Cyber Intelligence Fusion Analyst
Job in
Alexandria, Fairfax County, Virginia, 22336, USA
Listed on 2026-10-08
Listing for:
Leidos
Full Time
position Listed on 2026-10-08
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
Position Summary The Cyber Intelligence Fusion Analyst serves as the proactive analysis and threat-hunting engine for the J361 SOC. The analyst synthesizes all-source threat reporting to conduct structured threat hunts, perform proactive environment sweeps, and deliver tailored analytical reports and briefings to senior leadership.
The position combines cyber operations, threat intelligence, and analytic tradecraft to identify, characterize, and mitigate threats affecting tenants and subscribers throughout the National Capital Region. Responsibilities include correlating external intelligence with enterprise telemetry, mapping adversary TTPs, recommending detections and countermeasures, and providing threat context during incident investigations across classified, unclassified, and cloud environments.
Primary Responsibilities Ingest, analyze, and synthesize cyber threat reporting from OSINT, government reporting, commercial threat-intelligence platforms, and other authorized sources to identify threats relevant to the environment.
Correlate external threat intelligence with enterprise SIEM, EDR, endpoint, network, packet capture (PCAP), Net Flow, proxy, firewall, IDS/IPS, SSL decryption, session, and system-log telemetry to identify and assess malicious activity.
Conduct proactive IOC sweeps and hypothesis-driven threat hunts to identify activity associated with emerging adversary campaigns, vulnerabilities, malware, targeted threats, and stealthy or evasive adversary behavior.
Characterize adversary infrastructure, malware, tooling, and TTPs using MITRE ATT&CK, Cyber Kill Chain, and other applicable threat-modeling frameworks; assess potential risk to enterprise assets, tenants, and mission operations.
Develop hunt plans, adversary profiles, analytic methodologies, detection logic, and complex query strategies; plan, coordinate, and execute ad hoc threat hunts; document findings and recommendations in AARs; and other required mission products.
Develop, validate, and recommend countermeasures, including SIEM correlation searches, analytic content, custom signatures, and blocking recommendations, to improve prevention, detection, and response to known adversarial TTPs; technically vet suspicious indicators before submitting detection or blocking nominations.
Produce recurring and ad hoc threat reports, intelligence assessments, executive summaries, situational-awareness updates, time-sensitive threat notifications, and strategic threat assessments.
Translate technical telemetry, forensics, intelligence reporting, and analytic findings into clear, actionable technical, operational, and executive-level summaries; prepare and deliver recurring and on-demand briefings to leadership, tenant organizations, and mission partners.
Serve as a subject matter expert on adversary tradecraft and provide threat context, intelligence support, and analytic recommendations to incident responders and other SOC teams during active investigations.
Develop and maintain SOPs, work instructions, hunt methodologies, analytic playbooks, detection use cases, and knowledge-management artifacts; identify capability and workflow gaps, recommend improvements, and enhance automation for enrichment, case management, reporting, dashboards, and metrics.
Provide technical leadership on complex hunts and investigations; mentor junior analysts and contribute to team training and professional development.
Basic Qualifications Active Top Secret security clearance with ability to obtain SCI Bachelor’s degree in cybersecurity, information technology, computer science, intelligence studies, or a related technical discipline and 8+ years of relevant experience; additional relevant experience, cybersecurity education, or industry certifications may be substituted for a degree.
4+ years of experience supporting cybersecurity operations, cyber threat intelligence, threat hunting, incident response, cyber network defense, or a closely related cyber mission.
Must meet DoD 8140 IAT Level II baseline certification requirements before starting work and possess, or obtain and…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×