Job Description
The Opportunity:
Support the Security Operations Center by collecting, analyzing, and correlating cyber threat intelligence from a wide range of open‑source, commercial, government, and industry partners. Manage and operationalize ThreatConnect to enrich SOC investigations, identify emerging threats, and maintain high‑quality intelligence workflows. Develop and disseminate actionable intelligence products such as reports, alerts, and briefings to inform SOC operations, leadership, and mission stakeholders. Facilitate intelligence sharing and collaboration across interagency and cross‑industry communities such as ISACs and DHS AIS, ensuring timely exchange of relevant threat information. Contributes to the maturity of the CTI program by conducting annual capability assessments, identifying gaps, and developing strategic roadmaps to enhance intelligence processes, tooling, and integration with SOC operations.
You Have:
2+ years of experience in cyber threat intelligence, SOC support, or incident response, including intelligence analysis or threat research
Experience collecting, analyzing, and correlating intelligence from open and closed sources, including government, commercial, and industry feeds
Experience managing or administering threat intelligence platforms
Knowledge of intelligence sharing frameworks and communities, including ISACs, DHS AIS, or federal information‑sharing programs
Knowledge of cyber threat actor tactics, techniques, and procedures (TTPs) and frameworks such as MITRE ATT&CK
Ability to develop actionable intelligence products such as reports, alerts, and briefings for technical and non‑technical audiences
Ability to brief leadership and produce high‑quality analytic products
Public Trust
Bachelor’s degree
Nice If You Have:
Experience supporting SOC investigations with threat enrichment, indicator analysis, or adversary profiling
Experience with structured analytic techniques used in intelligence analysis
Experience with ThreatConnect playbooks, indicator management, or intelligence lifecycle workflows
Experience conducting CTI program maturity assessments, gap analyses, or roadmap development
Knowledge of Zero‑Trust, EDR technologies, or modern enterprise security architectures
Knowledge of malware analysis fundamentals, network forensics, or threat hunting concepts
Possession of excellent written and verbal communication skills
CompTIA CySA+, GIAC Cyber Threat Intelligence (GCTI), GIAC Open-Source Intelligence (GOSI), Certified Threat Intelligence Analyst (CTIA), CISSP or other relevant industry Certification
Vetting:
Applicants selected will be subject to a government investigation and may need to meet eligibility requirements of the U.S. government client; Public Trust determination is required.
Compensation
At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.
Salary at Booz Allen is determined by various factors, including but not limited to location, the individual’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $62,000.00 to $141,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen’s total compensation package for employees. This posting will close within 90 days from the Posting Date.Identity Statement
As part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.
Work Model
Our people-first culture prioritizes the benefits of flexibility and collaboration, whether that happens in person or remotely.
- If this position is listed as remote or hybrid, you’ll periodically work from a Booz Allen or client site facility.
- If this position is listed as onsite, you’ll work with colleagues and clients in person, as needed for the specific role.
Commitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.