Leidos logo

Cyber Threat Intelligence Analyst

Leidos
  • Washington, District of Columbia
    30+ days ago
    Leidos

    Job Description

    The Leidos Digital Modernization sector is looking for a Cyber Threat Intelligence Analyst to support a Defensive Cyber Operations (DCO) team in Washington, DC. This position is expected to become available in Summer 2026.

    Our team provides mission critical, 24/7 operational support to the customer’s mission of protecting federal networked systems and services from cyber threats impacting national security.  We are looking for a self-starter who is capable of independently performing their daily tasks but also works well within a team that requires significant coordination and communication.

    This hybrid position is primarily on-site, with potential for up to 20% telework.  While this position will primarily work during core hours (0600 – 1600), this position will be supporting a team of analysts working 24/7 rotating shifts (days, swings, nights).  As such, occasional shift work or weekend work may be required to fill unexpected gaps in coverage.

    PRIMARY RESPONSIBILITIES:

    • Produce High-Value Intelligence: Lead the production of strategic, operational, and tactical intelligence reports to inform stakeholders of emerging threats, actor motivations, and potential impacts.
    • Adversary Characterization: Analyze adversary tactics, techniques, and procedures (TTPs) using frameworks like MITRE ATT&CK to develop comprehensive profiles of Advanced Persistent Threats (APTs) relevant to the enterprise.
    • Intelligence Lifecycle Management: Drive the end-to-end intelligence cycle, including developing Priority Intelligence Requirements (PIRs), managing collection plans, and disseminating actionable intelligence to defensive teams.
    • Threat Modeling & Forecasting: Maintain proactive situational awareness by evaluating DoD, IC, and open-source reporting to forecast shifts in the threat landscape and identify systemic vulnerabilities before they are exploited.
    • Indicator Lifecycle Management: Evaluate the fidelity of Indicators of Compromise (IOCs) and Indicators of Behavior (IOBs); manage the ingestion, enrichment, and expiration of threat data within a Threat Intelligence Platform (TIP).
    • Support Hunt & DCO Operations: Provide the intelligence foundation for Hunt missions and Defensive Cyber Operations (DCO) by delivering "Indications & Warnings" and actionable pivot points for internal investigations.
    • Automated Intelligence Integration: Design solutions to automate the delivery of threat data to security controls (SIEM/SOAR/Firewalls) and develop scripts to streamline data collection and correlation.
    • Strategic Advisory: Provide recommendations for executive-level decision-making regarding risk management, security architecture improvements, and intelligence-driven defense strategies.

    BASIC QUALIFICATIONS:

    • Bachelor's Degree with 8+ yrs of experience or Master’s Degree with 6+ yrs of relevant experience; additional years of experience may be substituted in lieu of degrees.
    • DoD 8570 IAT Level II/III: Must hold an IAT Level II or higher certification (or obtain within 180 days). (e.g., CompTIA Security +, CySA+, GSEC and SSCP) or (CASP+ CE, CCNP Security, CISA, GCED, and GCIH)
    • DoD 8570 CSSP Analyst: Must hold a CSSP Analyst certification (or obtain within 180 days). (e.g., CompTIA CySA+, Cloud+, GIAC Global Information Assurance Certification (GCIA))
    • DoD 8570 CSSP Infrastructure Support: Must hold a CSSP Infrastructure Support certification (or obtain within 180 days). (e.g., CompTIA CySA+, Cloud+, EC-Council CEH, CND, CHFI, GIAC GICSP, and ISC2 SSCP)
    • Technical Proficiency: Strong knowledge of networking protocols, computing security elements (IDS/IPS, Firewalls), and experience with data correlation and analysis.
    • Security Clearance:Current DoD TS/SCI security clearance and ability to pass additional customer suitability screenings prior to start and maintain throughout employment.

