Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cyber Threat Analyst - Arlington, VA

VetJobs

Job Description

ATTENTION MILITARY AFFILIATED JOB SEEKERS - Our organization works with partner companies to source qualified talent for their open roles. The following position is available to Veterans, Transitioning Military, National Guard and Reserve Members, Military Spouses, Wounded Warriors, and their Caregivers. If you have the required skill set, education requirements, and experience, please click the submit button and follow the next steps. All positions are onsite, unless otherwise stated.

Position Title: Information Technology Specialist (INFOSEC)
Series & Grade: GS 2210 13
Promotion Potential: GS 14
Agency: Department of Homeland Security
Organization: Cybersecurity and Infrastructure Security Agency (CISA), Cybersecurity Division (CSD), Joint Cyber Defense Collaborative (JCDC)
Location: Arlington, VA (and other locations as determined by the agency)
Clearance: TS/SCI (ability to attain)
Who May Apply:
  • Veterans with a 30% or more service-connected disability rating
  • Individuals eligible under Schedule A (5 CFR 213.3102(u))
Summary
This position is located in the Cybersecurity and Infrastructure Security Agency (CISA), Cybersecurity Division (CSD), Joint Cyber Defense Collaborative (JCDC). CISA is the Nation's risk advisor, working with partners to defend against today's threats and to build more secure and resilient infrastructure for the future.
CSD leads cybersecurity efforts for CISA as the Nation's flagship civilian cyber defense organization. Within CSD, the JCDC brings together Federal, State, local, Tribal, territorial, international, and private sector partners to enable joint cyber defense planning, real time collaboration, and shared response to significant cyber risks and incidents.
As an Information Technology Specialist (INFOSEC), you will serve as a senior cyber defense incident responder and analyst. You will plan and implement advanced cyber defense capabilities, lead incident response activities, and conduct time sensitive enrichment and analysis of diverse cyber threat and telemetry data in support of JCDC operational priorities.

Duties:
As an Information Technology Specialist (INFOSEC), GS 2210 13, you will:
  • Implement higher level IT security requirements resulting from laws, regulations, and Presidential directives, and integrate security controls and practices across IT and cybersecurity disciplines.
  • Define the scope and level of detail for IT security plans and policies that govern CISA and JCDC security programs, ensuring alignment with agency wide cyber defense strategies.
  • Develop long range plans for IT security systems that anticipate, identify, evaluate, mitigate, and minimize risks associated with IT systems vulnerabilities across diverse environments.
  • Review proposed new systems, networks, and software designs for potential security risks and resolve integration issues related to the implementation of new capabilities within existing infrastructures.
  • Lead implementation activities for new security capabilities, institute measures to ensure awareness and compliance, and identify the need for changes based on evolving technologies and threats.
  • Review and evaluate security incident response policies and procedures and recommend improvements to enhance organizational readiness and response.
Cyber Defense Incident Response and Analysis
  • Serve as a primary cyber defense incident responder, coordinating and providing expert technical support to enterprise wide cyber defense personnel to resolve cyber incidents.
  • Perform cyber defense incident triage, including determining scope, urgency, and potential operational impact; identifying specific vulnerabilities or attack vectors; and recommending remediation actions to enable rapid response.
  • Conduct real time incident handling, including forensic collection, intrusion correlation and tracking, threat analysis, and direct system remediation in support of deployable Incident Response Teams (IRTs).
  • Correlate and analyze security relevant events from multiple sources (such as network activity, host-based telemetry, log analysis, alerts, and threat intelligence) to determine the nature, scope, and impact of cyber threats and attacks.
Threat Intelligence Enrichment and Data Driven Analysis (JCDC Focused)
  • Investigate and operationalize partner shared cybersecurity insights, unique cyber threat intelligence, and network/host telemetry into actionable outcomes, recommendations, and products in support of JCDC operations.
  • Contextualize and enrich technical indicators (such as IP addresses, domains, file hashes, and adversary tactics, techniques, and procedures) using:
    • Open source and commercial data sources requiring research, data correlation, and technical analysis skills;
    • Structured analytic frameworks and methodologies for threat intelligence and adversary behavior mapping;
    • Internal data holdings, including network flow analysis, asset management, and intelligence reporting.
  • Identify anomalies in network and host data and determine which systems may be vulnerable based on vulnerability and product/version information, as well as unique technical signatures.
  • Map technical insights and observed behaviors to structured analytic frameworks to support hunting, detection engineering, and partner outreach.
  • Pair threat, vulnerability, and defensive telemetry in novel ways to identify or predict high confidence malicious activity against partner networks or technologies.
  • Conduct open source and classified/partner intelligence research on operational priorities and emerging cyber events to keep JCDC operators and partners informed with timely, actionable details.
Documentation, Communication, and Partner Engagement
  • Author and maintain robust technical and operational documentation in knowledge management platforms, ensuring that workflows, playbooks, and analytic findings are clearly captured and reusable.
  • Clearly distill and summarize broad and complex operational information for varied audiences, including:
  • Executives and decision makers who require concise, risk focused summaries; and
  • Analysts, defenders, and hunters who require detailed technical context and indicators.
  • Draft and deliver technical reports, briefings, and presentations to internal and external partners, adjusting content and language to match audience technical depth.
  • Engage with JCDC partners (Federal, State/Local/Tribal/Territorial, international, and private sector/critical infrastructure) in technical and operational settings to:
    • Solicit new insights and data;
    • Collaborate on joint priorities; and
    • Provide additive technical and informational value in shared cyber defense efforts.
  • Perform other duties as assigned.

