Full-Time

Cyber Threat Intelligence Analyst

Dragos

Dragos

501-1,000 employees

Provides ICS/OT cybersecurity platform and consulting

Compensation Overview

$165k/yr

+ Equity package

No H1B Sponsorship

Norfolk, VA, USA

In Person

Onsite work in Norfolk, Virginia is required.

US Top Secret Clearance Required

Category
Cybersecurity (1)
Required Skills
Incident Response
Threat modeling
Cybersecurity

Get referred to Dragos

See people who can refer or advise you

Requirements
  • An active Top Secret security clearance is required.
  • Willingness and ability to work onsite in Norfolk, Virginia is required.
  • At least 5 years of hands-on experience in threat intelligence using multiple resources and disciplines, including network-based data such as NetFlow, open-source intelligence, security information and event management systems, malware repositories, and digital forensics and incident response.
  • Ability to create effective intelligence analysis products relevant to government agencies, federal civilian organizations, or critical infrastructure sectors.
  • Experience integrating unclassified and classified threat intelligence into cohesive deliverables.
  • Experience conducting threat hunting within industrial control systems and operational technology environments or related technology settings.
  • Experience producing operational and strategic intelligence reporting using confidence-based assessments.
  • Proficiency with data aggregation, hunting, and analysis tools such as Synapse.
  • Experience building threat models relevant to specific threat and risk profiles.
Responsibilities
  • Directly support the customer with industrial control systems and operational technology security and cyber threat intelligence needs.
  • Conduct threat research, analysis, and hunting tasks using proprietary and commercial resources to respond to client inquiries and create tailored deliverables based on priority intelligence requirements.
  • Develop expertise in industrial control systems and operational technology threats and risks relevant to the customer's environment, including attack surface analysis, threat hunting strategies, and threat modeling.
  • Support the customer's cybersecurity initiatives, including threat hunts, incident response, and exercises.
  • Partner with internal threat intelligence peers to create operational and strategic content for global customers.
  • Provide support and feedback to internal Incident Response, OT-Watch, Professional Services, and Customer Experience teams.

Dragos protects industrial control systems (ICS) and operational technology (OT) by offering a platform and services for visibility, threat detection, and rapid response. The Dragos Platform monitors ICS/OT networks to surface suspicious activity and enable containment, and is complemented by consulting to help organizations improve security roadmaps. It focuses on ICS/OT security across industries such as manufacturing, energy, water, and transportation, serving a global client base. Its goal is to reduce risk to critical assets, public safety, and economic stability by delivering clear visibility, effective detection, and practical response capabilities.

Company Size

501-1,000

Company Stage

Series D

Total Funding

$432.2M

Headquarters

Hanover, Maryland

Founded

2016

Get referred to Dragos

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Project Watershed 250 on September 6, 2026 spotlights Dragos across Texas water utilities.
  • Accenture projected Dragos, runZero, and NetRise at $208 million ARR in June 2026.
  • Federal and state critical-infrastructure spending favors OT vendors with proven incident-response depth.

What critics are saying

  • Accenture integration after August-September 2026 closing can distract engineers and sales.
  • EmberAI pricing inside the full platform blocks smaller utilities and manufacturers.
  • ServiceNow-Armis and Palo Alto pressure Dragos on platform breadth, bundling, and procurement cycles.

What makes Dragos unique

  • Dragos owns decade-deep OT telemetry, threat intelligence, and incident-response data.
  • EmberAI launched June 23, 2026, using OT-native models inside customer environments.
  • Accenture backed Dragos on June 18, 2026, validating its vendor-neutral OT platform.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Medical, dental, vision, disability, & life insurance

401k with match

Equity

Competitive compensation

Remote working options

Pet-friendly options

In-house brewery

Growth & Insights and Company News

Headcount

6 month growth

-3%

1 year growth

-4%

2 year growth

-4%
iTWire
Sep 4th, 2026
Dragos named a Leader in Operational Technology Security Solutions.

