1

Cyber Threat Intelligence Engineer Jobs in Reston, VA

Cyber Threat Intelligence Lead

Reston, VA ยท On-site

$120 - $150/hr

Cyber Threat Intelligence Lead Location: Reston, VA Clearance Level: TS (SCI Eligible) SUMMARY ... Integrates with the detection engineering and threat hunting teams, drive development of signatures ...

Cyber Threat Intelligence Analyst

Lorton, VA ยท On-site

$141K - $236K/yr

The core responsibility of the Cyber Threat Intelligence Analyst is to conduct deep research into social engineering and cyber-attack campaigns and collaborate closely with data scientists ...

Provide Cyber Threat Intelligence support to the clients. * Access and utilize client information and databases in adherence to all client policies, regulations, and procedures. * Expedite the ...

Provide Cyber Threat Intelligence support to the clients. * Access and utilize client information and databases in adherence to all client policies, regulations, and procedures. * Expedite the ...

next page

Showing results 1-20

Cyber Threat Intelligence Engineer information

See Reston, VA salary details

$30.7K

$127K

$205.5K

How much do cyber threat intelligence engineer jobs pay per year?

As of Aug 21, 2026, the average yearly pay for cyber threat intelligence engineer in Reston, VA is $127,036.00, according to ZipRecruiter salary data. Most workers in this role earn between $104,600.00 and $155,500.00 per year, depending on experience, location, and employer.

What is a cyber threat intelligence engineer?

A Cyber Threat Intelligence Engineer is a cybersecurity professional responsible for analyzing, interpreting, and responding to cyber threats facing an organization. They collect and assess data from various sources to identify potential attacks, vulnerabilities, and threat actors. Their work helps organizations anticipate cyber threats, strengthen defenses, and develop effective incident response strategies. They often collaborate with security teams, use specialized tools, and provide actionable intelligence to reduce risk.

What are the key skills and qualifications needed to thrive as a cyber threat intelligence engineer?

To thrive as a Cyber Threat Intelligence Engineer, you need a deep understanding of cybersecurity principles, threat analysis, malware investigation, and often a degree in computer science or related field. Familiarity with threat intelligence platforms, SIEM systems (such as Splunk or QRadar), and certifications like CISSP or GIAC are highly valuable. Analytical thinking, attention to detail, and strong communication skills help you interpret complex data and share actionable intelligence with stakeholders. These skills and qualifications are crucial for proactively identifying and mitigating evolving cyber threats, protecting organizational assets, and informing security strategies.

How does a cyber threat intelligence engineer typically collaborate with other teams to strengthen organizational security?

Cyber Threat Intelligence Engineers work closely with incident response, security operations, and IT teams to ensure timely detection and mitigation of threats. They analyze threat data and share actionable insights, often presenting findings to both technical and executive stakeholders. Regular coordination with these teams is essential for developing threat profiles, updating defense strategies, and responding to emerging vulnerabilities. This collaborative environment helps ensure that intelligence is effectively integrated into the organization's overall security posture.

What is the difference between Cyber Threat Intelligence Engineer vs Cyber Security Analyst?

AspectCyber Threat Intelligence EngineerCyber Security Analyst
Required CertificationsGCTI, CISSP, CEHCISSP, Security+, CEH
Work EnvironmentResearch-focused, threat analysis teamsMonitoring, incident response, security operations
Employer & Industry UsageTech firms, government agencies, cybersecurity companiesFinancial institutions, healthcare, government, private sector

While both roles focus on cybersecurity, the Cyber Threat Intelligence Engineer specializes in analyzing and predicting cyber threats through research and intelligence gathering. The Cyber Security Analyst primarily monitors security systems, responds to incidents, and maintains overall security posture. Understanding these differences helps organizations assign the right talent for specific cybersecurity needs.

What are popular job titles related to Cyber Threat Intelligence Engineer jobs in Reston, VA?

For Cyber Threat Intelligence Engineer jobs in Reston, VA, the most frequently searched job titles are:

What job categories do people searching Cyber Threat Intelligence Engineer jobs in Reston, VA look for?

The top searched job categories for Cyber Threat Intelligence Engineer jobs in Reston, VA are:

What cities near Reston, VA are hiring for Cyber Threat Intelligence Engineer jobs?

Cities near Reston, VA with the most Cyber Threat Intelligence Engineer job openings:

Infographic showing various Cyber Threat Intelligence Engineer job openings in Reston, VA as of August 2026, with employment types broken down into 92% Full Time, 4% Part Time, and 4% Contract. Highlights an 86% Physical, 6% Hybrid, and 8% Remote job distribution, with an average salary of $127,036 per year, or $61.1 per hour.

