Open?Source Cyber Threat Intelligence Analyst

Peraton

$104K — $166K *
Education, Government & Non-Profit
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree with 9 years of experience; Master's degree with 7 years; PhD with 4 years; additional 4 years of experience can substitute for the bachelor's degree.
  • Professional certification required prior to start: CASP+ CE, CCNP Security, CEH, CFR, CHFI, CISA, CISSP (or Associate), Cloud+, CND, CySA+, GCED, GCIH, GICSP, or SSCP.
  • Proven experience in cyber threat intelligence and APT actor analysis, including methodologies for identifying related infrastructure.
  • Familiarity with SIEMs, threat intelligence platforms, and threat modeling frameworks like MITRE ATT&CK.
  • Expertise in providing intelligence support during cyber incidents and conducting post-incident reviews.
  • Strong analytical and communication skills, with an ability to convey complex information clearly; knowledge of ICD-203 standards is a plus.
  • Must be U.S. citizen with Top Secret clearance and SCI eligibility; willingness to travel up to two weeks.

Responsibilities

  • Serve as the OSINT specialist for I&W, conducting targeted research across various web environments.
  • Track advanced persistent threats (APT) focusing on infrastructure and exploitation methods.
  • Perform behavioral and pattern analysis to pinpoint malicious activities aimed at Department personnel.
  • Maintain detailed analytic records and metadata on threat campaigns and indications of compromise (IOCs).
  • Identify and triage IOCs using security tools, correlating them with open-source leads.
  • Participate in fusion cell activities to enhance situational awareness by integrating OSINT findings.
  • Liaise with IC partners and private-sector researchers to validate intelligence and close gaps.

Benefits

  • Full-time, on-site role in Northern VA with potential travel for briefings.
  • Opportunity to contribute to proactive cybersecurity measures protecting government personnel and assets.
  • Engagement with a dedicated team focused on threat analysis in a high-stakes environment.
  • Experience working directly with the Intelligence Community and government partners.
Full Job Description
Responsibilities

Peraton is hiring an experienced Open‑Source Cyber Threat Intelligence Analyst for our Federal Strategic Cyber Programs.

 

Location: Northern VA. Full-time, on-site role. 

  • Travel: For this role, you must be able to travel up to two weeks at a time, both foreign and domestically.

Description:

 

The Open‑Source Cyber Threat Intelligence Analyst will serve as a dedicated OSINT specialist within the Indications & Warnings (I&W) branch, supporting proactive early warning of cyber threats targeting Department of State personnel, systems, and information assets. This role is ideal for an analyst who excels in open‑source investigations, threat actor tracking, and fusing multi‑source intelligence into high‑value assessments.

 

In this role, you will:

  • Serve as the primary OSINT collector and analyst for the I&W mission, performing targeted open‑source research across surface/deep/dark web environments, social media, threat forums, and global reporting sources.
  • Track advanced persistent threat (APT) actors, their infrastructure, exploitation methods, malware,  development, targeting trends, and behavioral signatures using OSINT, vendor, and classified feeds.
  • Conduct pattern, trend, link, and behavioral analysis to identify malicious cyber activity aimed at Department personnel, networks, and mission equities.
  • Maintain structured analytic records and metadata to catalog active campaigns, actor infrastructure changes, and IOCs.
  • Identify and triage Indicators of Compromise (IOCs) using SIEM tools and other security platforms; pivot from IOCs to external open‑source leads to identify additional malicious infrastructure.
  • Act as a core participant in I&W’s fusion cell, integrating OSINT findings with technical telemetry and intelligence reporting to enhance situational awareness and inform mitigation recommendations.
  • Liaise with Intelligence Community (IC) partners, private‑sector researchers, and internal CTAD teams to validate findings and close intelligence gaps.
  • Monitor geopolitical developments, emerging technologies, hacktivist activity, and cybercriminal ecosystems to anticipate cyber threat shifts affecting Department operations.
  • Produce high‑quality written and verbal assessments, including rapid-turn spot reports, actor profiles, trend analyses, and briefings tailored for both technical and non‑technical audiences.
  • Correlate external threat intelligence with internal events to identify vulnerabilities, pre‑intrusion indicators, and opportunities for proactive defense.
  • Support I&W’s mission to provide actionable analysis that informs Department cybersecurity policy, configuration changes, and mitigation actions.
  • Potential to travel to support cyber security briefings and consultations.

#DSCM

Qualifications

Minimum requirements are: 

 

  • Bachelors degree and a minimum of 9 years of experience; 7 years with Masters degree; and 4 years with PhD. 
    • An additional 4 years of experience may be substituted in lieu of the bachelor's degree requirement.
  • Must either possess and maintain, or obtain prior to start date, one of the following professional certifications:
    • CASP+ CE; CCNP Security; CEH; CFR; CHFI; CISA; CISSP (or Associate); Cloud+;CND;CySA+; GCED; GCIH; GICSP; SSCP
  • Cyber Threat Intelligence & APT Analysis: Demonstrated experience in cyber threat intelligence, including tracking and analyzing Advanced Persistent Threat (APT) actors, adversary operations, tactics, techniques, and procedures (TTPs), and pivoting from indicators of compromise (IOCs) to identify related infrastructure.
  • Threat Intelligence Tools & Methodologies: Experience with SIEMs, threat intelligence and threat detection platforms, and established threat modeling frameworks such as MITRE ATT&CK, Lockheed Martin Cyber Kill Chain, or Diamond Model.
  • Threat Analysis & Incident Support: Experience providing intelligence support before, during, and after cyber incidents, including attribution analysis, adversary profiling, correlating disparate events, conducting post-incident reviews, identifying lessons learned, and improving threat detection capabilities.
  • Cybersecurity & Predictive Analysis: Knowledge of cloud security and threats targeting cloud environments, network protocols and systems, and experience developing predictive models or assessments to anticipate emerging cyber threats and recommend preemptive mitigation measures.
  • Analytical & Communication Skills: Strong analytical, critical thinking, and problem-solving skills with demonstrated ability to work independently and collaboratively. Excellent written communication skills with the ability to convey highly technical information in an analytic format; familiarity with ICD-203 Intelligence Community tradecraft standards and finished intelligence products is desirable.
  • Environment, Clearance & Travel: Experience working in fast-paced classified environments supporting government, military, or Intelligence Community organizations.
  • U.S citizenship required. 
  • An active Top Secret security clearance with SCI eligibility.
  • Active U.S. Passport and the ability to travel up to two weeks at a time, both foreign and domestically.
Target Salary Range$104,000 - $166,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual’s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

Similar Jobs

More Jobs at Peraton

More Education, Government & Non-Profit Jobs

Find similar Open?Source Cyber Threat Intelligence Analyst jobs: