Associate Principal Cyber Threat Intelligence Analyst
About the Role:
Our Cyber Threat Intelligence Team is seeking a Cyber Threat Intelligence Analyst who will directly support a Dragos federal customer at their site in Norfolk, VA. In this role you'll partner closely with your assigned customer and deliver tailored ICS/OT threat intelligence products to their Security and Intel teams. You'll research and analyze threats against critical infrastructure and translate your findings into briefings, written reports and operational guidance. You'll work onsite with their staff, understand their systems and environment, and collaborate across their organization to ensure intelligence connects to real defensive action. Our ideal candidate will have a strong background in CTI, threat hunting and have an understanding of industrial control systems.
Responsibilities:
Directly support your customer with their respective ICS/OT security and cyber threat intelligence needs.
Conduct threat research, analysis, and hunting tasks using a variety of proprietary and commercial resources to respond to client inquiries and craft tailored deliverables based on priority intelligence requirements.
Develop expertise in ICS/OT threats and risks directly relevant to your customer's environment, including attack surface analysis, threat hunting strategies, and threat modeling.
Support your customer’s cybersecurity initiatives to include threat hunts, incident response, and exercises.
Partner with internal Threat Intelligence peers to craft operational and strategic content for global Dragos Worldview customers.
Provide support and feedback to other internal Dragos teams, such as Incident Response, OT-Watch, Professional Services and Customer Experience.
Qualifications:
Must have an active Top Secret (TS) Security Clearance.
Must be willing and able to work onsite in Norfolk, VA.
At least 5 years of hands-on experience in the threat intelligence field using multiple resources and disciplines including network-based data (ie, NetFlow), OSINT, SIEMs, malware repositories, and DFIR.
Proven ability to create effective intelligence analysis products relevant for government agencies, federal civilian organizations or critical infrastructure sectors.
Experience integrating unclassified and classified threat intelligence into cohesive deliverables.
Threat hunting experience within ICS/OT environments or related technology settings.
Proven experience producing operational and strategic intelligence reporting using confidence-based assessments.
Proficiency with data aggregation, hunting, and analysis tools (eg, Synapse).
Experience building threat models relevant to specific threat and risk profiles.
Compensation:
Salary: $165,000
Competitive Equity Package
Comprehensive Benefits Plan
#LI-JF1 #LI-REMOTE