Cyber Threat Intelligence Analyst III

Leidos

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
Washington, DCChandler, AZBay Saint Louis, MS
Posted
2 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

How this pay compares to similar roles

Similar $148k
$104k most similar roles pay here $197k

This listing doesn't post a salary. Most similar roles pay $122,900–$173,942.

Based on 239 similar postings.

Employer

About Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations.

Leidos currently has 264 open roles on FindRole.

Listed pay typically runs $92,300–$166,850 across 245 roles with salary data.

Most-posted roles

View all roles at Leidos

At a glance

TL;DR · Cyber Threat Intelligence Analyst III

The Tier 3 Cyber Threat Intelligence Analyst joins the Network Operations Security Operations team to support the Department of Homeland Security enterprise. This role involves identifying, tracking, and investigating high-priority threat campaigns and malicious actors by analyzing TTPs to enhance the organization's security posture. The analyst will develop cyber threat intelligence reports, conduct research into infrastructure using frameworks like MITRE ATT&CK and the Diamond Model, and perform host-based and network-based forensics for incident response and threat hunting. Key technical requirements include proficiency with Splunk, Analyst1, CrowdStrike Falcon, Tanium, Proofpoint TAP, and Zscaler. The role requires skills in Python, Bash, Visual Basic, or PowerShell to develop detection scripts. Candidates must possess a Top Secret/SCI clearance and demonstrate expertise in malware analysis, signature development, and correlating intelligence data from various sources to establish countermeasures.

What you'll do

  • Identify and investigate high-priority threat campaigns, malicious actors, and their associated TTPs.
  • Analyze the cyber threat landscape to enhance the organization's IT operating environment security posture.
  • Develop and deliver Cyber Threat Intelligence reports to provide situational awareness for peers and customers.
  • Support the Network Operations Security Center during incident response and proactive threat hunting activities.
  • Correlate various intelligence sources to collect indicators, identify shifts in TTPs, and establish countermeasures.
  • Perform host-based and network-based forensics to identify advanced threats and develop security content like signatures.
  • Enrich data from intelligence sources with internal logs and alerts to drive detection initiatives.
  • Develop scripts in languages like Python or PowerShell to support cyber threat detection and reporting.

What we're looking for

  • Must possess a Top Secret/SCI clearance.
  • Bachelor's degree in an IT field and 8-12 years of experience, or a Master's degree in an IT field and 8+ years of experience.
  • Minimum of 7 years of experience as a Tier III senior cyber security analyst performing intelligence analysis, collection management, and technical analysis.
  • Two years of recent experience with host-based and network-based security monitoring solutions including security content recommendation or development.
  • Must hold at least one of the following certifications: CASP+ CE, CCNP-Security, CISA, CISP (or Associate), GCED, GCIH, or CCSP.
  • Deep understanding of the Pyramid of Pain, Cyber Kill Chain, MITRE ATT&CK, and the Diamond Model.
  • Ability to correlate and enrich data from intelligence sources with internal logs and incident data from Splunk and Analyst1.
  • Proficiency in Python, Bash, Visual Basic, or PowerShell (preferred); experience with CrowdStrike Falcon, Tanium, Proofpoint TAP, and Zscaler (preferred).

More like this

Similar roles

Cyber Threat Intelligence Analyst

Leidos

Washington, DC 59 days ago $107,900$195,050
Cyber Threat Intelligence MITRE ATT&CK Threat Intelligence Platforms (TIP Python PowerShell SIEM SOAR Firewalls IDS/IPS AWS Azure O365 KQL Elastic DSL SPL Cyber Kill Chain Diamond Model Data Correlation
8+ yrs exp Hybrid

Cyber Intelligence Fusion Analyst

Leidos

Alexandria, VA 8 days ago $107,900$195,050
SIEM EDR MITRE ATT&CK Cyber Kill Chain Splunk Microsoft Sentinel Microsoft Defender for Endpoint Wireshark Python PowerShell SQL KQL SPL Lucene Linux Unix PCAP NetFlow OSINT Cyber Threat Intelligence Incident Response Threat Hunting
8+ yrs exp

Intelligence Lead Analyst, Advanced Analytics and Cyber OSINT

Citi

Remote (Charlotte, NC) 16 days ago $117,440$176,160
OSINT Python PowerShell Bash Recorded Future Mandiant Advantage ThreatConnect MISP OpenCTI Palantir Maltego i2 Analyst's Notebook Link Analysis Network Forensics Log Analysis Reverse Engineering Malware Analysis Cyber Threat Intelligence
6+ yrs exp Remote

Cyber Security Analyst

Leidos

Adelphi, MD 17 days ago $87,100$157,450
SIEM IDS Incident Response NetFlow Packet Capture AWS Microsoft Azure Google Cloud Platform Oracle Cloud TCP/IP Unix Cyber Kill Chain SaaS Vulnerability Management Network Security Security+ CE CSSP-Infrastructure Support
4+ yrs exp Hybrid

Cyber Security Analyst

Leidos

Adelphi, MD 17 days ago $87,100$157,450
SIEM IDS AWS Microsoft Azure Google Cloud Platform Oracle Cloud NetFlow Packet Capture TCP/IP Unix Incident Response Cyber Kill Chain SaaS Security+ CE CSSP-Infrastructure Support Vulnerability Management Network Security
4+ yrs exp Hybrid

Cyber Security Analyst

Leidos

Fort Belvoir, VA 17 days ago $87,100$157,450
SIEM IDS AWS Microsoft Azure Google Cloud Platform Oracle Cloud NetFlow Packet Capture TCP/IP Unix Incident Response Cyber Kill Chain SaaS Vulnerability Management Network Security Security+ CE CSSP-Infrastructure Support
4+ yrs exp