Jobs and Careers
TH

Cybersecurity Operations Analyst & Cyber Threat Intelligence Lead

The Aerospace Corporation
Colorado Springs, United StatesRemotefull_timeVerifiedPosted 19 Aug 2026
💰 $160,500/yr($107,000/yr$160,500/yr)

About the role

The Aerospace Corporation is the trusted partner to the nation’s space programs, solving the hardest problems and providing unmatched technical expertise. As the operator of a federally funded research and development center (FFRDC), we are broadly engaged across all aspects of space— delivering innovative solutions that span satellite, launch, ground, and cyber systems for defense, civil and commercial customers. When you join our team, you’ll be part of a special collection of problem solvers, thought leaders, and innovators. Join us and take your place in space.

The Aerospace Corporation seeks an experienced cybersecurity professional to serve as a Tier 2/3 Cyber Operations Analyst and Lead our Cyber Threat Intelligence (CTI) program. You'll handle escalated security events, conduct advanced threat analysis, lead complex investigations, and own all aspects of threat intelligence collection, analysis, production, and dissemination. As a SOC subject matter expert, you'll leverage cutting-edge security tools and deep technical expertise to identify, analyze, and mitigate advanced cyber threats while mentoring junior analysts.

Work Model

The selected candidate will be required to work full-time, on-site at our facility in Colorado Springs, CO.

What You'll Be Doing

Cyber Threat Intelligence Program Leadership:

  • Lead Aerospace's CTI program, establishing strategy, processes, and capabilities
  • Develop CTI roadmap, define intelligence requirements (PIRs/IRs), and align with organizational risk priorities
  • Manage relationships with external threat intelligence partners, ISACs/ISAOs, and government agencies
  • Produce strategic, operational, and tactical intelligence products including threat assessments, adversary profiles, and campaign analysis
  • Conduct all-source intelligence analysis on threat actors and emerging threats targeting aerospace/defense
  • Manage threat intelligence platforms (TIP) and establish intelligence workflows
  • Track and profile APT groups and adversaries relevant to Aerospace's threat landscape
  • Brief leadership on threat trends, emerging risks, and intelligence-driven recommendations
  • Establish metrics demonstrating CTI program value and effectiveness

Security Operations & Incident Response:

  • Serve as Tier 2/3 escalation point for complex security alerts and incidents
  • Conduct deep-dive investigations into sophisticated threats and APTs
  • Perform advanced threat hunting leveraging intelligence to guide hypotheses
  • Analyze security alerts from SIEM, IDS, EDR, and other security technologies
  • Correlate data from multiple sources to reconstruct attack timelines and identify compromise scope
  • Lead incident response for escalated events, coordinating containment and remediation
  • Integrate threat intelligence into detection workflows and develop advanced detection rules
  • Analyze malware, scripts, and attacker tools to understand adversary TTPs
  • Mentor Tier 1 analysts and develop their analytical skills
  • Create advanced playbooks, investigation workflows, and technical documentation
  • Generate detailed technical reports and executive summaries on complex threats
  • Provide after-hours escalation support for critical incidents as needed

Minimum Requirements for Information Security Staff III:

  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Intelligence Studies, or equivalent experience
  • 3-5 years in security operations, threat analysis, incident response, or SOC environments
  • 3+ years in cyber threat intelligence analysis, production, and program management
  • Proven experience building or managing a CTI program
  • Strong background in intelligence analysis methodologies, intelligence cycle (collection, processing, analysis, dissemination) & structured analytic techniques
  • Experience as Tier 2/3 SOC analyst handling complex security incidents
  • Experience producing intelligence products for various audiences (technical, operational, executive) and briefing stakeholders
  • Ability to analyze threat actors, track campaigns, and assess adversary capabilities
  • Advanced proficiency with SIEM platforms (Google SecOps, QRadar, LogRhythm, ArcSight, or similar) including custom query development
  • Hands-on experience with threat intelligence platforms (TIP) and OSINT tools
  • Deep understanding of network protocols, traffic analysis, and advanced attack techniques
  • Extensive log analysis and event correlation experience
  • Strong knowledge of Windows/Linux systems, forensic artifacts, and attacker techniques
  • Expertise with EDR platforms and advanced endpoint analysis
  • Expert

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

The Aerospace Corporation

View company profile →