Cyber Threat Intelligence (CTI) Analyst
Indexed description
The Cyber Threat Intelligence (CTI) Analyst is responsible for collecting, analyzing, and disseminating actionable cyber threat intelligence to support an Army contract. This role provides intelligence-driven analysis that enhances threat detection, informs Purple Team assessments, prioritizes remediation efforts, and improves the organization's overall cyber defense posture.
Key Responsibilities:
- Collect, analyze, and correlate cyber threat intelligence from classified and open-source reporting to identify emerging threats, adversary activity, and attack trends.
- Produce timely intelligence reports, threat assessments, and briefings for supported commanders, Regional Cyber Centers (RCC), ARCYBER, and cybersecurity leadership.
- Provide actionable intelligence to support Blue Team detection engineering, threat hunting, and incident response activities.
- Partner with Purple Team personnel to develop intelligence-driven assessment objectives and adversary emulation scenarios.
- Develop, review, validate, and maintain detection signatures and indicators of compromise (IOCs), ensuring proper syntax, functionality, and minimal false positives before deployment.
- Support continuous improvement of enterprise detection capabilities by reviewing and refining signature content, detection logic, and threat indicators.
- Conduct signature development and testing within isolated environments prior to production implementation.
- Track adversary tactics, techniques, and procedures (TTPs) using frameworks such as MITRE ATT&CK and provide recommendations to strengthen defensive capabilities.
- Maintain awareness of emerging cyber threats and communicate relevant intelligence to stakeholders across the cybersecurity enterprise.
- 5+ years experience performing Cyber Threat Intelligence analysis within a DoD, Intelligence Community, or federal cybersecurity environment.
- Strong understanding of nation-state and advanced persistent threat (APT) actors, malware analysis, and cyber threat reporting.
- Experience with threat intelligence platforms, SIEM technologies, detection engineering, and indicator management.
- Knowledge of MITRE ATT&CK, Cyber Kill Chain, STIX/TAXII, and common threat intelligence methodologies.
- Experience developing or validating detection signatures, YARA rules, Snort/Suricata signatures, or SIEM detection content is preferred.
- Excellent analytical, written, and verbal communication skills with experience producing executive and technical intelligence products.
- Active DoD Secret clearance with TS/SCI eligibility
Indigo IT is committed to hiring and retaining a diverse workforce. We are proud to be an Equal Opportunity/Affirmative Action Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. This employer uses E-Verify.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search