Requirements:
  • You must be a U.S. citizen.
  • You must be able to obtain and maintain a Top Secret clearance with eligibility for access to Sensitive Compartmented Information (TS/SCI).
  • This position is designated Special Sensitive.
  • This position requires pre employment drug testing and is subject to random drug testing thereafter.
  • You may be required to complete a probationary period.
  • This position may be designated as Essential Personnel. Essential personnel must be able to report for duty or remain on duty during continuity of operations events regardless of weather, protests, acts of terrorism, or funding lapses.

Certificates/Security Clearances/Other

Requirements:
  • You must be a U.S. citizen.
  • You must be able to obtain and maintain a Top Secret clearance with eligibility for access to Sensitive Compartmented Information (TS/SCI).

Additional Qualifications/Responsibilities

Qualifications: You must meet both the IT related experience requirement and the specialized experience requirement described below by the closing date of this announcement.
  • 1. IT Related Experience (All Applicants) Your resume must demonstrate IT related experience that shows each of the following four competencies (OPM 2210 standard):
    • Attention to Detail - Is thorough and conscientious in analyzing logs, telemetry, and indicators; carefully validates data and conclusions before disseminating.
    • Customer Service - Works with internal and external partners (e.g., other Federal agencies, SLTT entities, private sector organizations) to assess cyber defense needs, provide assistance, and ensure operationally useful outcomes.
    • Oral Communication - Clearly conveys technical and non technical information to audiences at varying levels of expertise; presents complex cyber issues in a structured, understandable manner.
    • Problem Solving - Identifies cyber issues; determines accuracy and relevance of information; uses sound judgment to generate and evaluate options and provide well reasoned recommendations.
  • 2. Specialized Experience (GS 13) You must have one full year of specialized experience at the GS 12 level or equivalent in the Federal service, performing all of the following:
    • Implementing or overseeing IT and cybersecurity controls and requirements derived from Federal laws, regulations, policies, or directives, and integrating those controls into operational systems or networks;
    • Developing or contributing to long range plans or strategies for IT security systems that anticipate, identify, evaluate, mitigate, and minimize risks associated with IT systems vulnerabilities;
    • Reviewing proposed or existing systems, networks, or software designs for security risks, identifying vulnerabilities, and recommending or implementing mitigations;
    • Performing or leading cyber defense incident response activities (e.g., incident triage, forensic data collection, intrusion tracking, threat analysis, and system remediation) in response to actual or potential cyber events;
    • Correlating and analyzing security events and telemetry from multiple sources (e.g., network data, host data, threat intelligence, logs, and alerts) to determine the nature, scope, and impact of cyber threats or incidents, and documenting and escalating incidents as appropriate; and
    • Conducting or supporting cyber threat intelligence enrichment and analysis, including the use of structured frameworks and multiple data sources (such as analytic methodologies for adversary behavior mapping and research across open-source, commercial, and government data) to produce actionable insights or products for defenders and decision-makers.
Desired (not required) experience and skills that may enhance your competitiveness include:
  • Experience in threat hunting, red/blue/purple team operations, or other deeply technical cyber defense domains.
  • Familiarity with advanced analytic and link-analysis skills for mapping relationships and patterns in complex data sets.
  • Familiarity with core networking and security protocols and concepts (e.g., DNS, SMTP, SSL/TLS) and Advanced Persistent Threat (APT) tactics, techniques, and procedures.
  • Experience documenting workflows, playbooks, and technical findings in structured knowledge management environments.
  • Demonstrated ability to work in fast paced operational environments, manage multiple concurrent tasks, and engage ad hoc with analysts, senior leaders, legal teams, and external partners.

