Quick Summary
Perform initial triage and assessment of incoming cyber threat tickets, incident reports, IOC submissions, and cybersecurity notifications.
U.S. Citizenship. Active TS/SCI security clearance. Ability to obtain and maintain DHS Suitability.
The successful candidate will operate in a role comparable to a Tier 1/Tier 2 SOC Analyst with enhanced Cyber Threat Intelligence (CTI) responsibilities. Analysts are expected to independently research cyber activity, rapidly evaluate technical information, develop defensible analytical conclusions, identify intelligence and information gaps, and recommend appropriate follow-on actions.
This position requires strong technical analysis skills combined with the ability to communicate and coordinate effectively with government organizations, private-sector partners, critical infrastructure stakeholders, and other cybersecurity professionals.
Responsibilities
~2 min readThe JCDC Cyber Triage Analyst will:
- →Perform initial triage and assessment of incoming cyber threat tickets, incident reports, IOC submissions, and cybersecurity notifications.
- →Analyze technical indicators and artifacts including IP addresses, domain names, URLs, file hashes, network traffic patterns, malware artifacts, and related telemetry.
- →Assess the credibility, severity, scope, and potential operational impact of reported cyber activity.
- →Evaluate potential impacts to federal networks and U.S. critical infrastructure sectors.
- →Enrich IOCs using Threat Intelligence Platforms (TIPs), OSINT resources, commercial intelligence sources, and authorized government-exclusive resources.
- →Correlate indicators with known threat actors, campaigns, malware families, vulnerabilities, tactics, techniques, and procedures (TTPs).
- →Develop concise, defensible cyber triage reports containing analytical findings and actionable recommendations.
- →Determine when incidents or threat activity require escalation or additional technical analysis.
- →Route tickets and analytical findings to appropriate JCDC teams, CISA organizations, or interagency partners.
- →Coordinate with sector-specific analysts, incident responders, threat hunters, intelligence analysts, and interagency liaisons to obtain additional technical and operational context.
- →Maintain complete and accurate documentation within ticketing, case management, and knowledge management systems.
- →Participate in operational shift handoffs and daily cybersecurity briefings.
- →Monitor emerging cyber threat campaigns, adversary activity, vulnerabilities, and trends.
- →Support development and continuous improvement of cyber triage playbooks, workflows, and Standard Operating Procedures (SOPs).
- →Provide appropriate feedback to submitters and partner organizations regarding ticket status, findings, and disposition.
- →Support collaboration across geographically distributed government and contractor teams.
Requirements
~2 min readCandidates must meet the following requirements:
- U.S. Citizenship.
- Active TS/SCI security clearance.
- Ability to obtain and maintain DHS Suitability.
- 2–4+ years of progressive cybersecurity experience supporting one or more of the following:
- Security Operations Center (SOC) operations
- Cyber Threat Intelligence (CTI)
- Cyber incident response
- Network security monitoring
- Threat hunting
- Cybersecurity operations
- Demonstrated ability to independently triage and analyze cybersecurity incidents, alerts, threat reports, or intelligence.
- Experience analyzing technical indicators such as IP addresses, domains, URLs, file hashes, network traffic, and malware-related artifacts.
- Experience researching and enriching IOCs using threat intelligence and OSINT resources.
- Ability to assess the severity, credibility, and potential impact of cyber threats.
- Ability to document analytical findings and develop concise, actionable recommendations.
- Strong technical research and analytical reasoning skills.
- Strong written and verbal communication skills.
- Ability to work effectively with government personnel, technical analysts, incident responders, intelligence professionals, and partner organizations.
- Ability to work collaboratively across geographically distributed teams and physical locations.
Highly qualified candidates may possess experience in several of the following areas:
- Previous cybersecurity experience supporting CISA, FBI, NSA, DoD, DHS, or another federal cybersecurity or intelligence organization.
- Understanding of the National Cyber Incident Scoring System (NCISS) and its application to incident prioritization and triage.
- Knowledge of common cyberattack lifecycle stages, including:
- Reconnaissance and footprinting
- Scanning and enumeration
- Initial access
- Privilege escalation
- Persistence
- Network exploitation and lateral movement
- Command and control
- Defense evasion and covering tracks
- Demonstrated ability to recognize and categorize cybersecurity vulnerabilities and associated attack techniques.
- Knowledge of Computer Network Defense (CND) policies, procedures, processes, and regulations.
- Understanding of different operational threat environments, ranging from opportunistic attackers and cybercriminal organizations to sophisticated nation-state actors.
- Knowledge of system and application security threats and vulnerabilities, including:
- Buffer overflows
- Cross-site scripting (XSS)
- SQL/PL-SQL and other injection attacks
- Malicious or mobile code
- Race conditions
- Covert channels
- Replay attacks
- Return-oriented programming/attacks
- Other common application and network exploitation techniques
- Experience working with SIEM platforms, Threat Intelligence Platforms (TIPs), case management systems, and cybersecurity ticketing platforms.
- Familiarity with cyber threat intelligence concepts, adversary TTPs, and IOC lifecycle management.
- Knowledge of U.S. critical infrastructure sectors and associated cyber risks.
- Familiarity with DHS/CISA cybersecurity products, services, alerts, advisories, and operational processes.
- Experience working in an operational SOC, watch floor, incident response center, or cyber fusion environment.
Candidates must possess one of the following:
Nice to Have
~1 min readOne or more of the following certifications is preferred:
- CompTIA Security+
- CompTIA CySA+
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Intrusion Analyst (GCIA)
- GIAC Cyber Threat Intelligence (GCTI)
- Other comparable cybersecurity, incident response, SOC, or threat intelligence certifications
This role is well suited for a cybersecurity professional who can move beyond simply reviewing alerts.
We are looking for analysts who can receive incomplete or ambiguous cyber threat information, independently research the available evidence, determine what is technically significant, identify what information is missing, and develop a defensible recommendation for what should happen next.
Successful candidates should be comfortable operating in a fast-paced cyber operations environment where accurate analysis, concise communication, sound judgment, and timely escalation directly contribute to the protection of federal systems and U.S. critical infrastructure.
Location & Eligibility
Listing Details
- First seen
- September 29, 2026
- Last seen
- September 29, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 56%
- Scored at
- September 29, 2026
Signal breakdown
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.