Senior Cyber Threat Intelligence Analyst

Socket.dev

Washington (District of Columbia)

On-site

USD 112,000 - 179,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Peraton is seeking a Senior Cyber Threat Intelligence Analyst to provide advanced CTI analysis and production in support of a classified government mission. The role requires translating complex technical findings into decision-ready assessments and developing repeatable processes to improve intelligence delivery.

The ideal candidate will have 12+ years in CTI or related fields, active TS or higher clearance, and demonstrated experience with MITRE ATT&CK, OT/ICS, and threat-hunting workflows.

Qualifications

  • 12+ years of CTI or related experience.
  • Active TS clearance or higher.
  • Experience producing intelligence assessments, threat reports, or other CTI products.

Responsibilities

  • Conduct advanced cyber threat intelligence analysis using classified and open-source data to identify TTPs, vulnerabilities, and emerging threats.
  • Develop, edit, publish, and classify/ downgrade intelligence products per guidance.
  • Author and maintain Hunt Guides and operational intelligence products for OT/ICS and industrial control systems.

Skills

CTI analysis
Intelligence production
Tradecraft development
Stakeholder engagement
SOP development
Pipeline management
MITRE ATT&CK
OT/ICS expertise
Threat hunting

Education

Bachelor's degree in Cybersecurity
MS/MA in related field
PhD

Tools

Cisco security
OT/ICS technologies
Threat intel platforms
SIEM/EDR data

Job description

Responsibilities

Position Overview

The Senior Cyber Threat Intelligence Analyst provides advanced cyber threat intelligence (CTI) analysis, production, tradecraft development, and stakeholder engagement in support of a classified government mission. The analyst is responsible for developing actionable intelligence products, translating complex technical and operational information into decision-ready assessments, and establishing repeatable processes that improve the quality, timeliness, accessibility, and dissemination of intelligence.

The position requires demonstrated expertise in cyber threat analysis, intelligence production, analytic tradecraft, product lifecycle management, and collaboration with government, industry, and mission partners. The successful candidate will operate effectively in classified environments and contribute to initiatives that strengthen collective cyber defense across government and critical-infrastructure stakeholders.

Key Responsibilities

  • Conduct advanced cyber threat intelligence analysis using classified and open-source reporting, technical data, threat reporting, incident information, and other intelligence sources to identify adversary tactics, techniques, procedures (TTPs), vulnerabilities, and emerging threats.
  • Develop, edit, validate, publish, and appropriately classify or downgrade intelligence products in accordance with established classification guidance, dissemination requirements, and mission objectives.
  • Author and maintain technical Hunt Guides and other operational intelligence products addressing enterprise and industrial-control-system technologies, including network infrastructure, security appliances, operational technology (OT), and industrial control systems (ICS).
  • Support the development and dissemination of intelligence products involving technologies such as Cisco security and network operating systems, Schneider Electric systems, SEL systems, and other critical-infrastructure technologies.
  • Identify opportunities to downgrade and broaden the dissemination of intelligence products while maintaining appropriate protection of sensitive information and compliance with classification and handling requirements.
  • Develop and maintain Standard Operating Procedures (SOPs) governing intelligence production, review, quality assurance, dissemination, and lifecycle management.
  • Establish and refine division-wide methodologies for intelligence product development to improve consistency, efficiency, accountability, and analytic quality.
  • Develop and apply analytic tradecraft standards and evaluation criteria to assess intelligence products for analytical rigor, sourcing, clarity, relevance, confidence, and actionable value.
  • Establish and maintain production-management processes and tracking mechanisms that provide real-time visibility into intelligence-product pipelines, milestones, dependencies, and deliverables.
  • Prepare and deliver recurring production-status briefings to senior leadership and cross-functional stakeholders, highlighting progress, priorities, risks, resource constraints, and production bottlenecks.
  • Develop and maintain intelligence dissemination strategies and distribution lists based on mission priorities, consumer requirements, partner relationships, and intelligence value.
  • Support efforts to identify, qualify, and prioritize government, industry, and mission partners to maximize the reach and operational impact of cyber intelligence.
  • Coordinate with government agencies, critical-infrastructure organizations, industry partners, intelligence organizations, and other stakeholders to facilitate timely exchange of actionable cyber threat information.
  • Translate complex technical findings into clear, concise, and actionable intelligence products tailored to technical, operational, and executive audiences.
  • Mentor junior analysts and contribute to the development of team-wide analytic standards, processes, methodologies, and best practices.
  • Identify workflow inefficiencies and recommend process improvements that reduce production delays, improve quality, and increase intelligence dissemination.
  • Track product development through the intelligence lifecycle and proactively identify issues requiring coordination, escalation, or corrective action.
  • Perform all duties in accordance with applicable security, classification, handling, privacy, and information-sharing requirements.
Qualifications