Note: Experience refers to paid and unpaid experience, including volunteer work done through National Service programs and other organizations. Your resume must clearly describe your relevant experience, including job titles, series and grades (if Federal), duties, and hours worked per week.
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Cyber Threat Analyst - Arlington, VA in Arlington, VA vacancy
  •  ...Staffing Pros, a division of VETS Inc., is recruiting for a full-time Cyber Threat Analyst with Splunk experience onsite in Arlington, VA. An Active Top Secret clearance is required for this role. This position is located in Arlington, VA and will be onsite 5... 
    Suggested
    Full time
    For contractors
    Remote work

    VETS

    Arlington, VA
    3 days ago
  •  ...Location: Arlington, VA Clearance Required: TS/SCI minimum (US Citizen) Employment...  ...enforcement. Our mission is to empower analysts and decision-makers through data-driven...  ...Analytics is seeking a highly skilled Senior Cyber Threat Analyst to join our team. This role... 
    Suggested
    Full time
    Local area

    Praescient Analytics

    Arlington, VA
    3 days ago
  • $100k - $124k

     ...customer approval. SkyePoint Decisions is seeking a Cyber Threat Analyst to support the Diplomatic Security Cyber Mission (DSCM) program...  ...secure business processes. This position is located in Arlington, VA and will be onsite 5 days a week. No hybrid/telework... 
    Suggested
    Contract work
    Remote work
    Overseas

    SkyePoint Decisions

    Arlington, VA
    4 days ago
  • Praescient Analytics in Arlington, VA is seeking a highly skilled Senior Cyber Threat Analyst to safeguard critical networks. The role involves planning, implementing, and monitoring security measures while analyzing cyber threats and vulnerabilities. Qualified candidates... 
    Suggested

    Praescient Analytics

    Arlington, VA
    4 days ago
  •  ...Cyber Threat Intelligence Analyst Nightwing provides technically advanced full-spectrum cyber, data operations, systems integration and intelligence...  ...Certified Threat Intelligence Analyst (C|TIA) Arlington, VA At Nightwing, we value collaboration and teamwork.... 
    Suggested
    Contract work
    Immediate start

    Nightwing

    Arlington, VA
    2 days ago
  •  ...strengthen and protect our nation's vital interests. Requisition #: 1617 Job Title: Cyber Threat Intelligence Analyst Location: Hybrid, Arlington, VA Clearance Level: Top Secret, Must Have Clearance to Start Job Description Agile... 
    2 days per week

    Agile Defense

    Arlington, VA
    1 day ago
  • $100k - $110k

     ...Cyber Threat Intelligence Analyst Job Number : 32285 Location : Arlington, VA Job Description : Cyber Threat Intelligence Analyst Arlington, VA Support mission-critical cyber threat intelligence for the Department... 
    Full time
    Flexible hours

    Allyon, Inc.

