Cybersecurity Operations Analyst & Cyber Threat Intelligence Lead
The Aerospace Corporation
- Agency: The Aerospace Corporation
- Location: Colorado Springs, CO
- Type: full-time
- Work arrangement: onsite
- Posted: 2026-08-19
- Apply by: 2026-09-21
Job Description
The Aerospace Corporation is the trusted partner to the nation's space programs, solving the hardest problems and providing unmatched technical expertise. As the operator of a federally funded research and development center (FFRDC), we are broadly engaged across all aspects of space- delivering innovative solutions that span satellite, launch, ground, and cyber systems for defense, civil and commercial customers. When you join our team, you'll be part of a special collection of problem solvers, thought leaders, and innovators. Join us and take your place in space.
The Aerospace Corporation seeks an experienced cybersecurity professional to serve as a
Tier 2/3 Cyber Operations Analyst and Lead
our Cyber Threat Intelligence (CTI) program. You'll handle escalated security events, conduct advanced threat analysis, lead complex investigations, and own all aspects of threat intelligence collection, analysis, production, and dissemination. As a SOC subject matter expert, you'll leverage cutting-edge security tools and deep technical expertise to identify, analyze, and mitigate advanced cyber threats while mentoring junior analysts.
Work Model
The selected candidate will be required to work full-time, on-site at our facility in Colorado Springs, CO.
What You'll Be Doing
Cyber Threat Intelligence Program Leadership:
Lead Aerospace's CTI program, establishing strategy, processes, and capabilities
Develop CTI roadmap, define intelligence requirements (PIRs/IRs), and align with organizational risk priorities
Manage relationships with external threat intelligence partners, ISACs/ISAOs, and government agencies
Produce strategic, operational, and tactical intelligence products including threat assessments, adversary profiles, and campaign analysis
Conduct all-source intelligence analysis on threat actors and emerging threats targeting aerospace/defense
Manage threat intelligence platforms (TIP) and establish intelligence workflows
Track and profile APT groups and adversaries relevant to Aerospace's threat landscape
Brief leadership on threat trends, emerging risks, and intelligence-driven recommendations
Establish metrics demonstrating CTI program value and effectiveness
Security Operations & Incident Response:
Serve as Tier 2/3 escalation point for complex security alerts and incidents
Conduct deep-dive investigations into sophisticated threats and APTs
Perform advanced threat hunting leveraging intelligence to guide hypotheses
Analyze security alerts from SIEM, IDS, EDR, and other security technologies
Correlate data from multiple sources to reconstruct attack timelines and identify compromise scope
Lead incident response for escalated events, coordinating containment and remediation
Integrate threat intelligence into detection workflows and develop advanced detection rules
Analyze malware, scripts, and attacker tools to understand adversary TTPs
Mentor Tier 1 analysts and develop their analytical skills
Create advanced playbooks, investigation workflows, and technical documentation
Generate detailed technical reports and executive summaries on complex threats
Provide after-hours escalation support for critical incidents as needed
Minimum Requirements for Information Security Staff III:
Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Intelligence Studies, or equivalent experience
3-5 years in security operations, threat analysis, incident response, or SOC environments
3+ years in cyber threat intelligence analysis, production, and program management
Proven experience building or managing a CTI program
Strong background in intelligence analysis methodologies, intelligence cycle (collection, processing, analysis, dissemination) & structured analytic techniques
Experience as Tier 2/3 SOC analyst handling complex security incidents
Experience producing intelligence products for various audiences (technical, operational, executive) and briefing stakeholders
Ability to analyze threat actors, track campaigns, and assess adversary capabilities
Advanced proficiency with SIEM platforms (Google SecOps, QRadar, LogRhythm, ArcSight, or similar) including custom query development
Hands-on experience with threat intelligence platforms (TIP) and OSINT tools
Deep understanding of network protocols, traffic analysis, and advanced attack techniques
Extensive log analysis and event correlation experience
Strong knowledge of Windows/Linux systems, forensic artifacts, and attacker techniques
Expertise with EDR platforms and advanced endpoint analysis
Expert-level understanding of MITRE ATT&CK framework
Experience with threat intelligence frameworks (Diamond Model, Cyber Kill Chain)
Advanced network packet analysis skills (Wireshark, tcpdump)
Ability to analyze malicious scripts, PowerShell commands, and malware behavior
Ability to work under pressure and manage multiple complex investigations
Ability to obtain and maintain US Secret clearance (US citizenship required)
Additional Requirements for Information Security Staff IV:
5-7 years in security operations, threat analysis, incident response, or SOC environments
5+ years in cyber threat intelligence analysis, production, and program management
How You Can Stand Out
Certifications: GCTI, CTIA, GCIA, GCIH, GCFA, GNFA, GMON, CySA+, CISSP, etc.
