About this role
Join the cyber-fusion team defending the nation's classified networks and Top-Secret mission systems. As a Cyber-Fusion Analyst, you'll operate at the intersection of cyber operations and intelligence, providing critical threat intelligence and incident response support to protect DoD, Intelligence Community, and Combatant Command networks at the highest classification levels.
Your Mission
Classified Threat Intelligence Operations:
- Monitor and analyze the global cyber threat landscape using classified Intelligence Community reporting, DoD intelligence products, and open-source intelligence to identify threats targeting TS/SCI networks and mission systems
- Synthesize complex, multi-source intelligence into actionable products for senior leadership and operational teams defending classified infrastructure
Develop comprehensive threat intelligence products including:
- Nation-state and APT threat profiles with classified attribution and capability assessments
- Monthly and quarterly intelligence assessments on threats to classified networks
- Strategic intelligence reports on adversary campaigns targeting sensitive DoD and IC systems
- Leverage classified intelligence sources to provide early warning of threats to Top Secret mission operations
Operational Cyber Defense:
- Provide real-time threat intelligence support during active incidents on classified networks
- Support continuous threat hunting operations to proactively identify adversary presence in TS/SCI environments
- Conduct threat and vulnerability analysis specific to classified network architectures and mission systems
- Develop security advisories and tactical recommendations for protecting sensitive, compartmented information systems
- Disseminate time-sensitive threat intelligence to DISA, mission partners, and Intelligence Community stakeholders through classified channels
Intelligence Community Collaboration:
- Serve as a liaison between cyber operations and Intelligence Community partners
- Participate in classified threat intelligence sharing initiatives and working groups
- Contribute to all-source intelligence fusion efforts combining SIGINT, HUMINT, and cyber threat data
- Apply advanced analytical frameworks (MITRE ATT&CK for ICS, Cyber Kill Chain, Diamond Model) to classified threat analysis
Platform & Capability Development:
- Contribute to the development and enhancement of classified Threat Intelligence Platforms
- Identify patterns and anomalies in complex, multi-source datasets from classified networks
- Develop new analytical methods and intelligence products tailored to TS/SCI mission requirements
- Mentor team members and foster a collaborative intelligence-sharing culture
What You Bring
Required Qualifications:
- Active Top-Secret clearance
- Current DoD 8570 IAT Level II baseline certification (Security+ CE or higher)
Strong understanding of:
- Network protocols, operating systems, and the OSI model
- Security technologies deployed in classified environments
- Classified network architectures and security requirements
Exceptional written and verbal communication skills, including:
- Ability to produce clear, concise intelligence reports and briefings for senior leadership
- Experience presenting complex threat information to diverse audiences including flag officers and SES-level officials
Advanced analytical skills:
- Pattern recognition and anomaly detection in complex, multi-source datasets
- Logical reasoning and intelligence-driven analysis
- Critical thinking applied to ambiguous threat scenarios
- Experience gathering and analyzing intelligence from open-source, commercial, and classified sources
- Proven ability to collaborate effectively with Intelligence Community partners and joint cyber teams
Highly Desired Qualifications:
- 4+ years of experience in cyber threat intelligence analysis, threat hunting, or incident response within classified environments
- Experience working with Intelligence Community partners on threat intelligence sharing and fusion initiatives
- Hands-on experience with malware analysis tools and techniques (static and dynamic analysis)
- Proficiency with Threat Intelligence Platforms (ThreatConnect, Anomali, MISP, or similar)
Deep knowledge of intelligence-driven frameworks:
- MITRE ATT&CK (Enterprise, ICS, Mobile)
- Cyber Kill Chain
- Diamond Model of Intrusion Analysis
- F3EAD targeting methodology
- Experience analyzing nation-state threat actors and Advanced Persistent Threats (APTs)
- Understanding of Intelligence Community Directives (ICDs) and intelligence oversight requirements
- Familiarity with SIGINT, HUMINT, or GEOINT integration with cyber threat intelligence
- Advanced certifications: GCTI, GCIA, GCFA, CISSP, or GIAC
Why This Role Matters
You'll be part of a team protecting the nation's most sensitive networks and mission-critical systems. Your intelligence analysis will directly support:
- Combatant Command operations in contested cyber environments
- Intelligence Community missions requiring the highest levels of security
- National security decision-making at the strategic level
- Warfighter protection through advanced threat intelligence
If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.
##
##
## Original Posting:
September 29, 2026
For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
## Pay Range:
Pay Range $87,100.00 - $157,450.00
The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.