Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cyber Threat Investigator

AGR, LLC

Redhawk Federal is looking for a Cyber Investigations Analyst to become part of our Federal Strategic Cyber Group.

Location: Rosslyn, VA;
full-time, on-site role.

In this role, you will:

  • Support the Cyber Threat Investigations & Analysis Division (CTAD) in conducting end-to-end insider threat and cyber investigations leveraging User Activity Monitoring (UAM) tools and data.
  • Collect, analyze, and interpret log data to detect anomalous user behavior, policy violations, and potential insider threats across enterprise systems.
  • Develop and refine detection rules, alerts, and behavioral baselines to improve threat detection capabilities.
  • Conduct forensic analysis of user activity logs, endpoint telemetry, and network data to support investigations and produce actionable intelligence.
  • Communicate complex investigative findings to both technical and non-technical stakeholders, including senior management.
  • Collaborate with legal, HR, and security teams to ensure investigations are conducted in accordance with applicable laws, policies, and Department guidelines.
  • Author detailed investigation reports, bulletins, and advisories documenting findings.
  • Promote awareness of insider threat indicators and UAM best practices among customer stakeholders, coworkers, and Department users.
  • Respond to escalated security incidents and provide expert guidance on user activity-related threat vectors.
  • Manage case documentation and investigative records in SharePoint repositories.
  • Provide guidance and mentorship to junior team members on investigative techniques and tool usage.
  • Stay current on emerging insider threat tactics, techniques, and procedures (TTPs) and incorporate findings into detection strategies.

QUALIFICATIONS

Minimum requirements:

  • A Bachelor’s degree and 5 years of experience. An additional 4 years of experience may be substituted in lieu of the bachelors degree requirement.
  • Minimum of 2 years experience in cybersecurity, digital forensics, or cyber investigations.
  • Must either possess and maintain, or obtain prior to start date, one of the following professional certifications:
  • CISSP-ISSAP;
    CISSP-ISSEP;
    CISSP;
    Security+ CE;
    CySA+;
    PPDA;
    Agile IC;
    SNOW App Dev
  • Experience conducting insider threat or cyber misconduct investigations in an enterprise environment.
  • Experience analyzing large datasets of user activity, log data, and endpoint telemetry.
  • Strong analytical, problem-solving, and decision-making skills to support complex, sensitive investigations.
  • Excellent written and verbal communication skills, including experience producing formal investigative reports.
  • Must possess strong time management skills and the ability to complete assigned tasks with minimal supervision.
  • U.S. citizenship required.
  • Active Top Secret security clearance.
  • Ability to obtain a final Top Secret/SCI security clearance.

Desired:

  • Experience with insider threat programs and familiarity with the National Insider Threat Policy.
  • Familiarity with SIEM platforms (e.G., Splunk, Microsoft Sentinel) for correlating UAM data with broader security telemetry.
  • Experience with digital forensics tools (e.G., EnCase, FTK, Magnet AXIOM).
  • Knowledge of Active Directory and Azure AD for user account analysis.
  • Experience working in a government or federal law enforcement investigative environment.
  • Technical writing skills and experience producing materials for senior leadership audiences.
  • Familiarity with chain of custody procedures, and eDiscovery processes.
  • Experience with behavioral analytics platforms or UEBA (User and Entity Behavior Analytics) tools.

Vacancy posted 17 hours ago
Similar jobs that could be interesting for youBased on the Cyber Threat Investigator in Arlington, VA vacancy
  • DescriptionThreat Intelligence AnalystDescription Threat Intelligence Analyst with strong knowledge and experience with Department of Defense...  ...in, cultural, social, and political environments relating to cyber and virtual environments. This position requires strong critical... 
    Suggested
    For contractors
    Work at office
    Shift work

    Science Applications International Corporation

    Arlington, VA
    4 days ago
  •  ...interviews which can be found here.ID.me is looking for a senior threat intelligence professional to lead technical tracking of the...  ...communities.Qualifications5+ years of experience in threat intelligence, cyber threat hunting, fraud intelligence, or a closely related... 
    Suggested
    Full time
    Work at office
    Remote work

    ID.me

    McLean, VA
    4 days ago
  • $115k - $125k

     ...– With a Commitment to Serve Clearance Level: **MUST HAVE A CURRENT ACTIVE SECRET CLEARANCE** Subsidiary: T&H Solutions Job Title: Threat Intelligence Analyst Work Location: Pentagon – Arlington, VA Labor Category: Full-Time | Exempt Work Schedule: Day Shift (8:00 AM –... 
    Suggested
    Full time
    Temporary work
    Local area
    Flexible hours
    Day shift

