ECS

Cyber Threat Intelligence (CTI) SME (Team Lead)

ECS$165K — $185K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years of experience in Cyber Threat Intelligence, threat hunting, or analysis roles
  • Active Top Secret Clearance with SCI eligibility
  • Expertise in tracking state-sponsored adversaries, specifically from PRC
  • Hands-on experience in developing behavioral fingerprints and signatures
  • Proficient in mapping adversary behaviors to the MITRE ATT&CK framework
  • Experience correlating diverse external datasets with internal telemetry
  • Background in designing automation-first analytics pipelines integrating AI/ML models

Responsibilities

  • Lead a specialized team in cyber threat collection and analytics
  • Design and implement a tailored collection and analytics framework
  • Facilitate proactive threat hunting and incident response
  • Establish a unified workflow for intelligence requests and service delivery
  • Build high-confidence behavioral fingerprints for threat actors
  • Map adversary behaviors to provide clear hunt guidance
  • Correlate various telemetry datasets to generate actionable leads

Benefits

  • Hybrid work model with options for routine remote work
  • Opportunity to work with advanced cyber threat intelligence technologies
  • Access to a dynamic and technical team environment
  • Engagement with high-profile national security clients
  • Significant influence on shaping intelligence operations
Full Job Description
Everforth ECS is seeking a Cyber Threat Intelligence (CTI) SME (Team Lead) to join our team in Arlington, VA (Hybrid). This position is contingent upon award.

ECS is seeking a CTI SME (Team Lead) to lead a specialized cyber threat collection and analytics capability within Threat Branch in support of our National Security client. The scope of the program includes designing, implementing, and operating a tailored collection and analytics framework to convert diverse external datasets into precise, actionable leads for Proactive Threat Hunting (PHB) and Incident Response (IRB) teams. This position is located in Ballston, VA (Arlington) with the option for routine remote work. In this role, you will lead a highly technical team of threat analysts and engineers delivering advanced threat intelligence, tracking priority PRC adversaries, and deploying automation-first analytics pipelines.

We are seeking an accomplished, dynamic, and hands-on CTI leader with experience managing technical threat intelligence capabilities in a fast-paced environment. The role requires strong technical authority and leadership to establish a unified intake-to-execution workflow that gives stakeholders visibility into intelligence requests, analytics outputs, and service delivery validated against operational needs. Your ability to build high-confidence behavioral fingerprints, map procedure-level actor behaviors to MITRE ATT&CK, and correlate disparate telemetry datasets will be critical to your success.

Salary Range: $165,000 - $185,000

General Description of Benefits

  • 10+ years of progressive experience in Cyber Threat Intelligence (CTI), threat hunting, or threat analysis roles, including experience leading technical teams.
  • Active Top Secret Clearance with SCI eligibility.
  • Demonstrated expertise tracking priority threat actors (including PRC state-sponsored adversaries), victim-facing infrastructure, relay/proxy networks, and obfuscation setups.
  • Deep hands-on experience developing high-confidence signatures, fingerprints, and heuristics (e.g., TLS/HTTP behavioral fingerprints, domain/IP clustering).
  • Technical proficiency mapping adversary behaviors at the procedure level to the MITRE ATT&CK framework and producing clear hunt/detection guidance.
  • Proven capability correlating diverse external datasets (e.g., internet-wide scans, commercial decoy feeds) with internal telemetry and sensor data to drive high-value hunt leads.
  • Experience designing and implementing automation-first analytics pipelines, including integrating AI/ML models (e.g., clustering, anomaly detection) with human-in-the-loop validation workflows.
  • Experience establishing intake-to-execution workflows to align service models, budgets, and request tracking directly with user operational needs.

About ECS

ECS is a leading provider of digital solutions and services to the federal government. The company was founded in 2001 by Roy Kapani and has since grown to become a trusted partner to a wide range of government agencies. ECS offers a broad range of services, including cloud computing, cybersecurity, and artificial intelligence. The company has been recognized for its innovative solutions and has won numerous awards, including the AWS Public Sector Partner of the Year award.
Learn more about ECS
Size
2,000 employees
Industry

Similar Jobs

More Jobs at ECS

More Information Technology Jobs

Find similar Cyber Threat Intelligence (CTI) SME (Team Lead) jobs: