Location: Chantilly, Virginia, USA
Remote Work: No
Job Number: R0167771
Cyber Threat Analyst, Mid
Are you looking for an opportunity to investigate the most pressing cyber events impacting national security and everyday victims? Are you driven by dismantling a cyber actor’s ability to harm victim systems? As a cyber threat intel analyst, you know that quality, risk-based threat intel mapped to a tactical behavior is the key to successfully detecting, deterring, and investigating malicious activity. This is your chance to take on the adversary’s perspective, identify their motivations, and recommend ways to harden systems, reduce their attack surface and thwart malicious actors.
On our team, you’ll be trusted to collect, document, assess and analyze raw cyber threat information using tools and technologies, including FireEye, LookingGlass, MITRE Attack Framework, Linux, UNIX, and tcpdump to enrich intelligence. You’ll conduct strategic assessments on systems and networks, provide tactical analyses and influential recommendations for network operation. You’ll be the key to discovering and correlating timely threat intel, deciphering what represents a real risk and play an active role in cyber investigations and intelligence dissemination to inform policy makers, cyber operators, and mission area leadership.
Cyber threats are evolving. Booz Allen is committed to creating an environment where you not only keep pace with the industry, but propel it forward so we can stay ahead of threat actors. With access to academic programs, certifications, mentorship, and opportunities to use expert tradecraft, we’ll continuously invest in you so you can create the career you want as you grow. Booz Allen is your cyber career destination.
Join us. The world can’t wait.
4+ years of experience in a Cybersecurity role, including cyber intelligence, cyber threat analysis, incident response, cyber investigations, malware analysis, or network forensics
Knowledge of intelligence gathering principles, policies, and procedures, including legal authorities and restrictions
Knowledge of cyber threat intelligence models, including MITRE ATT&CK, Kill Chain, and Diamond Model
Knowledge of network security architecture concepts, including topology, protocols, components, principles, and well-known networking protocols and services, including FTP, HTTP, SSH, SMB, and LDAP
Ability to vet, enrich, and maintain technical data, including indicators of compromise, shared from partner agencies and key stakeholders
Ability to extract threat data, including IPs, domains, ports, malware, and malicious communications from multiple sources
TS/SCI clearance with a polygraph
Nice If You Have:
Experience with Python
Experience with Elasticsearch, Logstash, and Kibana (ELK) Stack
Experience with Packet analysis tools, including tcpdump, Wireshark, and ngrep
Experience with Splunk
Experience with alternate scripting or programming languages, including Bash scripting, Perl, and Java
Ability to think and work independently with minimal supervision
Ability to communicate and present to a variety of internal and external audiences, including senior executives
Ability to prioritize and execute in a methodical and disciplined manner
Ability to lead staff and processes
Possession of excellent verbal and written communication skills
Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; TS/SCI clearance with polygraph is required.
Build Your Career:
Rewarding work, fun challenges, and a ton of investment in our people—that’s Booz Allen cyber. When you join Booz Allen, we’ll help you develop the career you want.
Competitions — From programming competitions at our PyNights (Python competition and learning events) to competing in CTFs, we’ve got plenty of chances for you to show off your skills.
Paid Research — Have an innovative idea to explore or hypothesis to test? You can participate in challenges via our crowdsourcing platform, the Garage, and other programs to be awarded dedicated time and/or funding to advance your skills.
Cyber University — CyberU has more than 5000 instructor-led and self-paced cyber courses, a free online library that you can access from just about anywhere—including your phone—and certification exam prep guides that include practical assessments to prepare you for your exam.
Academic Partnerships — In addition to our tuition reimbursement benefit, we’ve partnered with University of Maryland University College to offer two graduate certificate programs in cybersecurity—fully funded without a tuition cap.
Maker/Hackerspaces — Race drones, print 3D gadgets, drink coffee from our Wi-Fi coffee maker, and get hands-on training on tools and tech from in-house experts in our dedicated maker and hackerspaces.
At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.
Salary at Booz Allen is determined by various factors, including but not limited to location, the individual’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $58,400.00 to $133,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen’s total compensation package for employees.
Our people-first culture prioritizes the benefits of flexibility and collaboration, whether that happens in person or remotely.
If this position is listed as remote or hybrid, you’ll periodically work from a Booz Allen or client site facility.
If this position is listed as onsite, you’ll work with colleagues and clients in person, as needed for the specific role.
We’re an equal employment opportunity/affirmative action employer that empowers our people to fearlessly drive change – no matter their race, color, ethnicity, religion, sex (including pregnancy, childbirth, lactation, or related medical conditions), national origin, ancestry, age, marital status, sexual orientation, gender identity and expression, disability, veteran status, military or uniformed service member status, genetic information, or any other status protected by applicable federal, state, local, or international law.
Booz Allen / Equal Opportunity Employer
Top Secret with Polygraph Required, CLZTS, CLZCI, SKINT, SKCYB, — SKUUU, Chantilly,Virginia, USA Chantilly,Virginia, USA ZC ZCCX