×
Register Here to Apply for Jobs or Post Jobs. X

External Title ICS Threat Analyst​/Top Secret

Job in Arlington, Arlington County, Virginia, 22201, USA
Listing for: Peraton
Full Time position
Listed on 2026-09-03
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, IT Consultant
Salary/Wage Range or Industry Benchmark: 86000 - 138000 USD Yearly USD 86000.00 138000.00 YEAR
Job Description & How to Apply Below
Position: External Job Posting Title ICS Threat Hunt Analyst / Active Top Secret

Responsibilities

Peraton is currently hiring
Industrial Control System Cyber Threat Intelligence Analyst
for its Federal Strategic Cyber programs.

Location:
On-site role in Arlington, VA.

In this role, you will:

  • Conduct proactive threat hunting across operational technology (OT) and industrial control system (ICS) environments to identify adversary presence, misconfigurations, and indicators of compromise.
  • Leverage internet-facing asset discovery and reconnaissance platforms (e.g., Shodan, Censys) to identify exposed ICs/SCADA assets, assess attack surface, and inform threat assessments.
  • Perform open-source intelligence (OSINT) research and analysis to identify current and emerging threats targeting critical infrastructure sectors.
  • Analyze network traffic patterns, ICs communication protocols (e.g., Modbus, DNP3, BACnet, OPC UA, Ethernet/IP, S7comm), and system architectures to identify anomalous or malicious activity.
  • Fuse multiple intelligence sources to develop products, recommendations, and inform priorities for the organization.
  • Research and investigate current threats in operational technology, specific critical infrastructure sectors, and mission areas to inform senior leaders and drive priorities for operational teams, including forward-deployed incident response and threat hunting functions.
  • Prepare assessments and cyber threat profiles of current events and trends within ICs/SCADA environments.
  • Escalate new or high-priority threats to the Cyber Physical Forensics Section as required.
  • Map ICs threat activity using the MITRE ATT&CK for ICs Framework.
  • Seamlessly work alongside a team of host, network, and cloud forensic analysts to meet mission requirements for both incident response and threat hunting engagements.
  • Identify potential open-source vulnerabilities existing within ICs/SCADA systems and assess exploitability in the context of real-world threat actor capabilities.
  • Identify classified threat intelligence reporting related to ICs/SCADA and analyze for adversary intent and capability.
  • Contribute to Pre-Deployment Readiness Packages and campaign tracking.
  • Produce high-quality papers, presentations, recommendations, and findings for senior U.S. government intelligence and operations officials.
Qualifications

Basic Qualifications:
  • Bachelor's degree and 2 years of experience, or an Associate's degree and 4 years of relevant experience; or HS and 6+ years in lieu of a bachelors degree.
  • Demonstrated experience conducting threat hunting, network reconnaissance, or vulnerability assessment in IT or OT environments.
  • Familiarity with IC/SCADA systems, protocols (e.g., Modbus, DNP3, BACnet, OPC UA, Ethernet/IP), and their associated security risks.
  • Hands-on experience with internet-facing asset discovery tools such as Shodan, Censys, or similar platforms for identifying exposed infrastructure.
  • Experience performing open-source intelligence (OSINT) collection and analysis to support cyber threat assessments.
  • Understanding of networking fundamentals (TCP/IP, routing, switching, firewalls, VPNs) and how they apply to IT/OT convergence environments.
  • Experience researching and analyzing cyber threats across either a) multiple industries or b) multiple time frames, including but not limited to critical infrastructure sectors.
  • Familiarity with common cyber threat intelligence tools such as Domain Tools, Virus Total, Maltego, exploit-db, etc..
  • Experience producing and completing all-source (unclassified and classified) finished intelligence assessments that adhere to ICD
    203 analytic tradecraft standards.
  • Proven ability to collaborate and establish key threat intelligence partnerships to bolster information sharing and defenses.
  • U.S. citizenship required.
  • An Active Top Secret Security Clearance with SCI eligibility.
    • Additionally, have the ability to obtain/maintain DHS EOD agency clearance prior to starting
Preferred Qualifications:

Certifications (any of the following):

  • SANS GIAC Global Industrial Cyber Security Professional (GICSP)
  • SANS GIAC Response and Industrial Defense (GRID)
  • SANS GIAC Cyber Threat Intelligence (GCTI)
  • SANS GIAC Certified Enterprise Defender (GCED)
  • SANS GIAC Network Forensic Analyst (GNFA)
  • SANS GIAC Certified…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary