Senior Cyber Security Analyst (CAAT)
Fa Etbx Saasfaprod1 · Vienna, VA, United States
About The Role
Navy Federal Credit Union currently does not provide sponsorship for this role. Applicants must be authorized to work in the United States without the need for current or future sponsorship.
The Sr Cyber Security Analyst serves as a subject-matter expert on the Cyber Advanced Analysis Team (CAAT), whose mission is to identify and disrupt cyber-enabled threats targeting Navy Federal members. This role leads all-source intelligence analysis across open-source, social media, deep web, and dark web collection to detect, attribute, and disrupt phishing, smishing, vishing, brand abuse, telecom fraud, and impersonation campaigns before they cause financial or reputational harm.
As a senior member of a small, high-impact team, this analyst sets the tradecraft standard, drives complex and escalated investigations end-to-end, produces executive-ready intelligence, and mentors junior analysts. The role spans CAAT’s mission pillars — Brand Abuse & Telecommunications Fraud, Deep & Dark Web Hunting, and Cybercrime Investigations / OSINT — and collaborates with stakeholders across multiple business units.
- Lead advanced, all-source intelligence analysis for complex and escalated cyber-enabled fraud events, applying structured analytic techniques to mitigate bias and reach defensible assessments.
- Detect and disrupt threat actor infrastructure — phishing/smishing domains, malicious phone numbers, impersonation accounts, and rogue mobile apps — coordinating takedowns with vendors and industry partners.
- Perform threat actor attribution through persona-based collection and managed-attribution tradecraft, pivoting across domains, usernames, phone numbers, images, and breach data.
- Identify and characterize persistent and emerging threat actor TTPs and map them to the FS-ISAC Cyber Fraud Prevention Framework and MITRE ATT&CK.
- Produce executive-ready intelligence products — strategic lookbacks, threat-actor profiles, RFI responses, and tactical reports — using BLUF writing, clear key judgments, source summaries, and documented intelligence gaps.
- Present findings, conclusions, and recommendations clearly and concisely to executive leadership, investigators, and cross-functional stakeholders, translating technical detail for non-technical audiences.
- Maintain a consistent, high-quality analytic voice across CAAT’s report portfolio, applying active-voice intelligence writing and estimative language.
- Lead complex, sensitive investigations end-to-end and provide quality assurance reviews on intelligence products.
- Mentor and upskill junior analysts and partners on OSINT tradecraft, operational security, research-persona development, and analytic standards.
- Advise on intelligence collection strategy, tooling evaluation, and process-improvement initiatives.
- Serve as CAAT’s cross-functional liaison, supplying intelligence, disruption support, and referrals internal and external enforcement partners.
- Apply rigorous OPSEC and managed-attribution practices and set the standard for the team.
- Conduct collection ethically and safely across Telegram, onion sites, and foreign/niche platforms, defaulting to a passive posture and escalating active engagement for approval.
- Perform other duties as assigned in support of CAAT’s member-protection mission
- Bachelor’s degree in cyber security, Information Security, or related field, or the equivalent combination of education, training and experience.
- Hands on experience in conducting OSINT analysis on foreign web and social media sites (Chinese, Russian, Arabic, Korean, or Farsi).
- Hands-on experience with telecom fraud, spam, spoofing, brand abuse and counter-spoofing operations.
- Expertise in OSINT and analytic tradecraft, including structured analytic techniques, source evaluation, and managed-attribution research.
- Advanced verbal and written communication skills, with ability to produce BLUF-formatted intelligence and present to all levels of management and stakeholders.
- Hands-on experience with cybercrime intelligence, social media network analysis, phishing, and domain analysis.
- Hands-on experience with threat actor attribution and deep/dark web collection (Telegram, onion sites, breach data).
- Hands-on experience with domain analysis tooling.
- Experience in cybersecurity analysis, counter-fraud, or financial-sector intelligence with increasing responsibility.
- Extensive hands-on experience in open-source intelligence analysis, or a related Information Security discipline.
- Advanced skill monitoring and analyzing threat actor behavior across internal and external sources and multiple platforms, discerning patterns in complex adversary activity.
- Advanced research, analytical, and problem-solving skills, with independent critical thinking to diagnose and assess threat intelligence data.
- Knowledge of security architectures, devices, proxies, online forums, specialized sites, and social media as intelligence sources.
- Experience leading investigations, mentoring analysts, and collaborating with management, stakeholders, and vendors.
Desired Qualifications
- Relevant certifications (e.g., CAMS, CFE) or equivalent intelligence/OSINT training.
- Experience with professional journal or conference presentations.
- Hands-on experience with BSA/AML investigations or analysis including identification of actors, tactics and reporting to stakeholders.
- Familiarity with FS-ISAC Cyber Fraud Prevention Framework (CFPF) and MITRE ATT&CK.
Additional Information
Hours
- Monday - Friday, 8:00AM - 4:30PM
Location
- 820 Follin Lane, Vienna, VA 22180
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