    PREFERRED SKILLS:

    • Advanced Threat Analysis: Demonstrated expertise in analyzing malware reports, forensic data, and packet captures to extract actionable intelligence.
    • Framework Proficiency: Expert-level understanding of the Cyber Kill Chain and Diamond Model of Intrusion Analysis.
    • Intelligence Platforms: Experience utilizing Threat Intelligence Platforms (TIPs) such as Anomali, ThreatConnect, or MISP.
    • Analytical Writing: Strong ability to translate technical findings into concise, non-technical briefings for senior leadership.
    • Scripting & Querying: Proficiency with Python or PowerShell for data scraping/automation; familiarity with SPL, KQL, or Elastic DSL for querying large datasets.
    • Cloud & Infrastructure: Experience analyzing threats targeting AWS, Azure, O365, and containerized environments.
    • Global Landscape Knowledge: Deep understanding of geopolitical trends and how they influence cyber-adversary activity.

    #ms

    If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.

    Original Posting:

    March 12, 2026

    For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

    Pay Range:

    Pay Range $107,900.00 - $195,050.00

    The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

    Numbers & Facts

    LocationWashington, District of Columbia
    IndustryEngineering Services
    Company Size10,000 employees or more
    Year Founded1969
    Websitehttp://leidos.com/

    About Company

    Everything we do is built on our commitment to do the right thing for our customers, our employees, and our communities. Learn more about the values and culture that are the foundations of our business.

    Skills

    • Amazon Web Services (AWS)unmatched
    • Analysis Skillsunmatched
    • Automationunmatched
    • CCNP - Cisco Certified Network Professionalunmatched
    • CISA - Certified Information Systems Auditorunmatched
    • Cloud Computingunmatched
    • CompTIA - Computing Technology Industry Associationunmatched
    • CompTIA Security+unmatched
    • Computer Network Defense (CND)unmatched
    • Computer Securityunmatched
    • Customer Support/Serviceunmatched
    • DSL (Digital Subscriber Line)unmatched
    • Data Analysisunmatched
    • Data Collectionunmatched
    • Data Setsunmatched
    • Defense Intelligenceunmatched
    • DoD Clearanceunmatched
    • DoD Directive 8140unmatched
    • DoD Directive 8570unmatched
    • EC-Councilunmatched
    • Firewallsunmatched
    • Forecastingunmatched
    • GCIA - GIAC Certified Intrusion Analystunmatched
    • GCIH - GIAC Certified Incident Handlerunmatched
    • GIAC - Global Information Assurance Certificationunmatched
    • GSEC - GIAC Security Essentials Certificationunmatched
    • IAT - Information Assurance Technicalunmatched
    • Information/Data Security (InfoSec)unmatched
    • Integrated Circuits (ICs)unmatched
    • International Information Systems Security Certification Consortium (ISC)2unmatched
    • Internet Securityunmatched
    • Intrusion Detection Systemsunmatched
    • Intrusion Prevention Systemsunmatched
    • Leadershipunmatched
    • Legalunmatched
    • Malware Analysisunmatched
    • Microsoft Windows Azureunmatched
    • Network Protocolsunmatched
    • Network Systemsunmatched
    • Open Sourceunmatched
    • Operational Strategyunmatched
    • Operational Supportunmatched
    • Python Programming/Scripting Languageunmatched
    • Risk Managementunmatched
    • SSCP - Systems Security Certified Practitionerunmatched
    • Scripting (Scripting Languages)unmatched
    • Security Analysisunmatched
    • Security Architectureunmatched
    • Security Attacksunmatched
    • Security Clearanceunmatched
    • Security Information and Event Management (SIEM)unmatched
    • Sensitive Compartmented Information (SCI)unmatched
    • Tactical Operationsunmatched
    • Technical Presentationunmatched
    • Threat Modelingunmatched
    • Top Secret Clearanceunmatched
    • United States Department of Defense (DoD)unmatched
    • Windows PowerShellunmatched
    • Writing Skillsunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder