Description
We have a job opportunity for a Cyber Intelligence Fusion Analyst on the DISA GSM-O Penetration Handling, Incident, System Health (PHISH) Support Services II program. This position supports the Security Operations Center (SOC) Fusion mission at the Mark Center, Alexandria, Virginia. The team operates 100% onsite at the Mark Center during normal business hours, Monday through Friday, 0600-1800.
Position Summary
The Cyber Intelligence Fusion Analyst serves as the proactive analysis and threat-hunting engine for the SOC. The analyst synthesizes all-source threat reporting to conduct structured threat hunts, perform proactive environment sweeps, and deliver tailored analytical reports and briefings to leadership.
The position combines cyber operations, threat intelligence, and analytic tradecraft to identify, characterize, and mitigate threats affecting tenants and subscribers throughout the National Capital Region. Responsibilities include correlating external intelligence with enterprise telemetry, mapping adversary TTPs, recommending detections and countermeasures, and providing threat @context during incident investigations across classified, unclassified, and cloud environments.
Primary Responsibilities
· Ingest, analyze, and synthesize cyber threat reporting from OSINT, government reporting, commercial threat-intelligence platforms, and other authorized sources to identify threats relevant to the environment.
· Correlate external threat intelligence with enterprise SIEM, EDR, endpoint, network, packet capture (PCAP), NetFlow, proxy, firewall, IDS/IPS, SSL decryption, session, and system-log telemetry to identify and assess malicious activity.
· Conduct proactive IOC sweeps and hypothesis-driven threat hunts to identify activity associated with emerging adversary campaigns, vulnerabilities, malware, targeted threats, and stealthy or evasive adversary behavior.
· Characterize adversary infrastructure, malware, tooling, and TTPs using MITRE ATT&CK, Cyber Kill Chain, and other applicable threat-modeling frameworks; assess potential risk to enterprise assets, tenants, and mission operations.
· Develop hunt plans, adversary profiles, analytic methodologies, detection logic, and complex query strategies; plan, coordinate, and execute ad hoc threat hunts; document findings and recommendations in AARs; and other required mission products.
· Develop, validate, and recommend countermeasures, including SIEM correlation searches, analytic content, custom signatures, and blocking recommendations, to improve prevention, detection, and response to known adversarial TTPs; technically vet suspicious indicators before submitting detection or blocking nominations.
· Produce recurring and ad hoc threat reports, intelligence assessments, executive summaries, situational-awareness updates, time-sensitive threat notifications, and strategic threat assessments.
· Translate technical telemetry, forensics, intelligence reporting, and analytic findings into clear, actionable technical, operational, and executive-level summaries; prepare and deliver recurring and on-demand briefings to leadership, tenant organizations, and mission partners.
· Serve as a subject matter expert on adversary tradecraft and provide threat @context, intelligence support, and analytic recommendations to incident responders and other SOC teams during active investigations.
· Develop and maintain SOPs, work instructions, hunt methodologies, analytic playbooks, detection use cases, and knowledge-management artifacts; identify capability and workflow gaps, recommend improvements, and enhance automation for enrichment, case management, reporting, dashboards, and metrics.
· Provide technical leadership on complex hunts and investigations; mentor junior analysts and contribute to team training and professional development.
Required Qualifications
· Bachelor's degree in cybersecurity, information technology, computer science, intelligence studies, or a related technical discipline and 8+ years of relevant experience; additional relevant experience, cybersecurity education, or industry certifications may be substituted for a degree.
· 4+ years of experience supporting cybersecurity operations, cyber threat intelligence, threat hunting, incident response, cyber network defense, or a closely related cyber mission.
· Active Top Secret security clearance.
· Must meet DoD 8140 IAT Level II baseline certification requirements before starting work and possess, or obtain and maintain within the required program timeframe, a DoD 8140 CSSP Analyst (CSSP-A) certification.
· Demonstrated experience applying MITRE ATT&CK, Cyber Kill Chain, or comparable frameworks to characterize adversary activity, TTPs, attack lifecycles, vulnerabilities, malware behaviors, and indicators.
· Hands-on experience conducting hypothesis-driven threat hunts, developing detection logic and analytic queries, and pivoting from external threat reporting, IOCs, and OSINT to internal enterprise telemetry.
· Demonstrated experience querying, analyzing, and correlating high-volume SIEM, EDR, endpoint, network, NetFlow, packet, log, and other host- or network-based security data; working knowledge of TCP/IP, common ports and protocols, network traffic flow, OSI model, system administration, defense-in-depth, and enterprise security architecture.
