Haystack
← Back to Jobs
Technology
CT

TS / SCI cleared Cyber Threat Analyst

ClearBridge Technology GroupHI🇺🇸United StatesPosted Sep 29, 2026

Quick Overview

Salary
$56 - $81/hr
Seniority
Mid Senior
Work mode
On Site
Location
HI, United States
Posted
14 hours ago
ELKLogstashJiraKibana

Job Description

Our client, a leading Government Systems Integrator, is in need of 6 TS / SCI cleared Cyber Threat Analysts for initial 12 month contracts onsite in Pearl Harbor, HI. The Cyber Threat Analysts will be supporting an enterprise DOD customer working as part of their JFN (Joint Fires Network) SOC team. The JFN team provides specialized threat intelligence synthesis, behavioral anomaly detection and advanced threat hunting to safeguard the customers multi-level classified enclaves. The Cyber Threat Analysts will be responsible for analyzing network telemetry, advanced sensor feeds (Corelight and Darktrace) and syslog audits across up to 30 active operational nodes (including SD-WAN transport fabrics), developing novel behavioral threat hunting playbooks, formulating containment and response strategies in JIRA, etc.
Required Skills:
  • Must have an active TS / SCI clearance.
  • At least 4 years of experience working in Cyber Threat Intelligence, all-source cyber analysis, threat hunting or SOC tier 2 / tier 3 Operations and a Bachelors degree (military experience will suffice if candidates do not have a degree.
  • Prior experience analyzing and correlating network protocol telemetry, NetFlow, proxy logs and raw packet captures to reconstruct complex intrusion paths.
  • Experience querying SIEM platforms, specifically Elasticsearch, Logstash, Kibana (ELK) / Elastic Defend using KQL or Lucene query syntax.
  • Understanding of adversary TTPs, threat actor attribution and operational mapping, ideally using the MITRE ATT&CK framework.
  • Experience writing incident documentation, standard operating procedures and containment playbooks in JIRA.
  • Must hold a valid certification or degree meeting DOD 8140.03 / DCWF Work Role Code 532 Cyber Defense Incident Responder (at the intermediate proficiency level) prior to being onsite.
  • Any of the following certifications, CySA+, GIAC CGTI, EC-C CEH, CND, Security+, etc.

Preferred or Nice to Have Skills:
  • Operational experience analyzing telemetry from Corelight (Zeek), Darktrace, MDR or Palo Alto Advanced Threat Prevention (ATP).
  • Experience utilizing AI prompting tools (Gemini, Grok) to automate threat hunting data collection and indicator extraction.

ClearBridge Technology Group is an Equal Opportunity Employer.
We offer excellent benefits and compensation packages.
The expected hourly rate range for this role is $56 - 81 / hr
The posted range is an estimate, the actual compensation offer will be based on the candidate's experience, skills, qualifications and will be in line with internal equity.

Similar jobs