    Tlingit Haida Tribal Business Corporation

    Washington DC
    16 hours ago
  •  ...Phoenix Cyber is looking for a Threat Intelligence Analyst, with Operational Technology (OT) focus, to join our client delivery team.  Job Description:  Collects, reviews, and identifies cybersecurity threat intelligence from open source and intelligence reporting... 
    Suggested
    Full time

    Phoenix Cyber

    Washington DC
    13 days ago
  • Required Qualifications:Experience with intelligence analysis principles or cyber threat intelligence (CTI) principles, including the ability to collect, analyze, and assess threat information.Specific experience conducting CTI analysis focused on China cyber threatsExperience... 
    Suggested

    Maania Consultancy Services

    Arlington, VA
    4 days ago
  • $140k - $160k

    Job DescriptionEverforth ECS is seeking a Mid Cyber Threat Intelligence (CTI) Analyst to join our team in Arlington, VA (Hybrid). We are seeking a skilled and analytical Mid Cyber Threat Intelligence (CTI) SME to support the organization's cyber defense program through... 

    ECS Federal

    Arlington, VA
    2 days ago
  •  ...Redhawk Federal Solutions has an immediate opening for a Global Threat Analysis (GTA) for its' Federal Strategic Cyber program. Location: Arlington, VA (Full-time, On-site, 5-days per week) In this role, you will: Need to have regional cyber threat expertise... 
    Full time
    Immediate start
    Overseas

    AGR, LLC

    Arlington, VA
    17 hours ago
  • Everforth ECS in Arlington, VA is seeking a Mid Cyber Threat Intelligence (CTI) Analyst to join our hybrid team. This role focuses on collecting and analyzing cyber threat intelligence from open-source, commercial, and government sources to support security operations... 

    ECS

    Arlington, VA
    4 days ago
  • $106.92k - $242.82k

     ...outcomes to reduce and identify risk to TikTok USDS JV. As a Cyber Threat Intelligence Analyst, the candidate will be responsible for...  ...stakeholders. The candidate will possess strong skills in research and investigative techniques to develop tailored cyber threat intelligence... 
    Temporary work
    Shift work

    TikTok USDS Joint Venture LLC

    Washington DC
    5 days ago
  • $100k - $110k

     ...Arlington, VA Support mission-critical cyber threat intelligence for the Department of Homeland Security by analyzing and identifying...  ...integrate cyber security related data from relevant sources into investigative or analytical products Ability to work within a multi-... 
    Full time
    Flexible hours

    Allyon, Inc.

    Arlington, VA
    19 hours ago
  •  ...Description Candidate should meet minimum experience requirements: ~10 years' experience in conducting in-depth analysis of cyber threats, including malware, phishing campaigns, and other attack vectors. This involves identifying patterns, trends, and indicators of... 
    Full time
    Part time
    Work at office

    Avening Management and Technical Services LLC

    Washington DC
    1 day ago
  •  ...Manager to proactively gather and analyze CTI for vulnerability management and operational decision support. You will identify emerging threats, coordinate with stakeholders, and produce comprehensive CTI reports. The role requires TS/SCI clearance, DHS suitability, and the... 
    2 days per week
    3 days per week

    Business Computers Management Consulting Group

    Arlington, VA
    2 days ago
  •  ...BCMC is seeking a seasoned Incident Manager to support cyber threat intelligence efforts for a critical VM program. The role focuses on gathering and analyzing CTI to guide operational decisions, identify emerging threats and collaborate with stakeholders to implement... 

    BCMC, LLC

    Arlington, VA
    3 days ago
  •  ...Leidos is seeking a Tier 3 Cyber Threat Intelligence Analyst to join our team supporting DHS NOSC services. You will identify and investigate high-priority threat campaigns, track adversaries and TTPs, and deliver actionable intelligence to improve cyber resiliency across... 

    Leidos

    Washington DC
    5 days ago
  • $112k - $179k

    ResponsibilitiesPeraton is currently hiring Sr Industrial Control System Cyber Threat Intelligence Analyst for its Federal Strategic Cyber programs...  ...inform priorities for the organization.Perform research and investigate current threats in operational technology, specific critical... 
    Contract work
    Currently hiring
    Shift work

    Peraton Corporation

    Arlington, VA
    1 day ago
  • $99k - $225k

    Cyber Threat Intelligence Analyst Subject Matter ExpertThe Opportunity:  As a cyber threat intel analyst, you know the key to detecting...  ...tactical behavior. At Booz Allen, you can apply your expertise to investigate the most pressing cyber threats impacting our nation's... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Arlington, VA
    3 days ago
  •  ...through proactively identifying, analyzing, and responding to cyber threats to inform the customer’s vulnerability management (VM)...  ...integrate cyber security related data from relevant sources into investigative or analytical products • Ability to work within a multi-... 
    Full time
    Local area
    Flexible hours

    BCMC

    Arlington, VA
    a month ago
  • $70k - $85k

     ...cybersecurity support provider is seeking motivated individuals to deliver intelligence support by analyzing and responding to cyber threats. The position requires U.S. citizenship, an active TS/SCI clearance, and 5+ years of experience in relevant fields. Responsibilities... 