Cyber Threat Intelligence Analyst

Digital Global Connectors

Mclean, VA โ€ข On-site

$120 - $170/hr

Other

Posted 3 days ago

New


Job description

Cyber Threat Intelligence Analyst

Location: Bethesda, MD (Hybrid; On-site as Required)

Clearance: Tier 2 Public Trust (Required)

Employment Type: Full-Time

Position Summary

Digital Global Connectors (DGC) is seeking an experienced Cyber Threat Intelligence Analyst to support a Federal information security program. The Cyber Threat Intelligence Analyst is responsible for collecting, analyzing, correlating, and disseminating cyber threat intelligence to support enterprise cyber defense, incident response, vulnerability management, and proactive threat mitigation.

This position analyzes threat actor tactics, techniques, and procedures (TTPs), develops actionable intelligence products, monitors the evolving cyber threat landscape, and provides strategic and operational intelligence that enables informed cybersecurity decision-making. The analyst works closely with Threat Hunters, Incident Responders, Security Operations Center (SOC) personnel, Security Engineers, ISSOs, and program leadership to strengthen the organization's cybersecurity posture through intelligence-driven operations.

The successful candidate will possess extensive experience analyzing cyber threats, producing intelligence reports, and applying threat intelligence to improve enterprise detection, prevention, and response capabilities.

Essential Duties and Responsibilities Cyber Threat Intelligence Collection
  • Collect cyber threat intelligence from commercial, open-source, government, and industry information sources.
  • Evaluate intelligence for relevance, credibility, accuracy, and operational value.
  • Monitor emerging cyber threats affecting Federal information systems and critical infrastructure.
  • Identify threat actors, campaigns, malware families, vulnerabilities, and exploit activity.
  • Maintain awareness of evolving cybersecurity trends and adversary capabilities.
  • Support enterprise cyber defense through timely intelligence dissemination.
Threat Analysis
  • Analyze attacker tactics, techniques, and procedures (TTPs).
  • Correlate threat intelligence with enterprise security events and operational risks.
  • Identify indicators of compromise (IOCs) and indicators of attack (IOAs).
  • Evaluate adversary motivations, capabilities, infrastructure, and targeting.
  • Assess threats to enterprise systems, cloud environments, and mission operations.
  • Develop intelligence assessments supporting cybersecurity decision-making.
Intelligence Production

Develop and maintain intelligence products including:

  • Tactical Threat Reports
  • Operational Threat Assessments
  • Strategic Intelligence Reports
  • Threat Actor Profiles
  • Malware Intelligence Reports
  • Vulnerability Intelligence Summaries
  • Executive Intelligence Briefings
  • Indicators of Compromise (IOC) Bulletins
  • Emerging Threat Advisories
  • Intelligence Dashboards

Ensure intelligence products are timely, actionable, technically accurate, and appropriate for both technical and executive audiences.

Intelligence Integration
  • Support Threat Hunters by identifying emerging attacker behaviors and hunting opportunities.
  • Provide actionable intelligence to Incident Responders during active investigations.
  • Assist Security Engineers in improving enterprise detection capabilities.
  • Support Vulnerability Management personnel by prioritizing vulnerabilities based on active threat intelligence.
  • Recommend defensive measures based on current adversary activity.
  • Collaborate with SOC personnel to improve alert fidelity and operational awareness.
Threat Intelligence Platforms

Utilize technologies and intelligence sources including:

  • Microsoft Sentinel
  • Splunk Enterprise Security
  • Microsoft Defender XDR
  • Microsoft Defender Threat Intelligence
  • Recorded Future
  • MISP (Malware Information Sharing Platform)
  • VirusTotal
  • AlienVault Open Threat Exchange (OTX)
  • CISA Known Exploited Vulnerabilities (KEV) Catalog
  • MITRE ATT&CK Framework
  • MITRE D3FEND
  • Open Source Intelligence (OSINT) Platforms
  • Security Information and Event Management (SIEM)

Evaluate and integrate intelligence from multiple sources to support operational decision-making.

