The Advanced Cyber Threat Analyst performs cyber threat analysis, intelligence research, and investigative support to identify, analyze, and mitigate cyber threats targeting U.S. national interests. The analyst produces intelligence products, conducts malware and network analysis, and supports attribution efforts while advising government personnel on streamlined processes and analytical techniques.
Candidates must possess at least 5 years of related experience in cyber threat analysis, intelligence research, or cybersecurity operations.
None.
- Draft analytical products based on cyber threat analysis and participate in quality control reviews of reporting.
- Conduct allsource research to maintain awareness of emerging cyber threats and trends using JWICS and SCION.
- Communicate and collaborate with FBI offices and Department of Defense partners via JWICS and SCION.
- Conduct malware analysis, including binary analysis and reverse engineering, to determine functionality, complexity, and impact on compromised systems.
- Correlate and analyze digital threat data (e.g., IP addresses, URLs, malware indicators, system logs) from multiple sources to support attribution and investigative leads.
- Analyze network, security, web, O365, and NetFlow logs to identify anomalous behavior and potential cyber intrusion activity.
- Perform cyber threat hunting and analyze intrusion activity, recommending actions to collect, monitor, counteract, or mitigate threats.
- Conduct cyber threat hunting and data analytics using Splunk or similar SIEM platforms.
- Provide investigative and operational leads to support attribution, link analysis, and operational targeting.
- Support TACU mission priorities through tactical and strategic collaboration across FBI programs and intelligence community partners.
- Research, review, and analyze intelligence information to produce tactical analysis supporting operations and threat mitigation.
- Identify and report emerging threats, patterns, intelligence gaps, and anomalies across FBI programs and investigations.
- Integrate intelligence from internal and external sources to enhance operational awareness and investigative outcomes.
- Prepare intelligence products including intelligence notes, briefings, investigative reports, targeting packages, and analytic communications.
- Apply analytical expertise to develop conclusions and recommend investigative or operational actions supporting field office collection strategies.
- Evaluate intelligence collected by agents and collectors, identify reportable intelligence, and prepare Intelligence Information Reports (IIRs) when appropriate.
- Compare new reporting with existing intelligence to assess credibility, corroborate findings, and identify investigative opportunities.
- Identify new investigative targets, relationships, or subjects and disseminate findings to operational teams.
- Compile targeting packages documenting relationships between subjects, persons of interest, and investigative leads.
- Provide briefings to operational teams, leadership, and executive audiences as required.
- Perform additional duties as assigned.
Preferred Qualifications- Experience with threat intelligence platforms (e.g., MISP, Anomali, ThreatConnect).
- Familiarity with SIEM platforms (e.g., Splunk, QRadar, Elastic).
- Experience with malware analysis, reverse engineering, or memory forensics.
- Knowledge of the MITRE ATT&CK framework and threat modeling methodologies.
- Experience producing tactical, operational, and strategic threat assessments.
- Strong written and verbal communication skills for both technical and executive audiences.
- Ability to correlate intelligence from multiple sources to generate actionable insights.
Experience (Required)- Experience analyzing cyber intrusion activities and conducting cyber threat hunting.
- Experience with intelligence research, analysis, and link analysis.
- Experience analyzing network and security logs (e.g., NetFlow, web logs, O365 logs).
- Experience identifying trends, patterns, anomalies, and intelligence gaps.
- Experience exploiting intelligence derived from operational cases or investigations.
- Experience preparing intelligence products such as notes, reports, briefings, and investigative intelligence products.
- Ability to apply analytical expertise to formulate conclusions and recommendations.
- Experience compiling and disseminating targeting packages and investigative leads.
- Ability to brief analytical findings to diverse audiences.
Physical RequirementsThis position primarily involves prolonged periods of sitting and computer use. Candidates must be able to:
- Work at a computer for extended periods.
- Use a keyboard, mouse, and monitor effectively.
- Communicate clearly via phone, video conferencing, and email.
Work Environment / LocationPrimary work location will be at the customer site.
Travel RequiredRegular travel is not required; however, occasional travel may occur for company events, meetings, or customer support activities.
Additional Eligibility RequirementsAt H2L Solutions, Inc., we seek team members who exemplify our core values in both their work and conduct. In addition to meeting the technical qualifications of the position, all candidates must demonstrate the following:
- Commitment to Service: A strong dedication to supporting clients, teammates, and missioncritical objectives, especially in highstakes or fastpaced government environments.
- Positively Overcomes Challenges: Ability to adapt and remain solutionfocused when encountering obstacles, uncertainty, or evolving project requirements.
- Winning and Competitive Spirit: A drive to exceed expectations, deliver exceptional results, and contribute to the continued success and reputation of H2L in the defense and cybersecurity sectors.
- Efficiency and Productivity: Proven ability to manage time effectively, prioritize tasks, and consistently produce highquality work with attention to detail.
- Professionalism in All Aspects: Maintains the highest standards of ethics, accountability, and respectful communication when interacting with clients, colleagues, and stakeholders.
Employees who align with these values will thrive in our mission-driven, team-oriented environment and contribute meaningfully to the success of our customers and our company.
Work Authorization / Security Clearance
- Active TS clearance with SCI eligibility required
- U.S. Citizenship required in accordance with federal contract requirements
- Ability to pass required background checks
About H2L SolutionsH2L Solutions, Inc. is a cybersecurity and IT services provider delivering security, compliance, and technology solutions to government and commercial clients. Headquartered in Huntsville, Alabama, H2L specializes in cybersecurity compliance, risk management, and mission-critical IT services that help organizations protect digital assets and navigate complex regulatory environments.
Our team is committed to innovation, integrity, and operational excellence while supporting critical national security missions.
Compensation and BenefitsSalary is determined based on experience, qualifications, and contract requirements.
H2L offers a competitive benefits package including:- Health, dental, and vision insurance
- 401(k) retirement plan
- Companypaid life insurance
- Short and longterm disability coverage
- Supplemental insurance options
- Professional development and certification support
- Education reimbursement
- Employee referral program
Equal Opportunity EmployerH2L Solutions, Inc. is an Equal Opportunity Employer and federal contractor. We comply with all federal, state, and local nondiscrimination and affirmative action regulations, including Executive Order 11246, Section 503 of the Rehabilitation Act, and VEVRAA.