Jobs · Information Technology · Illinois

Principal Cyber Def Threat Intell Analyst

Exelon · Villa Park, IL · 6 days ago
HybridInformation Technology$137k/yrFull-time

About Us

We're powering a cleaner, brighter future. Exelon is leading the energy transformation, and we're calling all problem solvers, innovators, community builders and change makers. Work with us to deliver solutions that make our diverse cities and communities stronger, healthier and more resilient. We're a Fortune 200 company with 20,000 colleagues serving more than 10.7 million customers at six energy companies: Atlantic City Electric (ACE), Baltimore Gas and Electric (BGE), Commonwealth Edison (ComEd), Delmarva Power & Light (DPL), PECO Energy Company (PECO), and Potomac Electric Power Company (Pepco).

Our employee experience is grounded in four tenets: purposeful careers, growth opportunities, community impact, and support to thrive. We elevate diverse voices, fresh perspectives and bold thinking to drive excellence.

About the Role

The Principal Cyber Defense Threat Intelligence Analyst (CDTIA) identifies, collects, and monitors threat intelligence from various sources to analyze, synthesize, and provide actionable intelligence reports and briefings to the joint security operations center (JSOC) and other IT and operational technology (OT) teams. This role collaborates with the Energy Threat Analysis Center (ETAC) under the Department of Energy (DOE) to operationalize cyber and physical threat intelligence in support of defending Exelon’s enterprise and OT assets against Advanced Persistent Threats.

This is a hybrid position requiring in-office presence at least three days per week (Tuesday, Wednesday, and Thursday). The role is open to candidates in our corporate offices in Chicago/Oakbrook Terrace, IL; Philadelphia, PA; Newark, DE; Baltimore, MD; or Washington, DC. No relocation is available; candidates must be able to commute within our service area.

Responsibilities

  • Serve as a conduit for investigative exchange, correlating internal company data with partner organizations' detections (50%).
  • Develop threat hunting and detection campaigns jointly with partner organizations and implement them within the corporate environment (20%).
  • Support end-to-end intelligence efforts through expert analysis and reporting of threat intelligence (10%).
  • Support the identification, containment, and eradication of threats of all sophistication levels (10%).
  • Recommend short- and long-term adjustments to security controls for immediate and future threat identification, containment, and remediation (5%).
  • Provide direction on tuning signatures, rules, alerts, parsers, and custom scripts (5%).

Requirements

  • Bachelor's Degree in Computer Science, Information Systems, or a related 4-year technical degree, or equivalent military/government experience.
  • Typically 5 to 8 years of diverse experience in IT, cybersecurity, real-time systems, or a related field.
  • Willingness to travel to Golden, Colorado, monthly or as required.
  • Willingness to obtain and maintain a US government TS/SCI security clearance.
  • Experience in operational technology defense and engineering concepts.
  • Proven threat hunting experience and ability to track adversaries using their tactics, techniques, and procedures (TTPs), MITRE ATT&CK framework, OSINT collection, and deception techniques.
  • Proficiency in security tools such as SIEM solutions, IDS/IPS, threat intelligence platforms, and SOAR solutions.
  • Experience in incident handling, vulnerability management, hacking tools, intelligence gathering, and kill chain methodology.
  • Experience participating in collaborative threat analysis meetings with internal and external trusted entities.
  • Ability to analyze incident logs, assess malware, understand vulnerabilities and exploits, and strong operating systems knowledge.
  • Demonstrated understanding of network and host cybersecurity solutions.
  • Strong written and verbal communication skills across all levels of the organization.
  • One or more of the following certifications (or equivalent): GCIA, GCIH, GCTI, GNFA, OSCP.

Preferred Qualifications

  • Graduate degree in cybersecurity, intelligence and analysis, or a related field.
  • Minimum 3 years of experience supporting the energy sector.
  • Experience in a network security environment (e.g., Security Operations Center, Security Incident Response Team) investigating targeted intrusions.
  • Existing US government security clearance with experience working with sensitive classified data.

Pay

Annual salary range: $136,800 – $188,100. Eligible positions include an annual bonus of 20%.

Benefits

  • 401(k) match and annual company contribution.
  • Medical, dental, and vision insurance.
  • Life and disability insurance.
  • Generous paid time off, including vacation, sick time, floating and fixed holidays, maternity leave, bonding/primary caregiver leave, and parental leave.
  • Employee Assistance Program and resources for mental and emotional support.
  • Wellbeing programs, including tuition reimbursement, adoption and surrogacy assistance, and fitness reimbursement.
  • Referral bonus program.

Note: Exelon-sponsored compensation and benefit programs may vary based on length of service, job grade, job classification, or represented status.

Schedule

Hybrid position requiring in-office presence at least three days per week (Tuesday, Wednesday, and Thursday).

Similar jobs