Cyber Threat Intelligence Analyst - Hickam Afb
Core
Proactive threat hunting, incident response, and advanced detection strategy development for government and commercial clients.
Role type
Senior Cyber Threat Intelligence Analyst
Builds
Custom SIEM/IDS rules, dashboards, and monitoring content
Domain
Cybersecurity / Threat Intelligence / Defense
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
Threat hunting, incident response, log correlation, EDR platform proficiency, SIEM rule creation, security architecture knowledge, threat actor engagement, technical documentation, team mentoring
Preferred skills
CE certification, deep/dark web tracking, phishing/DDoS/ransomware analysis
Technologies
Cloud, Firewall, Network Security, Web, DevOps, Support
Responsibilities
Conduct proactive threat hunts to detect suspicious activities prior to escalation; Review and correlate logs from firewalls, hosts, EDR, IDS/IPS, and other internal systems; Respond to RFIs and conduct targeted investigations using available tools; Investigating alerts, anomalies, and malicious activity using EDR platforms; Creating custom SIEM and IDS rules/signatures to enhance detection capabilities; Executing incident handling tasks including triage, response, documentation, and lessons learned; Educating clients on threats and advising on security best practices; Tracking and engaging with threat actors across clear, deep, and dark web; Building dashboards, alerts, and monitoring content within SIEM and other security platforms; Continuously refining detection content to bolster SOC operations; Crafting and managing technical documentation, detection strategies, and monitoring processes; Identifying detection gaps and suggesting improvements; Mentoring SOC analysts and guiding team members in security practices; Developing strategies for incident handling and coordinating security breach responses