    Arlington, VA
    13 hours ago
  • $112k - $179k

    Cyber Network Security Analyst job at Peraton. Arlington, VA. Program Overview About The Role Peraton is hiring a Cyber Network Security Analyst for its' Federal...  ...available open and closed source information on related threats & vulnerabilities, diagnose observed activity for... 
    Internship
    Local area

    Payfuture Technologies

    Arlington, VA
    1 day ago
  • A tech consulting firm is seeking an Incident Manager with a focus on Cyber Threat Intelligence in Arlington, VA. The role involves gathering and analyzing cyber threat information to support operational decision-making and improve vulnerability management. Candidates... 

    Node.Digital LLC

    Arlington, VA
    1 day ago
  •  ...positions at different levels of responsibility, from mid‑level analyst to senior consultant. This is an office/remote hybrid...  ...collaborating with clients and team members remotely. Be present at our Arlington, VA Headquarters 3 days per week. And, if you don't quite have... 
    Work at office
    3 days per week

    Heuristics Solutions, LLC

    Arlington, VA
    2 days ago
  •  ...Cyber Threat Fusion Analyst The client is looking for a Cyber Threat Fusion Analyst. This position will support the Joint Service Provider (JSP...  ...role will be based onsite at the Mark Center in Alexandria, VA. Some remote work will be allowed. An active TS/SCI... 
    Remote work

    Beyond SOF

    Alexandria, VA
    13 hours ago
  • $62k - $141k

    Booz Allen Hamilton is seeking a Cyber Threat Specialist in Arlington, Virginia. In this role, you will leverage your skills to inform strategies and mitigate vulnerabilities for the Army National Guard. You will be responsible for solving cybersecurity issues, evaluating... 
    Remote job

    Booz Allen Hamilton

    Arlington, VA
    1 day ago
  • A leading cybersecurity firm in Arlington, Virginia is seeking Cyber Network Defense Analysts to support critical missions by analyzing network traffic and identifying threats. The ideal candidate requires U.S. Citizenship, active TS/SCI Clearance, and 5+ years of experience... 

    NewGen Technologies

    Arlington, VA
    13 hours ago
  • First Citizens Bank is looking for a skilled Information Security professional for a remote position available only in Virginia and North Carolina. This role involves analyzing vulnerabilities, recommending process improvements, and monitoring security incidents to safeguard...
    Remote job

    First Citizens Bank

    Arlington, VA
    1 day ago
  • A technology consulting firm in Arlington seeks a Cyber Threat Intelligence Analyst to support operational decision-making by providing timely intelligence on cyber threats. This role requires U.S. Citizenship and an active TS/SCI clearance, with a minimum of two years... 

    Limelight Health

    Arlington, VA
    4 days ago
  •  ...technically advanced full-spectrum cyber, data operations, systems...  ...a Cyber Network Defense Analyst to support this critical customer...  ...systems, and networks from threats. Responsibilities: - Characterize...  ...), Network+, Security+ Arlington, VA At Nightwing, we value... 
    Contract work
    Immediate start

    Nightwing

    Arlington, VA
    2 days ago
  •  ...Workplace Type : Onsite in Arlington, VA Clearance: Active TS/SCI...  ...(HIRT) secures the Nation's cyber and communications infrastructure...  ...a Cyber Network Defense Analyst (CNDA) to support this critical...  ...information systems, and networks from threats. CNDAs review data collected... 
    Full time
    Contract work
    Work at office
    Local area
    Immediate start
    Remote work

    Castalia Systems

    Arlington, VA
    1 day ago
  •  ...technically advanced full-spectrum cyber, data operations, systems...  ...seeking a Network Forensics Analyst to support this critical...  ...intrusion correlation and tracking, threat analysis, and advising on...  ...SANS GIAC GNFA preferred Arlington, VA At Nightwing, we value collaboration... 
    Contract work
    Immediate start

    Nightwing

    Arlington, VA
    3 days ago
  • A technology solutions provider in Arlington, VA, is seeking a Cyber Network Defense Analyst. The candidate will monitor network activity, analyze cyber events, and recommend proactive measures against threats. Responsibilities include documenting incidents, performing... 