Prior experience as CTI Lead, Manager, or Program Owner
Government, military, or defense intelligence background with formal training
Experience developing intelligence requirements and collection strategies
Advanced proficiency with ThreatConnect, Anomali, MISP, Recorded Future
OSINT research, dark web monitoring, and underground forum analysis experience
Malware analysis and reverse engineering skills
Published threat intelligence research or conference presentations
Scripting proficiency (Python, PowerShell, Bash) for automation and analysis
Experience with SOAR platforms
Cloud security operations experience (AWS, Azure, GCP)
Experience in classified or high-security environments
Network security monitoring tools experience (Zeek, Suricata, Snort)
Red team/purple team exercise participation
Analyst mentoring and training experience
Knowledge of compliance frameworks (NIST 800-53, 800-171, CMMC)
Familiarity with IC standards (ICD 203, ICD 206)
We offer a competitive compensation package where you'll be rewarded based on your performance and recognized for the value you bring to our business. The grade-based pay range for this job is listed below. Individual salaries within that range are determined through a wide variety of factors including but not limited to education, experience, knowledge and skills.
(Min - Max)
$107,000.00 - $160,500.00
Pay Basis: Annual
Leadership Competencies
Our leadership philosophy is simple: every employee, regardless of level and role, can demonstrate leadership. At Aerospace, our commitment is our people. To cultivate our talent and ensure that we have a strong pipeline of future leaders, we want individuals who:
Operate Strategically
Lead Change
Engage with Impact
Foster Innovation
Deliver Results
Ways We Reward Our Employees
During your interview process, our team will provide details of our industry-leading benefits.
Benefits vary and are applicable based on Job Type.
A few highlights include:
Comprehensive health care and wellness plans
Paid holidays, sick time, and vacation
Standard and alternate work schedules, including telework options
401(k) Plan - Employees receive a total company-paid benefit of 8%, 10%, or 12% of eligible compensation based on years of service and matching contributions; employees are immediately eligible and vested in the plan upon hire
Flexible spending accounts
Variable pay program for exceptional contributions
Relocation assistance
Professional growth and development programs to help advance your career
Education assistance programs
An inclusive work environment built on teamwork, flexibility, and respect
We are all unique, from various backgrounds and all walks of life, yet one thing bonds all of us to each other-the belief that we can make a difference. This core belief empowers us to do our best work at The Aerospace Corporation.
Equal Opportunity Commitment
The Aerospace Corporation is an
equal opportunity
employer. All qualified applicants will receive consideration for employment and will not be discriminated against on the basis of race, age, sex (including pregnancy, childbirth, and related medical conditions), sexual orientation, gender, gender identity or expression,
color, religion, genetic information,
marital status, ancestry, national origin, protected veteran status, physical disability, medical condition, mental disability, or disability status and any other characteristic protected by state or federal law. If you're an individual with a disability or a disabled veteran who needs assistance using our online job search and application tools or need reasonable accommodation to complete the job application process, please contact us by phone at 310.336.5432 or by email at
peoplemangmnt.mailbox@aero.org
. You can also review
Know Your Rights: Workplace Discrimination is Illegal
.
Newest government jobs in Colorado
- RAL Multi-media lead — Ncar / Ucar
- Full Stack Software Engineer — Peraton
- Applied Mechanical Engineer — NANA Regional Corporation (Akima family)
- Training Assistant IV (MD 31 HQ Support - Active Secret Clearance Required) — NANA Regional Corporation (Akima family)
- Senior Technical Advisor for Space Warfighting Implementation — Johns Hopkins Applied Physics Laboratory (APL)
- Guidance, Navigation & Controls Engineer I — Sierra Space
- MANAGEMENT & PROGRAM ANALYST — Air Force Manpower Analysis Agency
- SECRETARY (OFFICE AUTOMATION) — United States Space Force
- Chief Information Security Officer — Office of the Secretary of the Interior