ForgeApply · Job listing
Cybersecurity Operations Analyst & Cyber Threat Intelligence Lead
The Aerospace Corporation
See all 317 open roles at The Aerospace Corporation →
Tailor your resume for this The Aerospace Corporation job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for The Aerospace Corporation's site. Free trial, no card required.
About this role
The Aerospace Corporation is the trusted partner to the nation’s space programs, solving the hardest problems and providing unmatched technical expertise. As the operator of a federally funded research and development center (FFRDC), we are broadly engaged across all aspects of space— delivering innovative solutions that span satellite, launch, ground, and cyber systems for defense, civil and commercial customers. When you join our team, you’ll be part of a special collection of problem solvers, thought leaders, and innovators. Join us and take your place in space.
The Aerospace Corporation seeks an experienced cybersecurity professional to serve as a Tier 2/3 Cyber Operations Analyst and Lead our Cyber Threat Intelligence (CTI) program. You'll handle escalated security events, conduct advanced threat analysis, lead complex investigations, and own all aspects of threat intelligence collection, analysis, production, and dissemination. As a SOC subject matter expert, you'll leverage cutting-edge security tools and deep technical expertise to identify, analyze, and mitigate advanced cyber threats while mentoring junior analysts.
Work Model The selected candidate will be required to work full-time, on-site at our facility in Colorado Springs, CO.
What You'll Be Doing
Cyber Threat Intelligence Program Leadership: • Lead Aerospace's CTI program, establishing strategy, processes, and capabilities • Develop CTI roadmap, define intelligence requirements (PIRs/IRs), and align with organizational risk priorities • Manage relationships with external threat intelligence partners, ISACs/ISAOs, and government agencies • Produce strategic, operational, and tactical intelligence products including threat assessments, adversary profiles, and campaign analysis • Conduct all-source intelligence analysis on threat actors and emerging threats targeting aerospace/defense • Manage threat intelligence platforms (TIP) and establish intelligence workflows • Track and profile APT groups and adversaries relevant to Aerospace's threat landscape • Brief leadership on threat trends, emerging risks, and intelligence-driven recommendations • Establish metrics demonstrating CTI program value and effectiveness
Security Operations & Incident Response: • Serve as Tier 2/3 escalation point for complex security alerts and incidents • Conduct deep-dive investigations into sophisticated threats and APTs • Perform advanced threat hunting leveraging intelligence to guide hypotheses • Analyze security alerts from SIEM, IDS, EDR, and other security technologies • Correlate data from multiple sources to reconstruct attack timelines and identify compromise scope • Lead incident response for escalated events, coordinating containment and remediation • Integrate threat intelligence into detection workflows and develop advanced detection rules • Analyze malware, scripts, and attacker tools to understand adversary TTPs • Mentor Tier 1 analysts and develop their analytical skills • Create advanced playbooks, investigation workflows, and technical documentation • Generate detailed technical reports and executive summaries on complex threats • Provide after-hours escalation support for critical incidents as needed
Minimum Requirements for Information Security Staff III: • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Intelligence Studies, or equivalent experience • 3-5 years in security operations, threat analysis, incident response, or SOC environments • 3+ years in cyber threat intelligence analysis, production, and program management • Proven experience building or managing a CTI program • Strong background in intelligence analysis methodologies, intelligence cycle (collection, processing, analysis, dissemination) & structured analytic techniques • Experience as Tier 2/3 SOC analyst handling complex security incidents • Experience producing intelligence products for various audiences (technical, operational, executive) and briefing stakeholders • Ability to analyze threat actors, track campaigns, and assess adversary capabilities • Advanced proficiency with SIEM platforms (Google SecOps, QRadar, LogRhythm, ArcSight, or similar) including custom query development • Hands-on experience with threat intelligence platforms (TIP) and OSINT tools • Deep understanding of network protocols, traffic analysis, and advanced attack techniques • Extensive log analysis and event correlation experience • Strong knowledge of Windows/Linux systems, forensic artifacts, and attacker techniques • Expertise with EDR platforms and advanced endpoint analysis • Expert-level understanding of MITRE ATT&CK framework • Experience with threat intelligence frameworks (Diamond Model, Cyber Kill Chain) • Advanced network packet analysis skills (Wireshark, tcpdump) • Ability to analyze malicious scripts, PowerShell commands, and malware behavior • Ability to work under pressure and manage multiple complex investigations • Ability to obtain and maintain US Secret clearance (US citizenship required)
Additional Requirements for Information Security Staff IV: • 5-7 years in security operations, threat analysis, incident response, or SOC environments • 5+ years in cyber threat intelligence analysis, production, and program management
How You Can Stand Out • Certifications: GCTI, CTIA, GCIA, GCIH, GCFA, GNFA, GMON, CySA+, CISSP, etc. • Prior experience as CTI Lead, Manager, or Program Owner • Government, military, or defense intelligence background with formal training • Experience developing intelligence requirements and collection strategies • Advanced proficiency with ThreatConnect, Anomali, MISP, Recorded Future • OSINT research, dark web monitoring, and underground forum analysis experience • Malware analysis and reverse engineering skills • Published threat intelligence research or conference presentations • Scripting proficiency (Python, PowerShell, Bash) for automation and analysis • Experience with SOAR platforms • Cloud security op
Tailor your resume for this The Aerospace Corporation role before you apply.
Tailor my resume for this jobSimilar jobs
- Cyber Threat Intelligence Analyst — Intersystems · Boston, MA
- Cyber Threat Analyst — Booz Allen Hamilton · Remote
- Cyber Operations Lead — Accenturefederalservices · Arlington, VA
- Senior Cyber Threat Analyst — Tmhcc · Remote
- Senior Cyber Threat Analyst — Brown Brothers Harriman (BBH) · Boston | Philadelphia
- Senior Cyber Threat Analyst — Brown Brothers Harriman (BBH) · Boston | Philadelphia | Jersey City
- Cybersecurity Threat & Vulnerability Analyst — Hc · Remote
- Cyber Security Analyst Leads – Cyber Threat Hunting — FIS · US FL JAX 347
More like this: Security & Cybersecurity Jobs · Browse all jobs
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)