Cyber Threat Intelligence (CTI) SME (Team Lead)
$165k - $185kECS
Job Description Everforth ECS is seeking a Cyber Threat Intelligence (CTI) SME (Team Lead) to join our team in Arlington, VA (Hybrid) . This position is contingent upon award. ECS is seeking a CTI SME (Team Lead) to lead a specialized cyber threat collection and analytics capability within Threat Branch in support of our National Security client. The scope of the program includes designing, implementing, and operating a tailored collection and analytics framework to convert diverse external datasets into precise, actionable leads for Proactive Threat Hunting (PHB) and Incident Response (IRB) teams. This position is located in Ballston, VA (Arlington) with the option for routine remote work. In this role, you will lead a highly technical team of threat analysts and engineers delivering advanced threat intelligence, tracking priority PRC adversaries, and deploying automation-first analytics pipelines. We are seeking an accomplished, dynamic, and hands-on CTI leader with experience managing technical threat intelligence capabilities in a fast-paced environment. The role requires strong technical authority and leadership to establish a unified intake-to-execution workflow that gives stakeholders visibility into intelligence requests, analytics outputs, and service delivery validated against operational needs. Your ability to build high-confidence behavioral fingerprints, map procedure-level actor behaviors to MITRE ATT&CK, and correlate disparate telemetry datasets will be critical to your success. Salary Range: $165,000 - $185,000 Required Skills 10+ years of progressive experience in Cyber Threat Intelligence (CTI), threat hunting, or threat analysis roles, including experience leading technical teams. Active Top Secret Clearance with SCI eligibility. Demonstrated expertise tracking priority threat actors (including PRC state-sponsored adversaries), victim-facing infrastructure, relay/proxy networks, and obfuscation setups. Deep hands-on experience developing high-confidence signatures, fingerprints, and heuristics (e.g., TLS/ behavioral fingerprints, domain/IP clustering). Technical proficiency mapping adversary behaviors at the procedure level to the MITRE ATT&CK framework and producing clear hunt/detection guidance. Proven capability correlating diverse external datasets (e.g., internet-wide scans, commercial decoy feeds) with internal telemetry and sensor data to drive high-value hunt leads. Experience designing and implementing automation-first analytics pipelines, including integrating AI/ML models (e.g., clustering, anomaly detection) with human-in-the-loop validation workflows. Experience establishing intake-to-execution workflows to align service models, budgets, and request tracking directly with user operational needs. Desired Skills GIAC Cyber Threat Intelligence (GCTI), Certified Information Systems Security Professional (CISSP), or equivalent technical certifications. Experience managing DHS or CISA cybersecurity programs (specifically supporting PHB, IRB, EOS, or Unified Persistent Hunt stakeholders). Expertise in evaluating commercial threat feeds and external context providers (e.g., GreyNoise, residential proxy/TOR context feeds) to deliver signal-to-noise and cost-benefit assessments. Proven track record of integrating CTI analytics outputs into enterprise target toolsets (e.g., "single pane of glass" dashboards). In-depth knowledge of evolving threat actor tactics, techniques, and procedures (TTPs) and advanced data-driven correlation methodologies. #EverforthECS1 ECS Federal LLC is an equal opportunity employer and does not discriminate or allow discrimination on the basis any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law. Everforth ECS is the federal segment of Everforth, a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies. Our work powers mission-critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow. We Value Attracting and developing top talent and high-performing teams Fostering a culture that is engaging, accountable, and mission-driven Meet the challenge. Make a difference with Everforth ECS! #J-18808-Ljbffr ECS
$165k - $185k
Everforth ECS is seeking a Cyber Threat Intelligence (CTI) SME (Team Lead) to join our team in Arlington, VA (Hybrid). ECS is seeking a CTI SME (Team Lead) to lead a specialized cyber threat collection and analytics capability within Threat Branch in support of our National...CyberIntelligenceRemote work- Everforth ECS in Arlington, VA is seeking a Cyber Threat Intelligence (CTI) SME (Team Lead) to direct a specialized threat collection and analytics capability within Threat Branch for a National Security client. The role is hybrid in Ballston, VA with potential remote...CyberIntelligenceRemote work
$140k - $160k
