Operational Technology Threat Intelligence Analyst
Operational Technology Threat Intelligence Analyst
Collects, reviews, and identifies cybersecurity threat intelligence from open source and government intelligence reporting to analyze and provide actionable threat reporting and briefings for Operational Technology (OT) cybersecurity analysts. Provides support to content developers and cybersecurity engineers in identifying gaps in protection and detection of OT systems. Reviews log and network events and alerts related to OT systems for signs of attack or Advanced Persistent Threats. Works closely with Cyber Intelligence analysts and Incident Response analysts to ensure expert analysis and reporting of Cybersecurity OT threats and attacks. Performs root cause analysis and supports remediation efforts for incidents related to Operational Technology cybersecurity incidents. Acts as the Subject Matter Expert on OT cybersecurity related issues.
Minimum Requirements:
Six (6) years of relevant IT experience
Two (2) years of experience working with OT or related technologies.
Two (2) years utilizing cyber threat intelligence
Two (2) years working with a SIEM in an engineering or incident response role
Experience collecting and interpreting qualitative and quantitative data from multiple sources
Understanding of the NIST Incident Response Framework
Understanding of the MITRE ATT&CK framework
Experience with OT such as Programmable Logic Controllers (PLCs) and Supervisory Control and Data Acquisition (SCADA) software
Understanding of threats and vulnerabilities in OT environments
Must possess a current DOD Top Secret Clearance and be eligible for an IT-I Critical Sensitive security clearance or Tier 5 (T5) at time of proposal submission.