Dragos named a Leader in Operational Technology Security Solutions. Dragos | Published 4 Sept 2026 COMPANY NEWS: Dragos Platform receives highest score in the Strategy category, highest scores possible in eight criteria Dragos, the global leader in extended operational technology (xOT) cybersecurity, been named a Leader in The Forrester Wave: Operational Technology Security Solutions, Q3 2026. Dragos received the highest score in the Strategy category and was the only vendor to receive a 5/5 score in the Vision criterion. The Forrester report finds that "operational technology (OT) environments are now tightly interconnected with enterprise IT, cloud platforms, and third-party service providers, fundamentally changing their risk profile," and that "traditional OT security approaches built on perimeter controls and asset visibility are no longer sufficient." "We built the Dragos Platform for the environment as it exists, not as it was categorised," said Robert M. Lee, CEO and Co-Founder of Dragos. "Operational environments have extended beyond the boundaries the industry historically drew around OT. Power grids, pipelines, manufacturing facilities, and data centres now depend on a wider range of technologies connected to and capable of affecting operations. Together, those technologies make up xOT, and adversaries are already operating across them. Defenders need visibility, intelligence, and control that reach just as far." Dragos received the highest available score in eight criteria across the evaluation. In the Strategy category, those criteria were Vision, Innovation, Adoption, and Community. In the Current Offering category, they were threat and anomaly detection, OT-specific incident investigation and response, IT/OT convergence support and SOC integration depth, and OT security services. The Dragos Platform provides the foundation for securing xOT environments across critical infrastructure and manufacturing, combining asset visibility, detailed situational awareness, and operational context with continuous monitoring, vulnerability management, and threat detection at scale. It is powered by the Dragos Intelligence Fabric built from over a decade of operational telemetry, adversary research, and incident response. Dragos EmberAI puts that intelligence directly in every analyst's hands to empower them, regardless of experience, to move from alert to informed action faster, and make defensible decisions grounded in real adversary data. Dragos also delivers finished threat intelligence addressing threats to xOT systems, produced by the largest private OT/ICS threat intelligence team in the industry. "For us, this recognition reflects years of work building an ecosystem that includes our platform, intelligence and services that elevates and encompasses the full operations for xOT environments," said Jodi Schatz, Chief Product Officer, Dragos. "Attack timelines have compressed from months to weeks to days, and security teams need the knowledge, tools and services to ensure the security and resiliency of their entire xOT footprint. Our commitment has been constant and unwavering because safeguarding civilisation is and has always been our mission. The investments we've made in our development of new and innovative methodologies, and technologies, and partnerships are all in service of giving customers the strongest and most comprehensive xOT defence across their industrial footprint." Forrester's evaluation of Dragos states, "Dragos's vision takes a comprehensive view of the IT and OT interconnection while focusing on the importance of cyber resilience for industrial control systems." Dragos has continued to build momentum to define and defend the extended operational environment, most recently through Accenture's majority stake investment which will bring runZero (exposure management) and NetRise (software supply chain risk) under Dragos management, extending the platform's reach even more broadly across xOT. Dragos has also expanded its partnership with Microsoft, deploying the Dragos Platform on Microsoft Azure and integrating with Microsoft Sentinel and Defender. This recognition caps 12 months of notable analyst recognition for the Dragos Platform, including being named a Leader in the 2026 Gartner(R) Magic Quadrant(TM) for CPS (Cyber-Physical Systems) Protection Platforms, Leader in the Omdia Market Radar: OT Cybersecurity Platforms, 2026, and Leader and no. 1 in Innovation in Frost & Sullivan's Frost RadarTM: OT Cybersecurity Solutions, 2025. Forrester does not endorse any company, product, brand, or service included in its research publications and does not advise any person to select the products or services of any company or brand based on the ratings included in such publications. Information is based on the best available resources. Opinions reflect judgment at the time and are subject to change. This report is part of a broader collection of Forrester resources, including interactive models, frameworks, tools, data, and access to analyst guidance. For more information, read about Forrester's objectivity here.

Eric Deters
Aug 31st, 2026
FIRST ON FOX: Texas becomes testing ground for new defense against attacks on America's water systems.

FIRST ON FOX: Texas becomes testing ground for new defense against attacks on America's water systems. FIRST ON FOX: The Trump administration is launching "Project Watershed 250" Monday, Fox News Digital exclusively learned, deploying American artificial intelligence and cybersecurity tools to protect Texas water systems from cyberattacks in a pilot the administration plans to scale nationwide. "Project Watershed 250 is another example of President Trump putting American families and communities first. President Trump is relentless in his work to secure our critical infrastructure against our most determined adversaries," National Cyber Director Sean Cairncross told Fox News Digital. "President Trump has cemented America's leadership in AI security and innovation and is now bringing those exquisite tools to local communities and utilities in Texas and ultimately, across the nation through the launch of Project Watershed 250 - a scalable cyber water pilot program." The Trump administration is bringing federal, state and private-sector cyber defenses together in a six-month Texas pilot aimed at finding vulnerabilities in water systems before adversaries can exploit them - while testing whether the model can be expanded across the country. The program will connect Texas water utilities with U.S. cybersecurity companies to test their existing defenses and strengthen vulnerable systems using private-sector cyber and artificial intelligence tools, a White House official told Fox News Digital. The program will use "red-teaming" to stress-test water utilities' networks, identify weaknesses hackers could exploit and then strengthen those systems with cybersecurity tools, according to a White House official. Dragos CEO Robert Lee said that U.S. water infrastructure faces active, documented threats, particularly at small utilities that often lack strong cybersecurity defenses. Lee said Watershed 250 will help get technology, training and support to those vulnerable systems before an attack occurs. "There is nothing more important to Texans than clean, reliable drinking water. Project Watershed 250 puts federal, state, and private-sector cyber defenses behind our utilities at no cost. The White House, the Texas Cyber Command, and industry now work from the same playbook," said Texas Gov. Greg Abbott. A White House official, however, said the program is not in response to recent cyberattacks that targeted more than 30 Minnesota water systems, though the incidents underscored vulnerabilities in local infrastructure. "However, these recent attacks have reiterated the need for this modernization and focus on water systems," said the White House official. "Critical Infrastructure protection has long been a priority for ONCD and President Trump and this effort has been in the works since last year." The Environmental Protection Agency and Department of Homeland Security's Cybersecurity and Infrastructure Security Agency will serve as federal partners in the effort, while Texas Cyber Command will work alongside the White House with local governments and tech companies such as Microsoft, Reflection AI, Palo Alto Networks and Dragos Inc. "Few things matter more than the safety of the water Americans drink, and this is a powerful example of how open-weight AI models, built in the U.S. and running on a utility's own systems, can help keep communities safe," said Becky Sosnov, Reflection AI head of corporate affairs. "Microsoft applauds the administration's leadership in strengthening the cybersecurity of America's water infrastructure and is proud to support the Project Watershed 250 effort in partnership with the Office of the National Cyber Director, the State of Texas, and Texas Cyber Command," said Microsoft US Public Sector president Chris Barry. "By bringing together Microsoft's cybersecurity expertise, threat intelligence, and AI-powered security capabilities, we aim to help water utilities strengthen their resilience against evolving cyber threats and develop scalable approaches that can enhance the security of water systems nationwide." The push comes as the Trump administration races to build out U.S. data centers to fuel the AI boom, putting more attention on the water and power needed to keep them running. The pilot program builds on Trump's June executive order on Promoting Advanced Artificial Intelligence Innovation and Security and his Cyber Strategy for America released in March. Latest Political News on Fox News

Fox News
Aug 31st, 2026
FIRST ON FOX: Texas becomes testing ground for new defense against attacks on America's water systems.