Job DescriptionEverforth ECS is seeking a Mid Cyber Threat Intelligence (CTI) Analyst to join our team in Arlington, VA (Hybrid). We are seeking a skilled and analytical Mid Cyber Threat Intelligence (CTI) SME to support the organization's cyber defense program through...CyberIntelligence- ...Position Title Threat Emulation & Readiness Lead / Red Team Lead Position Overview The... ...emulation, red team operations, cyber readiness exercises, and... ...to: MITRE ATT&CK, intelligence reporting, and real-... ...closely with SOC, CTI, Threat Hunt, and Detection...CyberIntelligenceFull time
- Information International Associates, Inc. is seeking a Cyber Threat Intelligence (CTI) Lead in Alexandria, VA. This role involves providing technical support to a 24x7 cyber program with responsibilities including the development of CTI analysis and incident response....CyberIntelligence
$112k - $179k
...Sr Industrial Control System Cyber Threat Intelligence Analyst for its Federal... ...priorities for operational teams, including the forward deployed... ...Serve as subject matter expert (SME) for ICS Security activities... ...the galaxy. As the world’s leading mission capability...CyberIntelligenceContract workCurrently hiringShift work$125k - $150k
..., federal civilian, and intelligence markets. We offer high-end... ...cloud services, cyber, software, advanced analytics... .... We are seeking a COOP SME - Test, Training and Exercise (TT&E) Team Lead to lead the resilience,... ...system security controls, threat models, and mission dependencies...CyberIntelligenceFull time- ...Position Title Cyber Threat Intelligence & Threat Hunting Lead Position Overview The Cyber Threat Intelligence & Threat Hunting Lead will oversee integrated cyber threat intelligence (CTI), detection engineering, and proactive threat hunting operations supporting...CyberIntelligenceFull time
- Required Qualifications:Experience with intelligence analysis principles or cyber threat intelligence (CTI) principles, including the ability to collect, analyze, and assess threat information.Specific experience conducting CTI analysis focused on China cyber threatsExperience...CyberIntelligence
- ...Ridge, TN, Dayton, OH, Morgantown, WV, Alexandria, VA, and the UK. Job Description KeyLogic is actively seeking a Cyber Threat Intelligence (CTI) Lead to enable our operational counterparts advanced analytics support to promote rapid analysis of national level cyber...CyberIntelligenceFull timeMonday to Friday
- ...BCMC is seeking a seasoned Incident Manager to support cyber threat intelligence efforts for a critical VM program. The role focuses on gathering and analyzing CTI to guide operational decisions, identify emerging threats and collaborate with stakeholders to implement...CyberIntelligence
- Accenture is seeking a Threat Informed Defense Senior Manager to lead the technical core of a global cyber threat intelligence program. You will own the capability that turns intelligence into defensive outcomes across Accenture's managed security stacks and client environments...CyberIntelligence
- ...(BCMC) is seeking an experienced Incident Manager to proactively gather and analyze CTI for vulnerability management and operational decision support. You will identify emerging threats, coordinate with stakeholders, and produce comprehensive CTI reports. The role requires...CyberIntelligence2 days per week3 days per week
- ...Evolver Federal is seeking a Lead Cyber Threat Analyst to fulfil a requirement for a potential... ...role focuses on proactive threat hunting, intelligence analysis, and developing strategies to... ...Lead Cyber Threat Analyst will lead a team of analysts, collaborate with SOC and incident...CyberIntelligenceFlexible hours
- cFocus Software seeks a CTI Analyst to join our program supporting... ...-depth technical analysis of cyber data (writing reports on... ...underlying raw telemetry to convey threat actor TTPs). ~2+ years of experience... ...and aggregating threat intelligence from OSINT platforms, dark web...CyberIntelligenceWork at office
$138k - $166k
...Engineer (Trellix SME), you’ll serve as the technical lead for the organization... ...infrastructure, application teams, and leadership to... ...emerging threats, evaluating new security... ...enterprise cyber defenses.What you’ll... ...(FRP/FRMP), Threat Intelligence Exchange (TIE), Data...CyberIntelligenceFull timeLocal area- cFocus Software seeks a Threat Hunt Lead to join our program supporting the... ...hunts leveraging threat intelligence, adversary tactics, techniques... ...Triage and Incident Response teams in accordance with the... ...operations. Work closely with Cyber Threat Intelligence teams to...CyberIntelligenceFull timeWork at office
$120k - $165k