    ARSIEM

    Arlington, VA
    3 days ago
  •  ...Threat Detection Security Engineer Job Description Overview CoStar Group (NASDAQ...  ...work in tandem with CoStar's global cyber threat center team to provide continuous...  ...security coverage. This position is in Arlington, VA or Richmond, VA and is in office Monday... 
    Full time
    Work at office
    Work from home
    Monday to Thursday

    CoStar Realty Information, Inc.

    Arlington, VA
    13 hours ago
  •  ...Job Title: Senior Cyber Analyst City: Alexandria State: Virginia Position Requirements Active DoD Top Secret / SCI Clearance...  ...Familiarity with intelligence tools including Defense Intelligence Threat Library, Validated Online Lifecycle Threat reports, Community... 
    Work experience placement
    Work at office
    Local area

    Noetic Strategies, Inc.

    Alexandria, VA
    2 days ago
  •  ...Location: Mclean, Virginia Type: Contract Job #3712 Title: Cyber Threat Hunt Analyst Location: McLean, VA *Clearance: *Active TS/SCI w/ Polygraph needed to apply * Company Overview: Cornerstone Defense is the Employer of Choice within... 
    Contract work

    Cornerstone Defense

    McLean, VA
    1 day ago
  •  ...Summary Cyber Threat Analysts assess foreign cyber intentions and capabilities to support U.S. national security interests. Learn more about this agency Duties Help As a Cyber Threat Analyst at CIA, you will analyze foreign cyber intentions and capabilities... 
    Full time
    Part time

    Central Intelligence Agency

    Washington DC
    4 days ago
  •  ...Government agencies and critical asset owners who experience cyber-attacks, providing immediate investigation and resolution. Contract...  ...with the restoration of services. They are seeking a  Cyber Threat Analyst  to support this critical customer mission.... 
    Contract work
    Immediate start
    Shift work

    NewGen Technologies (Maryland)

    Arlington, VA
    2 days ago
  •  ...Senior Cyber Incident Analyst Everforth ECS is seeking a Senior Cyber Incident Analyst to work in our Arlington, VA office. ECS is seeking talented professionals to join our successful...  ...to proactively defend against cyber threats. Our ECS team is at the center of... 
    Work at office
    3 days per week

    ECS Limited

    Arlington, VA
    4 days ago
  •  ...Cyber Threat Analyst As a Cyber Threat Analyst at CIA, you will analyze foreign cyber intentions and capabilities to support U.S. national security interests. You will identify, monitor, and counter threats against US information systems and critical infrastructure... 

    US Government Jobs - Other Agencies

    Washington DC
    13 hours ago
  • $115k - $135k

     ...CI Cyber Threat Analyst Clearance: Must currently possess an active TS/SCI security clearance and be able to obtain a CI polygraph after hire (if not before) Location: Springfield, VA Salary Range: $115,000 - $135,000 Experience: Must have at least 7 years... 
    Work at office
    Flexible hours

    Sphinx

    Springfield, VA
    2 days ago
  •  ...strengthen and protect our nation's vital interests. Requisition #: 1613 Job Title: Cyber Insider Threat Analyst III Location: Hybrid, Springfield, VA Clearance Level: Top Secret / SCI, Must Have Clearance to Start Job Description This... 
    Work at office

    Agile Defense

    Springfield, VA
    2 days ago
  •  ...Cyber Threat Analyst 2 Everforth ECS is seeking a Cyber Threat Analyst 2 to work in our Fairfax, VA office. Everforth ECS is a leading managed cybersecurity services provider, ECS delivers a highly tailored and customized offering to each customer. Our team is responsible... 
    Work at office

    ECS

    Fairfax, VA
    1 day ago
  • Soft Tech Consulting, Inc. is seeking a Cloud Engineer (RPA) in Arlington, VA. The role involves designing, testing, and deploying RPA workflows, and requires a Bachelor's degree in a relevant field along with significant programming experience. A Secret Clearance is mandatory... 

    Soft Tech Consulting, Inc

    Arlington, VA
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cyber Threat Analyst - Arlington, VA. Be the first to apply!