FIRST ON FOX: Texas becomes testing ground for new defense against attacks on America's water systems. The six-month pilot pairs federal agencies, Texas Cyber Command, and firms like Microsoft and Dragos to defend utilities. Fox News chief national security correspondent Jennifer Griffin reports on the Trump administration's program to protect U.S. water systems following alleged foreign hacking attempts on 'Special Report.' FIRST ON FOX: The Trump administration is launching "Project Watershed 250" Monday, Fox News Digital exclusively learned, deploying American artificial intelligence and cybersecurity tools to protect Texas water systems from cyberattacks in a pilot the administration plans to scale nationwide. "Project Watershed 250 is another example of President Trump putting American families and communities first. President Trump is relentless in his work to secure our critical infrastructure against our most determined adversaries," National Cyber Director Sean Cairncross told Fox News Digital. "President Trump has cemented America's leadership in AI security and innovation and is now bringing those exquisite tools to local communities and utilities in Texas and ultimately, across the nation through the launch of Project Watershed 250 - a scalable cyber water pilot program." The Trump administration is bringing federal, state and private-sector cyber defenses together in a six-month Texas pilot aimed at finding vulnerabilities in water systems before adversaries can exploit them - while testing whether the model can be expanded across the country. President Donald Trump speaks during an executive order signing in the Oval Office of the White House on June 22, 2026. (Bonnie Cash/UPI/Bloomberg via Getty Images) The program will connect Texas water utilities with U.S. cybersecurity companies to test their existing defenses and strengthen vulnerable systems using private-sector cyber and artificial intelligence tools, a White House official told Fox News Digital. The program will use "red-teaming" to stress-test water utilities' networks, identify weaknesses hackers could exploit and then strengthen those systems with cybersecurity tools, according to a White House official. An official said the program is not in response to cyberattacks on Minnesota water systems, though the incidents underscored vulnerabilities in local infrastructure. (Thomas Trutschel/Photothek via Getty Images) Dragos CEO Robert Lee said that U.S. water infrastructure faces active, documented threats, particularly at small utilities that often lack strong cybersecurity defenses. Lee said Watershed 250 will help get technology, training and support to those vulnerable systems before an attack occurs. "There is nothing more important to Texans than clean, reliable drinking water. Project Watershed 250 puts federal, state, and private-sector cyber defenses behind our utilities at no cost. The White House, the Texas Cyber Command, and industry now work from the same playbook," said Texas Gov. Greg Abbott. A White House official, however, said the program is not in response to recent cyberattacks that targeted more than 30 Minnesota water systems, though the incidents underscored vulnerabilities in local infrastructure. "However, these recent attacks have reiterated the need for this modernization and focus on water systems," said the White House official. "Critical Infrastructure protection has long been a priority for ONCD and President Trump and this effort has been in the works since last year." President Donald Trump wraps up his speech at the opening of the Great American State Fair, June 24, 2026, on the National Mall in Washington. (Jacquelyn Martin/AP) The Environmental Protection Agency and Department of Homeland Security's Cybersecurity and Infrastructure Security Agency will serve as federal partners in the effort, while Texas Cyber Command will work alongside the White House with local governments and tech companies such as Microsoft, Reflection AI, Palo Alto Networks and Dragos Inc. "Few things matter more than the safety of the water Americans drink, and this is a powerful example of how open-weight AI models, built in the U.S. and running on a utility's own systems, can help keep communities safe," said Becky Sosnov, Reflection AI head of corporate affairs. A coordinated cyberattack reached operational technology at dozens of Minnesota water systems, exposing security risks for smaller utilities nationwide. (City of St. Cloud) "Microsoft applauds the administration's leadership in strengthening the cybersecurity of America's water infrastructure and is proud to support the Project Watershed 250 effort in partnership with the Office of the National Cyber Director, the State of Texas, and Texas Cyber Command," said Microsoft US Public Sector president Chris Barry. "By bringing together Microsoft's cybersecurity expertise, threat intelligence, and AI-powered security capabilities, we aim to help water utilities strengthen their resilience against evolving cyber threats and develop scalable approaches that can enhance the security of water systems nationwide." The push comes as the Trump administration races to build out U.S. data centers to fuel the AI boom, putting more attention on the water and power needed to keep them running. The pilot program builds on Trump's June executive order on Promoting Advanced Artificial Intelligence Innovation and Security and his Cyber Strategy for America released in March. Ashley J. DiMella reports on politics for Fox News Digital.

Citybiz
Aug 25th, 2026
SecureW2 names Martin Musierowicz president and Mark Packham CMO.

SecureW2 names Martin Musierowicz president and Mark Packham CMO. August 25, 2026 SecureW2 has appointed Martin Musierowicz as president and Mark Packham as chief marketing officer, expanding its executive leadership team as the cybersecurity company increases investment in go-to-market operations and extends its certificate-based security platform to machine workloads and AI agents. Musierowicz will lead SecureW2's go-to-market strategy and work across the company to scale commercial execution. Packham will oversee global marketing and the company's positioning as it expands its public key infrastructure, or PKI, beyond human users and devices to additional categories of non-human identity. The appointments come as SecureW2 works to capitalize on enterprise adoption of certificate-based authentication and access controls. The company's platform is designed to replace shared credentials with identity-driven security across networks, applications and workloads, while applying real-time trust information to access decisions. "Martin and Mark bring exactly the kind of experience we need as we enter our next phase of growth," CEO and co-founder Bert Kashyap said. He cited Musierowicz's experience scaling revenue organizations and Packham's background connecting technology brands with commercial growth. Musierowicz previously served as chief revenue officer at SmartBear and Keyfactor. His Keyfactor role included direct experience with PKI and machine identity go-to-market operations, giving him familiarity with the security infrastructure SecureW2 is seeking to expand across enterprise environments. Earlier in his career, Musierowicz led global channels and alliances at Atlassian through the software company's initial public offering. He built and scaled Atlassian's worldwide partner ecosystem, experience that adds a channel component to his new responsibility for SecureW2's commercial strategy. "I've spent my career helping security and identity companies scale their go-to-market as demand accelerates, and SecureW2 is at exactly that inflection point," Musierowicz said. Packham joins SecureW2 from industrial cybersecurity company Dragos, where he served as CMO. He previously was executive vice president of marketing at digital trust company DigiCert. With more than 25 years of B2B technology marketing experience, Packham will be responsible for developing SecureW2's market position around certificate-based security as the company broadens its focus from traditional user and device authentication to machine and AI agent identities. The expansion into non-human identities reflects an operational security challenge emerging as enterprises deploy more automated software processes and AI agents. Those workloads require authentication and access controls without relying on conventional passwords designed for human users. SecureW2 is positioning its PKI infrastructure to issue and manage certificate-based identities for those environments. "Machine and AI agent identities have surpassed human identities, and most enterprises still lack the certificate-based infrastructure to secure them," Packham said. His role will include translating that technical requirement into a clearer market category and commercial message for enterprise buyers. SecureW2's JoinNow Platform combines Dynamic PKI, Cloud RADIUS and policy logic to provide certificate-based access across networks, applications and workloads. IT and security teams use the platform to onboard devices, remove shared credentials and manage access according to user and device trust signals. For enterprises, deploying certificate-based authentication at scale requires coordination across identity systems, network infrastructure, device onboarding and security policy. SecureW2's strategy is to consolidate those functions while extending the same trust model to workloads and automated agents. The company said the executive additions follow a period of sustained growth as organizations move from shared credentials and legacy authentication toward certificate-based access control. SecureW2 plans to continue investing in its go-to-market organization and brand through the remainder of 2026. SecureW2 serves organizations across enterprise, education and government markets. With Musierowicz and Packham joining the leadership team, the company is strengthening the commercial infrastructure around its next stage of expansion as PKI moves from securing people and devices to a wider set of machine identities and AI-driven workloads.

