careertakescareertakes

Cyber Fusion Analyst

Confidential ClientSoftware & Technology
Entry LevelFull-timeOn-Site$114,400 - $124,800
Alexandria, Virginia
16 Hours Ago

The Cyber Fusion Analyst at Confidential Client supports the Security Operations Center (SOC) Fusion mission by proactively analyzing and hunting cyber threats using all-source intelligence and enterprise telemetry. This role involves synthesizing threat data, conducting hypothesis-driven hunts, developing detection logic, and delivering actionable intelligence reports and briefings to leadership. The analyst also provides technical leadership, mentors junior staff, and enhances SOC capabilities through development of SOPs and analytic playbooks, working fully onsite at the Mark Center in Alexandria, VA.

Boost your chances. Upload your resume to see your match score.

Unlock Match Rate
Description

About Careertakes

👉 Important disclosure: Careertakes is a third-party recruiting platform supporting this hiring process. If selected, you will be employed directly by our client, Information Technology Services.

Applicants for this role may also receive access to additional matched opportunities through the Careertakes platform.


Role Overview

Confidential Client is seeking a Cyber Fusion Analyst to support a Security Operations Center (SOC) fusion mission at the Mark Center in Alexandria, VA. This on-site role is focused on threat hunting, cyber threat intelligence, correlation of external intelligence with enterprise telemetry, and delivering concise analytical products and briefings to leadership and mission partners. The team operates primarily Monday–Friday during normal business hours; schedule flexibility may be required for mission support.


Primary Responsibilities

  • Ingest, analyze, and synthesize cyber threat reporting from OSINT, government reporting, commercial threat-intelligence platforms, and authorized sources to identify relevant threats.
  • Correlate external threat intelligence with enterprise telemetry (SIEM, EDR, endpoints, network logs, PCAP, NetFlow, proxy, firewall, IDS/IPS, SSL decryption, session and system logs) to detect and assess malicious activity.
  • Conduct proactive IOC sweeps and hypothesis-driven threat hunts to detect activity tied to emerging campaigns, vulnerabilities, malware, targeted threats, and evasive adversary behavior.
  • Characterize adversary infrastructure, malware, tooling, and TTPs using MITRE ATT&CK, Cyber Kill Chain, and related frameworks; assess risk to enterprise assets and mission operations.
  • Develop hunt plans, adversary profiles, analytic methodologies, detection logic, and complex query strategies; document findings and recommendations in after-action reports (AARs) and required mission products.
  • Develop, validate, and recommend countermeasures (SIEM correlation searches, analytic content, custom signatures, and blocking recommendations); technically vet indicators prior to submitting detection nominations.
  • Produce recurring and ad hoc threat reports, intelligence assessments, executive summaries, situational updates, time-sensitive notifications, and strategic assessments.
  • Translate technical telemetry, forensics, and analytic findings into actionable technical, operational, and executive-level summaries and briefings.
  • Provide threat-context support to incident responders and SOC teams during active investigations; serve as a subject-matter expert on adversary tradecraft.
  • Maintain and improve SOPs, playbooks, hunt methodologies, detection use cases, and knowledge-management artifacts; identify capability gaps and recommend automation and process improvements.
  • Provide technical leadership on complex hunts and investigations and mentor junior analysts.

Minimum (Required) Qualifications

  • Bachelor’s degree in cybersecurity, information technology, computer science, intelligence studies, or a related technical discipline AND 8+ years of relevant experience; equivalent additional experience, training, or certifications may substitute for a degree.
  • 4+ years supporting cybersecurity operations, threat intelligence, threat hunting, incident response, cyber network defense, or closely related missions.
  • Active Top Secret security clearance required.
  • Must meet DoD 8140 IAT Level II baseline certification requirements prior to starting and possess or obtain DoD 8140 CSSP Analyst (CSSP-A) certification within the required program timeframe.
  • Practical experience applying MITRE ATT&CK, Cyber Kill Chain, or similar frameworks to characterize adversary TTPs and attack lifecycles.
  • Hands-on experience performing hypothesis-driven threat hunts, developing detection logic, and pivoting from external threat reporting and IOCs to internal telemetry.
  • Demonstrated ability to query, analyze, and correlate high-volume SIEM, EDR, endpoint, network, NetFlow, packet, and log data.
  • Working knowledge of TCP/IP, common ports/protocols, network traffic flow, OSI model, system administration, defense-in-depth, and enterprise security architecture.
  • Strong written and verbal communication, analytical skills, and ability to produce technical and executive-level reports and briefings.
  • Ability to work 100% onsite at the Mark Center in Alexandria, VA during normal business hours; schedule flexibility may be required.

Preferred Qualifications

  • TS/SCI eligibility (including reciprocal acceptance) preferred.
  • Advanced cybersecurity certifications such as CISSP, CASP+, CySA+, CEH, or GIAC (GCIH, GCIA, GCTI, etc.).
  • Experience supporting DISA, DoD networks, Cyber Security Service Provider (CSSP) operations, Cyber Protection Teams, or large enterprise SOCs.
  • Experience across NIPRNet, SIPRNet, JWICS, cloud, or similarly complex enterprise environments.
  • Familiarity with SIEM, EDR, threat-intel, and network-analysis tools (e.g., Splunk, Elastic, Microsoft Defender for Endpoint, Microsoft Sentinel, VirusTotal, Wireshark, PCAP, NetFlow) and building/tuning detection content and automated enrichment.
  • Malware analysis, digital/network forensics, endpoint telemetry, intrusion detection, vulnerability research, and intelligence-driven defense experience.
  • Familiarity with query languages and scripting (SPL, KQL, Lucene, SQL, Python, PowerShell, Unix/Linux CLI).
  • Experience producing intelligence products and briefings for senior leaders and mentoring junior staff.

Location, Role Type & Compensation

  • Workplace type: Fully onsite at the Mark Center — Alexandria, VA (Alexandria, Virginia).
  • Job type: Contract to Hire (Contractor to direct hire with Confidential Client).
  • Work hours: Primarily normal business hours (the team operates 0600–1800 Monday–Friday); schedule flexibility may be required.
  • Pay range: $55.00 - $60.00 per hour. Individual pay within this range will depend on qualifications, relevant experience, geographic location, and other job-related factors.
  • Application deadline (anticipated): Sep 28, 2026.

Benefits & Additional Information

  • If eligible, benefits for this temporary/contract role may include: medical, dental & vision; critical illness, accident, and hospital coverage; 401(k) plan options; voluntary life & AD&D; short- and long-term disability; HSA; transportation benefits; Employee Assistance Program; and paid time off (eligibility and specifics depend on job classification and length of employment).
  • This role requires an active TS clearance and compliance with program certification requirements (DoD 8140/CSSP-A).
  • Confidential Client and Careertakes comply with applicable US employment laws. Reasonable accommodations are available for applicants with disabilities; please note any accommodation needs when invited to interview.

Experience Level

  • Senior / Experienced — typically 8+ years of relevant experience and 4+ years in cyber operations or threat-hunting roles.

Equal Opportunity & Hiring Transparency

Careertakes and our client are Equal Opportunity Employers committed to building a diverse and inclusive workforce. We prohibit discrimination or harassment of any kind. To support a fair and efficient hiring process, AI tools may be used to assist with application review or resume screening. These tools do not replace human decision-making. Final hiring decisions are made by people.

If you have questions about how your data is used, please contact us directly.

Negotiate a higher salary! Check the salary ranges for this job type in your area.

View My Salary Range