Vulnerability Intelligence
  • Analyze newly disclosed vulnerabilities for organizational impact.
  • Assess exploitability and threat activity associated with Common Vulnerabilities and Exposures (CVEs).
  • Monitor active exploitation campaigns.
  • Support prioritization of vulnerability remediation activities.
  • Provide risk-based recommendations to Vulnerability Management teams.
  • Track emerging threats associated with software, hardware, and cloud services.
Threat Hunting Support
  • Develop threat hunting hypotheses based on current intelligence.
  • Recommend new detection use cases and behavioral analytics.
  • Identify opportunities to improve enterprise detection capabilities.
  • Support adversary emulation and purple team exercises.
  • Assist Threat Hunters with intelligence-driven investigations.
Reporting and Documentation

Develop and maintain:

  • Threat Intelligence Reports
  • Threat Actor Profiles
  • Executive Briefings
  • Intelligence Dashboards
  • Indicators of Compromise (IOC) Reports
  • Vulnerability Intelligence Bulletins
  • Malware Intelligence ReportsThreat Trend Analyses
  • Standard Operating Procedures
  • Lessons Learned

Ensure documentation is technically accurate, actionable, and aligned with organizational reporting standards.

Collaboration
  • Coordinate with Threat Hunters, Incident Responders, Digital Forensics Analysts, Security Engineers, ISSOs, Vulnerability Management personnel, SOC Analysts, and Government stakeholders.
  • Participate in cybersecurity working groups and threat intelligence exchanges.
  • Present intelligence findings to technical teams and executive leadership.
  • Support enterprise cybersecurity exercises and operational planning.
  • Promote intelligence sharing across cybersecurity disciplines.
Continuous Improvement
  • Monitor evolving adversary tradecraft and emerging cyber threats.
  • Evaluate new intelligence sources and analytical methodologies.
  • Recommend improvements to enterprise threat intelligence capabilities.
  • Develop repeatable intelligence processes and analytical frameworks.
  • Maintain professional certifications and technical expertise in cyber threat intelligence.
Minimum Qualifications
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Intelligence Studies, Information Systems, or a related discipline.
  • Minimum five (5) years of experience performing cyber threat intelligence analysis or cyber defense operations.
  • Experience producing tactical, operational, and strategic cyber threat intelligence.
  • Experience analyzing threat actors, malware, vulnerabilities, and attacker tactics.
  • Experience utilizing threat intelligence platforms and security monitoring technologies.
  • Strong analytical, research, writing, briefing, and communication skills.
  • U.S. Citizenship required.
  • Ability to obtain and maintain a Tier 2 Public Trust.
Preferred Qualifications
  • Master's degree in Cybersecurity, Intelligence Studies, Information Assurance, or a related discipline.
  • Experience supporting a Federal civilian agency.
  • Experience utilizing the MITRE ATT&CK Framework for intelligence analysis.
  • Experience supporting enterprise cyber defense or Security Operations Center environments.
  • GIAC Cyber Threat Intelligence (GCTI)
  • Certified Threat Intelligence Analyst (CTIA)
  • GIAC Certified Intrusion Analyst (GCIA)
  • CompTIA CySA+
  • Microsoft Certified: Security Operations Analyst Associate (SC-200)
  • Certified Information Systems Security Professional (CISSP) (preferred)
Knowledge, Skills, and Abilities
  • Cyber Threat Intelligence
  • Threat Analysis
  • Threat Hunting Support
  • Threat Actor Profiling
  • Vulnerability Intelligence
  • Malware Intelligence
  • Indicators of Compromise (IOCs)
  • Indicators of Attack (IOAs)
  • MITRE ATT&CK Framework
  • MITRE D3FEND
  • Microsoft Sentinel
  • Splunk Enterprise Security
  • Microsoft Defender XDR
  • Microsoft Defender Threat Intelligence
  • Recorded Future
  • MISP
  • VirusTotal
  • AlienVault OTX
  • CISA Known Exploited Vulnerabilities (KEV)
  • Security Information and Event Management (SIEM)
  • Open Source Intelligence (OSINT)
  • Risk Analysis
  • Executive Briefing Development
  • Technical Writing
  • Microsoft Office Suite
  • ServiceNow
  • Jira
Security Requirements
  • Ability to successfully obtain and maintain a Tier 2 Public Trust investigation.
  • Compliance with all applicable Federal security, privacy, ethics, and information assurance training requirements before receiving system access.
  • Ability to support cybersecurity operations, incident response activities, continuity of operations (COOP), emergency response, and surge support as required.
  • Must maintain strict confidentiality while handling sensitive threat intelligence, operational assessments, investigative findings, and Federal information systems.
  • Ability to analyze complex cyber threats, produce actionable intelligence, communicate findings to technical and executive stakeholders, and strengthen enterprise cyber defense through timely, intelligence-driven recommendations and continuous monitoring of the evolving threat landscape.
#J-18808-Ljbffr