Cyber Threat Intelligence Analyst

Leidos

Confirmed live yesterday High trust
Hybrid

Quick summary

Work type
Hybrid
Location
Washington, DC
Salary
$107,900–$195,050 / yr
Posted
59 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $149k
This role $151k
$97k most similar roles pay here $206k

This role pays more than 59% of similar roles. Most pay $122,275–$175,076 — the shaded band above. At the midpoint, this role pays about $151k versus about $149k for comparable roles.

Based on 238 similar postings.

Employer

About Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations.

Leidos currently has 264 open roles on FindRole.

Listed pay typically runs $92,300–$166,850 across 245 roles with salary data.

Most-posted roles

View all roles at Leidos

At a glance

TL;DR · Cyber Threat Intelligence Analyst

The Cyber Threat Intelligence Analyst joins the Digital Modernization team to support Defensive Cyber Operations in protecting federal networked systems from national security threats. This role involves producing strategic, operational, and tactical intelligence reports, characterizing adversary TTPs using the MITRE ATT&CK framework, and managing the end-to-end intelligence lifecycle including PIR development and indicator management. The analyst will perform threat modeling, provide actionable pivot points for hunt missions, and design automated solutions to deliver data to SIEM, SOAR, and firewalls. Key technical requirements include proficiency in networking protocols, security elements like IDS/IPS, and scripting with Python or PowerShell. Candidates should be skilled in analyzing malware, packet captures, and forensic data while utilizing platforms such as Anomali or ThreatConnect to address complex cyber-adversary activities within cloud and containerized environments.

What you'll do

  • Produce strategic, operational, and tactical intelligence reports regarding emerging threats and adversary motivations.
  • Analyze adversary tactics, techniques, and procedures using the MITRE ATT&CK framework to profile Advanced Persistent Threats.
  • Manage the end-to-end intelligence cycle including developing Priority Intelligence Requirements and managing collection plans.
  • Evaluate and manage the lifecycle of Indicators of Compromise (IOCs) within a Threat Intelligence Platform.
  • Provide actionable "Indications & Warnings" and pivot points to support Hunt missions and Defensive Cyber Operations.
  • Develop scripts and automated solutions to deliver threat data to security controls like SIEM, SOAR, and firewalls.
  • Provide executive-level recommendations for risk management and intelligence-driven defense strategies.

What we're looking for

  • Must possess a Bachelor's degree with 8 years of experience or a Master's degree with 6 years of experience.
  • Must hold a current DoD TS/SCI security clearance and pass customer suitability screenings.
  • Must hold a DoD 8570 IAT Level II or III certification (e.g., Security+, CySA+, GSEC, or SSCP).
  • Must hold a DoD 8570 CSSP Analyst certification (e.g., CySA+, Cloud+, GCIA).
  • Must hold a DoD 8570 CSSP Infrastructure Support certification (e.g., CEH, CND, CHFI, GICSP, or SSCP).
  • Must have strong knowledge of networking protocols and computing security elements like IDS/IPS and firewalls.
  • Experience with data correlation, analysis, and utilizing Threat Intelligence Platforms (TIPs) is required.
  • Proficiency in Python or PowerShell for automation and experience with KQL or SPL for querying datasets.

More like this

Similar roles

Cyber Intelligence Fusion Analyst

Leidos

Alexandria, VA 8 days ago $107,900$195,050
SIEM EDR MITRE ATT&CK Cyber Kill Chain Splunk Microsoft Sentinel Microsoft Defender for Endpoint Wireshark Python PowerShell SQL KQL SPL Lucene Linux Unix PCAP NetFlow OSINT Cyber Threat Intelligence Incident Response Threat Hunting
8+ yrs exp

Cyber Security Analyst

Leidos

Adelphi, MD 17 days ago $87,100$157,450
SIEM IDS Incident Response NetFlow Packet Capture AWS Microsoft Azure Google Cloud Platform Oracle Cloud TCP/IP Unix Cyber Kill Chain SaaS Vulnerability Management Network Security Security+ CE CSSP-Infrastructure Support
4+ yrs exp Hybrid

Cyber Security Analyst

Leidos

Adelphi, MD 17 days ago $87,100$157,450
SIEM IDS AWS Microsoft Azure Google Cloud Platform Oracle Cloud NetFlow Packet Capture TCP/IP Unix Incident Response Cyber Kill Chain SaaS Security+ CE CSSP-Infrastructure Support Vulnerability Management Network Security
4+ yrs exp Hybrid

Cyber Security Analyst

Leidos

Adelphi, MD 17 days ago $87,100$157,450
SIEM IDS Incident Response NetFlow Packet Capture AWS Microsoft Azure Google Cloud Platform Oracle Cloud TCP/IP Unix Cyber Kill Chain SaaS Vulnerability Management Network Security Security+ CE CSSP-Infrastructure Support
4+ yrs exp Hybrid

Cyber Threat Intelligence Analyst III

Leidos

Washington, DC +2 2 days ago
Cyber Threat Intelligence Cyber Kill Chain Diamond Model Splunk Analyst1 Python Bash PowerShell C++ CrowdStrike Falcon Tanium Proofpoint TAP Zscaler Malware Analysis Incident Response Threat Hunting Forensics XML HTML
8+ yrs exp

Cyber Security Analyst

Leidos

Fort Belvoir, VA 17 days ago $87,100$157,450
SIEM IDS AWS Microsoft Azure Google Cloud Platform Oracle Cloud NetFlow Packet Capture TCP/IP Unix Incident Response Cyber Kill Chain SaaS Vulnerability Management Network Security Security+ CE CSSP-Infrastructure Support
4+ yrs exp