Tharros is seeking a Cyber Threat Analyst to support the DoD Cyber Crime Center (DC3). This position provides cyber threat intelligence analysis, proactive threat hunting, malware triage support, and analytical reporting.
The Cyber Threat Analyst will analyze cyber threat activity, identify indicators of compromise (IOCs), develop actionable intelligence products, and support collaborative cyber defense operations by integrating intelligence from open-source, commercial, and internal data sources. This role works closely with cyber operations, digital forensics, and partner organizations to identify emerging threats, support incident response, and enhance threat detection capabilities.
- Produce cyber threat intelligence reporting identifying emerging threat actors, campaigns, malware, vulnerabilities, and indicators of compromise impacting Defense Industrial Base organizations.
- Conduct proactive threat hunting activities by analyzing network traffic, endpoint telemetry, and security event data to identify malicious activity and previously unknown threats.
- Analyze adversary tactics, techniques, and procedures (TTPs) using frameworks such as MITRE ATT&CK to develop actionable intelligence products.
- Correlate intelligence from open-source intelligence (OSINT), commercial threat feeds, and internal reporting to enrich threat assessments and identify intelligence gaps.
- Perform indicator analysis, IOC enrichment, suspicious file triage, and malware submission analysis to support cyber investigations.
- Support cyber forensic investigations through evidence coordination, compromised media intake, and collaboration with forensic laboratories.
- Develop technical intelligence reports, threat assessments, and executive-level analytical products to support cybersecurity decision-making.
- Assist in the development and enhancement of threat intelligence platforms, data analytics workflows, and automated intelligence processes.
- Collaborate with cyber analysts, incident responders, and intelligence professionals to improve threat detection, investigation, and mitigation efforts.
- Maintain accurate documentation, analytical products, and intelligence records in accordance with established DCISE tradecraft and reporting standards.
- Support cyber information sharing activities with Defense Industrial Base partners by providing timely, actionable threat intelligence and defensive recommendations.
- Contribute to the continuous improvement of cyber threat intelligence methodologies, standard operating procedures, and analytical best practices.