Principal Cyber Def Threat Intell Analyst
About Us
We're powering a cleaner, brighter future. Exelon is leading the energy transformation, and we're calling all problem solvers, innovators, community builders, and change makers. Work with us to deliver solutions that make our diverse cities and communities stronger, healthier, and more resilient. We're a Fortune 200 company with 20,000 colleagues serving more than 10.7 million customers across six energy companies: Atlantic City Electric (ACE), Baltimore Gas and Electric (BGE), Commonwealth Edison (ComEd), Delmarva Power & Light (DPL), PECO Energy Company (PECO), and Potomac Electric Power Company (Pepco).
Our employee experience is grounded in four tenets: purposeful careers, growth opportunities, community impact, and support to thrive. We elevate diverse voices, fresh perspectives, and bold thinking to drive excellence.
About the Role
The Principal Cyber Defense Threat Intelligence Analyst (CDTIA) identifies, collects, and monitors threat intelligence from various sources to analyze, synthesize, and provide actionable intelligence reports and briefings to the joint security operations center (JSOC) and other IT and operational technology (OT) teams. This role collaborates with the Energy Threat Analysis Center (ETAC) under the Department of Energy (DOE) to operationalize cyber and physical threat intelligence in support of defending Exelon’s enterprise and OT assets against Advanced Persistent Threats.
This is a hybrid position requiring in-office presence at least three days per week (Tuesday, Wednesday, and Thursday). The role is open to candidates in Chicago/Oakbrook Terrace, IL; Philadelphia, PA; Newark, DE; Baltimore, MD; or Washington, DC. No relocation is available.
Responsibilities
- Serve as a conduit for investigative exchange, correlating internal company data with partner organizations' detections (50%).
- Develop threat hunting and detection campaigns jointly with partner organizations and apply them within the corporate environment (20%).
- Support end-to-end intelligence efforts through expert analysis and reporting of threat intelligence (10%).
- Support the identification, containment, and eradication of threats of all sophistication levels (10%).
- Recommend short- and long-term adjustments to security controls for immediate and future threat identification, containment, and remediation (5%).
- Provide direction on tuning signatures, rules, alerts, parsers, and custom scripts (5%).
Requirements
- Bachelor’s Degree in Computer Science, Information Systems, or a related 4-year technical degree, or equivalent military/government experience.
- Typically 5 to 8 years of diverse experience in IT, cybersecurity, real-time systems, or a related field.
- Willingness to travel to Golden, Colorado, monthly or as required.
- Willingness to obtain and maintain a US government TS/SCI security clearance.
- Experience in operational technology defense and engineering concepts.
- Proven threat hunting experience and ability to track adversaries using TTPs, MITRE ATT&CK framework, OSINT collection, and deception techniques.
- Proficiency in security tools such as SIEM, IDS/IPS, threat intelligence platforms, and SOAR solutions.
- Experience in incident handling, vulnerability management, hacking tools, intelligence gathering, and kill chain methodology.
- Experience participating in collaborative threat analysis meetings with internal and external entities.
- Ability to analyze incident logs, assess malware, and understand vulnerabilities and exploits, with strong operating systems knowledge.
- Demonstrated understanding of network and host cybersecurity solutions.
- Strong written and verbal communication skills across all organizational levels.
- One or more of the following certifications (or equivalent): GCIA, GCIH, GCTI, GNFA, OSCP.
Preferred Qualifications
- Graduate degree in cybersecurity, intelligence and analysis, or a related field.
- Minimum 3 years of experience supporting the energy sector.
- Experience in a network security environment (e.g., Security Operations Center, Security Incident Response Team).
- Existing US government security clearance with experience handling sensitive classified data.
Pay
Annual salary range: $136,800 – $188,100, with an annual bonus of 20% for eligible positions.
Benefits
- 401(k) match and annual company contribution.
- Medical, dental, and vision insurance.
- Life and disability insurance.
- Generous paid time off, including vacation, sick time, floating and fixed holidays, maternity leave, bonding/primary caregiver leave, and parental leave.
- Employee Assistance Program for mental and emotional support.
- Wellbeing programs, including tuition reimbursement, adoption and surrogacy assistance, and fitness reimbursement.
- Referral bonus program.
Note: Eligibility for Exelon-sponsored compensation and benefits may vary based on length of service, job grade, or classification.
Schedule
Hybrid position requiring in-office presence at least three days per week (Tuesday, Wednesday, and Thursday).