Senior Threat-Warning Analyst with Secret Clearance

CALNET Inc.Fort Bragg, NC
Onsite

About The Position

This position provides proactive CTI support to inform Blue Team detection priorities, drive assessment scoping, prioritize remediation effort, and deliver finished intelligence products to supported commanders, the supported RCC, and ARCYBER. CTI operations shall integrate classified and open-source reporting consistent with the analyst's cleared access (historical baseline: 6–10 daily cyber threat reports analyzed; approximately 1,300 sensor-grid signatures reviewed, activated, modified, or deactivated monthly). This position validates proposed signatures for proper syntax and minimal false positives prior to deployment; all development and signature testing shall be conducted on isolated networks.

Requirements

  • Bachelor’s Degree in an IT field preferred
  • U.S Citizenship and Secret Clearance is required.
  • 5+ years’ IT Infrastructure experience

Responsibilities

  • Conduct persistent collection, aggregation, and analysis of OSINT, commercial threat feeds, ISAC reporting, community intelligence reporting, and Government-Furnished Intelligence (GFI) to identify emerging threats relevant to supported networks.
  • Conduct open-source research to identify commercial exploits, zero-day vulnerabilities, and adversary TTPs requiring DCO action, and integrate findings into the supported environment's detection capability (host-based security, IPS/IDS, SIEM).
  • Develop, test, and recommend host-based and network-based signatures (YARA, Snort, Suricata, Elastic detection logic, custom host-based policies) based on identified adversary tradecraft, and coordinate signature submissions with the ARCYBER signature working group portal for global standardization.
  • Correlate internal sensor data and incident reports against classified and open-source threat reporting to identify campaign patterns and persistent adversary activity, and conduct hypothesis-driven and indicator-based threat hunt missions.
  • Provide tactical DCO integration support when directed, integrating tactical network sensor events and signature analysis into the supported RCC's DCO processes and enabling tactical units to detect, identify, and respond to threats on their networks.
  • Develop and maintain a DCO test lab using a Government-approved commercially leased connection (isolated from NIPRNet) for malware analysis and OSINT collection.
  • Produce and disseminate Threat Intelligence Reports (TIR), Indicator of Compromise (IOC) packages, Request for Information (RFI) responses, and trend analyses; maintain a current intelligence requirements (IR) management process aligned to the supported command's requirements and higher Army echelons.
  • Document and conduct annual test plans for the CTI signature-development pipeline (or as signatures are developed/updated) and conduct monthly DCO-specific internal training, maintaining a Program of Instruction (POI), attendee list, and After-Action Reports (AAR).

Benefits

  • medical
  • dental
  • vision
  • life
  • short- and long-term disability insurances
  • a 401(k)-retirement savings plan
  • generous leave time
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service