· Strong written, verbal, analytical, and collaboration skills, including the ability to produce technical and executive-level reports and briefings; ability to work independently, manage competing priorities, and work effectively with technical and non-technical mission partners.
· Ability to work 100% onsite at the Mark Center during normal business hours; schedule flexibility may be required to support mission requirements.
Preferred Qualifications
· TS/SCI eligibility, including eligibility for reciprocal acceptance, preferred.
· Advanced cybersecurity certifications, such as CISSP, CASP+, CySA+, CEH, GIAC GCIH, GCIA, GCED, GCTI, or comparable credentials.
· Experience supporting DISA, Department of Defense networks, Cyber Security Service Provider operations, Cyber Protection Teams, or a large enterprise SOC.
· Experience conducting threat hunting and cyber investigations across NIPRNet, SIPRNet, JWICS, cloud, commercial, or similarly complex enterprise environments.
· Experience using SIEM, EDR, threat-intelligence, and network-analysis tools-such as Splunk, Elastic, Microsoft Defender for Endpoint, Microsoft Sentinel, Google Threat Intelligence, VirusTotal, Wireshark, PCAP, and NetFlow-to develop or tune correlation searches, detection rules, signatures, threat blocks, analytic queries, dashboards, and automated enrichment workflows.
· Familiarity with commercial threat-intelligence platforms; malware analysis; digital and network forensics; endpoint telemetry; intrusion detection; vulnerability research; cloud security; and intelligence-driven defense methodologies, including MITRE ATT&CK and Cyber Kill Chain.
· Familiarity with query languages and scripting tools, such as SPL, KQL, Lucene, SQL, Python, PowerShell, and Unix/Linux command-line utilities.
Experience producing intelligence products, operational reports, and executive briefings for executives, General Officer/Flag Officer, Executive Service, or equivalent leadership; demonstrated ability to lead complex cyber investigations or threat hunts and mentor junior technical staff
Experience Level
Entry Level
Job Type & Location
This is a Contract to Hire position based out of Alexandria, VA.
Pay and Benefits
The pay range for this position is $55.00 - $60.00/hr.
Individual compensation offered for this position within this range will depend on many factors, including qualifications, skills, relevant experience, job knowledge, geographic location, internal equity, and other pertinent job-related factors.
Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms. If eligible, the benefits available for this temporary role may include the following: - Medical, dental & vision - Critical Illness, Accident, and Hospital - 401(k) Retirement Plan - Pre-tax and Roth post-tax contributions available - Life Insurance (Voluntary Life & AD&D for the employee and dependents) - Short and long-term disability - Health Spending Account (HSA) - Transportation benefits - Employee Assistance Program - Time Off/Leave (PTO, Vacation or Sick Leave)
Workplace Type
This is a fully onsite position in Alexandria,VA.
Application Deadline
This position is anticipated to close on Sep 28, 2026.
About TEKsystems
We're partners in transformation. We help clients activate ideas and solutions to take advantage of a new world of opportunity. We are a team of 80,000 strong, working with over 6,000 clients, including 80% of the Fortune 500, across North America, Europe and Asia. As an industry leader in Full-Stack Technology Services, Talent Services, and real-world application, we work with progressive leaders to drive change. That's the power of true partnership. TEKsystems is an Allegis Group company.
The company is an equal opportunity employer and will consider all applications without regards to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.
About TEKsystems and TEKsystems Global Services
We're a leading provider of business and technology services. We accelerate business transformation for our customers. Our expertise in strategy, design, execution and operations unlocks business value through a range of solutions. We're a team of 80,000 strong, working with over 6,000 customers, including 80% of the Fortune 500 across North America, Europe and Asia, who partner with us for our scale, full-stack capabilities and speed. We're strategic thinkers, hands-on collaborators, helping customers capitalize on change and master the momentum of technology. We're building tomorrow by delivering business outcomes and making positive impacts in our global communities. TEKsystems and TEKsystems Global Services are Allegis Group companies. Learn more at TEKsystems.com.
The company is an equal opportunity employer and will consider all applications without regard to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.
San Francisco Fair Chance Ordinance: Pursuant to the San Francisco Fair Chance Ordinance, for all positions located in the city and county of San Francisco, we will consider for employment qualified applicants with arrest and conviction records.
Massachusetts Lie Detector: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Use of Artificial Intelligence (AI): We may use Artificial Intelligence (AI) to support parts of our hiring process, including sourcing, screening, and evaluating candidates. AI helps assess applications and qualifications, but final decisions are made by our hiring team. By applying, you acknowledge and agree that your application may be reviewed using AI tools.