Required Qualifications

  • Bachelor's degree in Cybersecurity, Intelligence Studies, Computer Science, Information Technology, Engineering, or a related field; equivalent professional experience may be considered.
  • 12+ years of relevant experience in cyber threat intelligence, cybersecurity analysis, intelligence operations, cyber defense, or a related discipline; Minimum of 10 years with MS/MA; Minimum of 7 years with Ph.D.
  • Active TS or Q clearance or higher is required. Ability to obtain Q/SCI.
  • Demonstrated experience producing intelligence assessments, threat reports, hunt guides, analytic products, or other operationally focused CTI products.
  • Demonstrated understanding of cyber threat intelligence lifecycle principles, including collection, processing, analysis, production, dissemination, and feedback.
  • Strong knowledge of adversary TTPs, cyber kill chain concepts, MITRE ATT&CK, network security, vulnerability exploitation, malware, intrusion activity, and defensive cyber operations.
  • Experience analyzing threats to operational technology (OT), industrial control systems (ICS), critical infrastructure, or other specialized environments.
  • Demonstrated experience developing SOPs, analytic standards, production methodologies, or other process-improvement frameworks.
  • Experience managing intelligence-product pipelines, production schedules, task tracking, or workflow-management processes.
  • Experience developing intelligence dissemination strategies and tailoring products to different intelligence consumers.
  • Excellent written and verbal communication skills, including the ability to communicate complex technical and intelligence concepts to senior government and mission stakeholders.
  • Ability to work independently, prioritize competing requirements, and operate effectively in a fast-paced mission environment.
  • Ability to collaborate across technical, intelligence, operational, government, and industry organizations.
  • Experience working with classified information and operating within security and information-handling requirements appropriate to the mission.

Preferred Qualifications

  • Master's degree in Cybersecurity, Intelligence Studies, Computer Science, Information Assurance, or a related field.
  • Experience supporting U.S. Government cyber, intelligence, national security, or critical-infrastructure missions.
  • Experience producing intelligence for government-industry information-sharing organizations or fusion centers.
  • Experience with cyber intelligence platforms, SIEM/EDR data, network telemetry, malware analysis, vulnerability intelligence, or threat-hunting workflows.
  • Experience with IC/OT technologies and vendors, including Cisco, Schneider Electric, and Schweitzer Engineering Laboratories (SEL).
  • Familiarity with intelligence community analytic standards and structured analytic techniques.
  • Experience developing or evaluating analytic tradecraft rubrics and quality-assurance programs.
  • Experience creating dashboards, production trackers, workflow-management tools, or automated reporting mechanisms.
  • Relevant professional certifications such as CISSP, GIAC, GCTI, GCIA, GCIH, Security+, CEH, or equivalent.
  • Familiarity with intelligence classification, downgrading, sanitization, declassification, and dissemination processes.
  • Active security clearance appropriate to the contract, with the ability to maintain that clearance.
Peraton Overview

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the worlds leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can't be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we're keeping people around the world safe and secure.

Target Salary Range

$112,000 - $179,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual's experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

EEO

EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cyber Threat Intelligence Analyst
Senior Cyber Threat Intelligence Analyst

Peraton • Washington

On-site
USD 112,000 - 179,000
Medical insurance
Dental insurance
Vision insurance
+3
Senior Cyber Threat Analyst / Public Trust
Senior Cyber Threat Analyst / Public Trust

Peraton • United States

On-site
USD 86,000 - 138,000
All-Source Analyst and Production - Senior
All-Source Analyst and Production - Senior

Peraton • Fort Meade (MD)

On-site
USD 112,000 - 179,000
External Job Posting Title ICS Threat Hunt Analyst / Active Top Secret
External Job Posting Title ICS Threat Hunt Analyst / Active Top Secret

Peraton • Arlington (VA), Northern (KY)

Hybrid
USD 86,000 - 138,000
Senior Threat Hunter
Senior Threat Hunter

Peraton • Chandler (AZ)

On-site
USD 104,000 - 166,000
Intel Analyst
Intel Analyst

Peraton • Washington

On-site
USD 135,000 - 216,000
Open‑Source Cyber Threat Intelligence Analyst
Open‑Source Cyber Threat Intelligence Analyst

Peraton • Arlington (VA)

On-site
USD 104,000 - 166,000
ICS Threat Hunt Analyst / Active Top Secret
ICS Threat Hunt Analyst / Active Top Secret

Peraton • Arlington (VA)

On-site
USD 86,000 - 138,000
Sr Cyber Intelligence Analyst / TS/SCI
Sr Cyber Intelligence Analyst / TS/SCI

Peraton • Chandler (AZ)

On-site
USD 104,000 - 166,000
OpenSource Cyber Threat Intelligence Analyst
OpenSource Cyber Threat Intelligence Analyst

Peraton • Arlington (VA)

On-site
USD 104,000 - 166,000