligence Analyst
Intelligence Analyst

Peraton • Bethesda (MD)

On-site
USD 112,000 - 179,000
Heavily subsidized employee benefits
25 days of PTO annually
Eligible for bonus plan
External Job Posting Title ICS Threat Hunt Analyst / Active Top Secret
External Job Posting Title ICS Threat Hunt Analyst / Active Top Secret

Peraton • Arlington (VA), Northern (KY)

Hybrid
USD 86,000 - 138,000
ICS Threat Hunt Analyst / Active Top Secret
ICS Threat Hunt Analyst / Active Top Secret

Peraton • Arlington (VA)

On-site
USD 86,000 - 138,000
External Job Posting Title Intelligence Management Specialist (Executive Support) - Mid
External Job Posting Title Intelligence Management Specialist (Executive Support) - Mid

Peraton • Fort Meade (MD), Northern (KY)

On-site
USD 86,000 - 138,000
Counterintelligence (CI) Analyst
Counterintelligence (CI) Analyst

Peraton • Fort Meade (MD)

On-site
USD 112,000 - 179,000
Cyber Threat Analyst
Cyber Threat Analyst

Peraton • Linthicum (MD)

On-site
USD 112,000 - 179,000