Cyber Threat Intelligence Analyst
MANTECH · Lorton, VA · Yesterday
On-siteInformation TechnologyFull-time
About the role
ManTech is seeking a motivated, career and customer-oriented Cyber Threat Intelligence Analyst to join our team in Lorton, VA. The analyst will conduct deep research into social engineering and cyber-attack campaigns and collaborate closely with data scientists, researchers, investigators, engineers, and internal & external partners to counter these threats. This role owns the Cyber Threat Operations Center (CTOC) Threat Intelligence processes and procedures and may require working outside of core hours for high-priority investigations or on-call responsibilities.
Responsibilities
- Identify and analyze techniques relevant to protection systems, proactively raising awareness of potential threats before compromise.
- Produce intelligence on the attack landscape to drive actionable protection enhancements into products, services, and infrastructure.
- Prototype new detection methods and experiment with new data sources, tools, and methods for proactively identifying and monitoring attacker campaigns and changes in the attack landscape.
- Collaborate effectively and share actionable curated intelligence with internal and external stakeholders to drive impact and disruption through their workflows.
- Recommend and update CTOC Threat Intelligence processes, procedures, and tools; publish intelligence on novel social engineering techniques and campaigns.
- Mentor others and contribute to an inclusive and collaborative team culture.
Requirements
- Bachelor’s degree and at least 5 years of experience in Security Operations, Malware Analysis, Threat Intelligence, Cyber Incident Response, and/or Penetration Testing. An additional 1 year of experience may substitute for the degree.
- Current DoD 8570 IAT Level 2 certification or the ability to obtain one within 3 months of starting.
- 3+ years of data analysis and scripting experience (SQL, Python, C#, Regex, Azure Data Explorer – KQL, etc.).
- Ability to immediately take ownership of the role and operate with minimal guidance.
- Experience with the MITRE ATT&CK Framework, the Cyber Kill Chain, or other threat intelligence/hunting tools.
- Proficient in research and writing (e.g., SOPs, threat intelligence reports).
- Awareness of modern security trends such as threat hunting, digital forensics, reverse engineering, phishing, and penetration testing.
- Current/active Top-Secret Clearance with SCI Eligibility.
Preferred Qualifications
- Experience with Cyber Threat Intelligence in Cloud environments.
- CISSP, CISA, CISM, SANS, GCIA, GCIH, MITRE ATT&CK, and/or OSCP certifications.
- Desire to acquire Microsoft SC-200 certification.
- Experience with Azure Sentinel, Defender for Cloud, and/or Microsoft Defender Threat Intelligence.
- Familiarity with Common Vulnerabilities and Exposures (CVE) tracking and remediation.
Physical Requirements
Sedentary work.