...Department of Defense (DoD), Intelligence Community, and... ...seeking a Principal Cyber Systems Engineer, SME to provide high-level... ...superiority. You will lead the evaluation of... ...collaboration with numerous teams to ensure client... ...investigations, and insider threat detection.Our team of...CyberIntelligenceFull timeWork at office$100k - $110k
...Arlington, VA Support mission-critical cyber threat intelligence for the Department of Homeland Security... ...prevent attacks. Their work enables federal teams to anticipate risks, close intelligence... ...responses across agencies. Without CTI analysts, organizations would be blind...CyberIntelligenceFull timeFlexible hours- ...working with technologies like AI, cyber and cloud to careers in intelligence and health, we offer endless opportunities... ...The Azure Architecture SME – Lead is responsible for architecting, designing... ...Support: An internal mobility team focused on helping you achieve your...CyberIntelligence3 days per week
$150k - $195k
CTEC is a leading technology firm that provides modernization... ..., CTEC has over 300 team members working on... ...of Defense and U.S. Intelligence Community.Cybermedia... ...an experienced SME Business Management Analyst... ...on emerging cyber and physical threats, critical-infrastructure...CyberIntelligenceContract workWork at officeRemote work$106.92k - $242.82k
...Responsibilities About the Team The USDS FUSE Intelligence program is an all-hazards team... ...to TikTok USDS JV. As a Cyber Threat Intelligence Analyst, the candidate... ...partners Contribute CTI intelligence resources to... ...things with great people. We lead with curiosity, humility,...CyberIntelligenceTemporary workShift work- ...supporting a customer by delivering intelligence support to customer through... ...analyzing, and responding to cyber threats to inform the customer’s... ...disseminate timely and accurate CTI to support operational... ...work within a multi-disciplined team • Must be able to work collaboratively...CyberIntelligenceFull timeLocal areaFlexible hours
$104k - $166k
ResponsibilitiesThe Cyber Threat Analysis Division (DS/CTI/CTAD) conducts advanced digital... ...the mobile ecosystem.The team leverages a wide variety... ...team provides actionable intelligence and mitigation strategies... ...the galaxy. As the world’s leading mission capability...CyberIntelligenceContract workWorldwideOverseasShift work$130k - $180k
...ownership, and execution over bureaucracy. Lead Cyber Threat Intelligence Analyst Location: Onsite –... ...government-controlled secure facilities. The CTI function is the program's strategic... ...threat landscape — and leading a CTI team that delivers that intelligence with...CyberIntelligenceFull timeWork experience placementFlexible hoursShift work- ...Phoenix Cyberis looking for a Threat Intelligence Analyst, with Operational Technology (OT) focus, to join our client delivery team. Job Description Collects, reviews, and... ...experience applying ATT&CK for ICSSPARTA, or Cyber Kill Chain for ICSTo dissect adversary...CyberIntelligence
- ...development, network engineering, intelligence, surveillance, and... ...highly qualified senior-level Team Lead to support the American regional... ...the Americas and transnational threats (Mexico, Venezuela, Cuba, Brazil... ...(all-source, C4I, cyber, HUMINT, SIGINT, GEOINT, OSINT...CyberIntelligenceContract workFor contractorsWork at office
- ...Leidos is seeking a Tier 3 Cyber Threat Intelligence Analyst to join our team supporting DHS NOSC services. You will identify and investigate high-priority threat campaigns, track adversaries and TTPs, and deliver actionable intelligence to improve cyber resiliency across...CyberIntelligence
- ...SOSI is seeking a Cyber Intelligence Analyst III to lead cyber threat intelligence activities in support of mission-critical defense and government services.... ...chain concepts, coordinate with defense and incident teams, and guide intelligence-driven operations in a demanding...CyberIntelligenceWork at officeRemote work
$89.6k - $204k
...Engineer (Entry Level to SME) TS/SCI with Poly... ...collaborative team to deliver state-of... ...controls, monitoring for threats, and documenting... ...builder of daily cyber defenses. CGI... ...Federal Civilian, or Intelligence Community requirements... ...Framework (RMF): Lead the RMF process...CyberIntelligenceWork at officeLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Threat Intelligence (CTI) SME (Team Lead). Be the first to apply!
- recruitment team leader Arlington, VA
- market leader Arlington, VA
- manufacturing team lead Arlington, VA
- mobile team lead Arlington, VA
- leader Arlington, VA
- grocery team leader Arlington, VA
- team lead data science Arlington, VA
- remote team lead Arlington, VA
- team leader training Arlington, VA
- team leader production Arlington, VA



