Cybersecurity Intelligence Counterintelligence Analyst
Job Description
MANTECH is hiring a Cybersecurity Intelligence Counterintelligence Analyst for an on-site position at Vandenberg Space Force Base, CA, supporting the 630th Cyberspace Squadron. In this role, you will help connect cyber threat intelligence, counterintelligence-informed research, and mission assurance activities to support launch and test range safety networks and related environments.
What You’ll Do
- Perform intelligence research and analysis using authorized intelligence reporting, cyber threat intelligence sources, mission data, open-source information, and other approved repositories relevant to Western Range operations.
- Monitor designated cyber threat intelligence platforms and reporting channels for emerging threats, adversary campaigns, indicators of compromise, technical indications and warnings, suspicious activity, and potential foreign cyber threat indicators impacting mission systems.
- Assist senior analysts with cyber threat analysis, adversary profiling, pattern-of-life analysis, and proactive threat-hunting across designated mission environments.
- Research and document adversary tactics, techniques, and procedures (TTPs), malware, indicators of compromise, cyber infrastructure, targeting patterns, and active cyber campaigns; identify analytic gaps and elevate significant findings to senior analysts and designated government personnel.
- Support intelligence requirements, collection planning, and information-gap management with mission-planning cells, range operators, cybersecurity personnel, and authorized intelligence partners.
- Draft, review, and maintain intelligence products and analytic records, including threat summaries, assessments, indications-and-warning products, briefing materials, executive summaries, technical reports, Requests for Information (RFIs), intelligence databases, production trackers, and source-reference documentation.
- Support Mission Area Intelligence Preparation of the Battlefield (IPB) reassessments and weekly intelligence briefings through research, validation, updates to source material, identification of adversary trends, and preparation of leadership presentation materials.
- Support analysis and exercise activities affecting mission-critical systems, including SCADA, industrial control systems, operational technology, and electrical distribution infrastructure, including threat-emulation activities, cyber exercises, post-action validation, lessons learned, and recommended cyber-hardening actions.
Required Qualifications
- Bachelor’s degree in Cybersecurity, Intelligence, IT, Engineering, or a related field; an additional 4 years of relevant experience may be substituted for a degree.
- 2+ years of relevant experience in intelligence analysis, cyber threat intelligence, cybersecurity operations (including defensive or security operations), threat analysis, counterintelligence support, military operations, or a related field.
- Foundational knowledge of cyber threat intelligence, intelligence requirements, collection management, intelligence production, analytic reporting, defensive cyberspace operations concepts, adversary TTPs, indicators of compromise, malware, and cyber campaign reporting.
- Ability to research cyber threats, produce intelligence summaries and briefings, identify analytic gaps, and escalate critical findings.
- Must meet applicable Department of War 8140.3 Cybersecurity Workforce Qualification Requirements, Basic Level, for the assigned labor category and work role.
Technologies and Tools
- Mission Area Intelligence Preparation of the Battlefield (IPB)
- Supervisory Control and Data Acquisition (SCADA)
- Industrial control systems
- Operational technology
- Defensive Cyber Operations–Space (DCO-S)
- Manticore
- Kraken
Clearance and Physical Requirements
- Clearance: Current Top Secret/Sensitive Compartmented Information (TS/SCI) clearance required.
- Willingness to travel within the organizational area of responsibility, including air and ground transportation, as required.
- Ability to remain in a stationary position approximately 50 percent of the time using standard or adjustable desks and chairs in secure work environments.
- Occasionally move about office and technical work areas to access files, systems, equipment, and other mission-support resources.
- May support cyber exercises, operational briefings, incident-driven activities, and other mission requirements outside normal business hours.
Preferred Qualifications
- Experience supporting United States Space Force, Department of War, intelligence community, space-launch, range-operations, cybersecurity, or critical-infrastructure missions.
- Experience supporting cyber threat intelligence, defensive cyberspace operations, security operations centers, incident response, cyber threat hunting, or intelligence-production activities.
- Familiarity with Mission Area IPB, intelligence requirements management, collection planning, or Joint Planning Process concepts.
- Familiarity with Defensive Cyber Operations–Space (DCO-S) tools, including Manticore and Kraken, and intelligence and counterintelligence collection tools and resources.
- Familiarity with SCADA systems, industrial control systems, operational technology, critical infrastructure, or mission-support infrastructure, including experience supporting cyber exercises, threat emulation, adversary-replication activities, or post-action validation assessments.