Cyber Analysis Lead - Security Clearance Required
Listed on 2025-12-09
-
IT/Tech
Cybersecurity, Information Security
Overview
ICF is seeking an experienced Cyber Analysis Lead to support a Defense Human Resources Activity (DHRA) cybersecurity program. In this role, you will lead a team of cyber analysts responsible for threat analysis, vulnerability assessments, and security monitoring across multiple DHRA systems. The Cyber Analysis Lead develops and implements advanced cyber defense strategies, mentors analysts in tradecraft and tool usage, and delivers actionable risk-reduction recommendations to improve the agency’s security posture.
LocationWork will be performed on-site in Seaside, CA or Alexandria, VA.
What You’ll Do- Lead and direct cybersecurity analysts performing threat detection, analysis, and incident triage across DHRA networks and systems.
- Develop and maintain enterprise security monitoring strategies, procedures, and data analytics to detect anomalies and emerging threats.
- Oversee daily and strategic cyber defense operations, ensuring alignment with DoD and DHRA cybersecurity policies.
- Guide vulnerability assessment and management activities, including scanning, prioritization, remediation tracking, and reporting.
- Mentor and train analysts on cybersecurity tools, threat intelligence integration, and analytic methodologies.
- Correlate threat intelligence, vulnerability data, and incident information to provide risk-based recommendations to leadership.
- Collaborate with SOC, RMF, and IT Operations teams to ensure coordinated defense-in-depth and response readiness.
- Prepare analytic reports and dashboards summarizing trends, key metrics, and security posture improvements.
- Support cyber exercises, tabletop reviews, and after-action analyses to strengthen monitoring and incident response processes.
- Continuously evaluate and recommend new technologies, tools, and processes to enhance analytic capabilities.
- Bachelor’s degree in a technical discipline (or related field).
- A minimum 10 years of progressively responsible experience in cybersecurity operations, threat analysis, or incident response roles.
- Demonstrated ability to lead cyber defense or analysis teams in a DoD or Federal environment.
- Experience with SIEM platforms, network monitoring tools, and vulnerability management systems.
- Proficiency in interpreting MITRE ATT&CK, STIGs, and DoD cyber threat frameworks.
- An active US Government issued security clearance.
- Due to contract requirements, US citizenship is required.
- A current certification is required in at least one of the following:
- CISSP
- CASP
- Elastic/Splunk certifications
- Master’s degree in cybersecurity, computer science, or information systems.
- Experience supporting DoD Cyber Operations Centers or mission partner environments.
- Hands-on experience with Splunk, Elastic, Tenable, or comparable SIEM and vulnerability platforms.
- Strong understanding of NIST 800-53, DoD Cloud SRG, and threat-hunting methodologies.
- Experience integrating cyber threat intelligence feeds into operational workflows.
- Excellent analytical, communication, and leadership skills, with the ability to brief senior stakeholders on complex threats and mitigations.
ICF is a global advisory and technology services provider, but we’re not your typical consultants. We combine unmatched expertise with cutting-edge technology to help clients solve their most complex challenges, navigate change, and shape the future.
We can only solve the world s toughest challenges by building a workplace that allows everyone to thrive. We are an equal opportunity employer. Together, our employees are empowered to share their expertise and collaborate with others to achieve personal and professional goals. For more information, please read our EEO policy.
We will consider for employment qualified applicants with arrest and conviction records.
Reasonable Accommodations are available, including, but not limited to, for disabled veterans, individuals with disabilities, and individuals with sincerely held religious beliefs, in all phases of the application and employment process. To request an accommodation, please email c and we will be happy to assist. All information you provide will be kept confidential and will be…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).