    ARGO Cyber Systems

    Arlington, VA
    4 days ago
  • Cyber Threat intelligence Analyst II Location: Onsite (CONUS) / Shift Work Clearance: Active TS/SCI (DHS EOD Suitability required) Company...  ...cyber security related data from relevant sources into investigative or analytical products • Ability to work within a multi-... 
    Shift work

    ARGO Cyber Systems

    Arlington, VA
    5 days ago
  •  ...information handling, and collaboration across DoD and law enforcement agencies. Candidates will provide intelligence analysis, brief senior leaders, and develop strategic papers and target packages to support counter-threat finance operations, with #J-18808-Ljbffr... 

    Amentum

    Arlington, VA
    2 days ago
  • SOSI is seeking a Cyber Intelligence Analyst III to lead cyber threat intelligence activities in support of mission-critical defense and government services. The role focuses on producing intelligence, supporting detection and response, and delivering actionable reports... 
    Work at office
    Remote work

    SmartRecruiters, Inc.

    Washington DC
    5 days ago
  •  ...Enterprises is currently seeking the following: TITLE: Insider Threat Program - Management Analyst 2 LEVEL: Mid RELATIONSHIPS:...  ...resources personnel responsible for the submission of requests for investigations and clearance actions Participates in various committee and... 
    Interim role
    Work at office

    H4 Enterprises LLC

    Arlington, VA
    5 days ago
  •  ...next step in your career. Come join our team! Zantech is looking for a talented Threat Intelligence Analyst to contribute to the success of our upcoming Program Management and Cyber Support Services project for an Onsite role based out of Arlington, VA. The... 
    Full time
    Contract work

    Zantech

    Arlington, VA
    6 days ago
  • Job TitleMid CI Specialist (Cyber Crime Investigator)LocationWashington, DC 20032 US (Primary)CategoryIntelligenceJob TypeFull-TimeCareer LevelStaffEducationBachelor...  ...on U.S. persons, activities and interests, including threats posed by emerging technologies to U.S. operations and... 

    Prescient Edge

    Washington DC
    4 days ago
  • Job TitleSenior-Level CI Specialist (Cyber Crime Investigator - TAB/CVE)LocationWashington, DC 20032 US (Primary)CategoryIntelligenceJob TypeFull...  ...on U.S. persons, activities, and interests, including threats posed by emerging technologies to U.S. operations and interests... 

    Prescient Edge

    Washington DC
    4 days ago
  •  ...Insight Global is seeking a Cyber Intelligence Fusion Analyst to sit at the Mark Center...  ...individual will serve as the proactive threat-hunting and intelligence-analysis engine...  ...including hypothesis-driven hunts and IOC investigations Experience developing detection logic,... 

    Insight Global

    Alexandria, VA
    2 days ago
  •  ...AV is seeking a Cyber Threat Intelligence Analyst to identify, analyze, and communicate cyber threats affecting the organization, employees...  ...cybersecurity skills to translate findings into detections, investigations, and defensive improvements. Responsibilities include... 

    A/V Services LLC

    Herndon, VA
    1 day ago
  • $65k - $70k

    A national security services company in McLean, VA, is seeking an Intelligence Analyst I. The role focuses on analyzing intelligence information, producing reports, and supporting customer's needs with tailored analysis. A bachelor’s degree in a relevant field is required...

    Agile Defense

    Mc Lean, VA
    4 days ago
  •  ...by using your expertise to protect our country from threats. Job Description How A Cyber Threat Intelligence (Fusion) Analyst Will Make an Impact...  ...in sensor and system logs, SIEMs, and other data; investigate to identify or rule out system compromises, provide written... 
    Immediate start

    General Dynamics Information Technology

    Reston, VA
    a month ago
  • $86k - $138k

    ResponsibilitiesPeraton is currently hiring Industrial Control System Cyber Threat Intelligence Analyst for its Federal Strategic Cyber programs...  ..., and inform priorities for the organization.Research and investigate current threats in operational technology, specific critical... 
    Contract work
    Currently hiring
    Shift work

    Peraton Corporation

    Arlington, VA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cyber Threat Investigator. Be the first to apply!