Enterprise Times
Jun 23rd, 2026
Dragos unveils EmberAI for ot-native security intelligence.

Dragos unveils EmberAI for ot-native security intelligence. June 23, 2026 Dragos has unveiled EmberAI, an OT-native AI built on the Dragos Intelligence Fabric. It gives security analysts access to OT-specific data from a decade of OT (operational technology) defence carried out by Dragos. The company claims that EmberAI is built on the world's largest OT cybersecurity data set. It sits on the Dragos Intelligence Fabric, which the company has been building for the last decade. It contains in excess of five petabytes of daily OT telemetry. There are 10-plus years of adversary tracking across named OT threat groups. It also has access to Dragos' proprietary OT vulnerability research as a CVE Numbering Authority. Its asset and protocol research spans more than 600 OT protocols, and frontline incident response experience from critical infrastructure environments. Robert M. Lee, CEO and Co-Founder, Dragos, said, "We built EmberAI to harness Dragos's decade-plus of experience in threat intelligence, incident response, adversary tracking, and frontline operations for OT environments. "It is hard to reproduce this depth of OT-specific expertise and build AI that understands and can action OT specific findings." The complex nature of OT. IT has a limited set of architectures and protocols. OT, by comparison, can be extremely complicated. Critical infrastructure, from power stations to oil and gas platforms, manufacturing plants to transport infrastructure, is built with longevity in mind. That longevity means that over time, knowledge of the architecture and the protocols inside devices is lost. It makes replacing equipment, maintaining and updating equipment difficult. Securing those environments is equally complex. You cannot just throw patches at vulnerabilities. The interconnectedness means a mistake can take down a plant or disrupt the infrastructure for months. Introducing EmberAI, with its OT awareness, from protocols to attack methods, will appeal heavily to customers. Dragos has built its reputation on its OT knowledge. Forrester has noted that "Dragos is 'laser focused on OT,' distinguishing it from vendors that dilute their capabilities by prioritising prevention and IT-centric features like firewalls." Discovery and context are the keys to security. EmberAI will give security teams a detailed view of all their assets, vulnerabilities and activity on their network. Enumeration and understanding of the tools is done by EmberAI using the tools in the Dragos Platform. It then uses the Dragos Intelligence Platform to provide the analyst with a deep understanding of what they have and how it is all connected. EmberAI also uses a risk-based approach. It identifies the most at-risk systems based on how they work, rather than basic scoring. Once it has identified those systems, it gives SecOps teams a way to remediate them. This means that the most at-risk systems are protected first, and security posture is improved. Competitive landscape. The OT security market is crowded, yet few competitors offer native AI grounded in operational reality. * Microsoft and CrowdStrike: While leaders in IT security, their AI models generalise across environments. They struggle with the deterministic nature of industrial control systems. A generic model might flag a safety shutdown as a threat. * Nozomi Networks and Claroty: These pure-play OT competitors offer strong asset discovery. However, Dragos claims EmberAI surpasses them in adversary intelligence. Dragos integrates named threat group tracking directly into the AI response, whereas others often rely on static signatures. Dragos positions EmberAI as the bridge between raw data and decisive action. Its xOT strategy extends this capability beyond traditional OT to include other systems. Building controls, HVAC, and access systems are all entry points for attackers. As these integrations expand, the Intelligence Fabric grows. What's Next for Dragos and EmberAI. This first version of EmberAI draws on tools and data developed over a decade. EmberAI has been trained on all the data, threat intelligence, and incident reports that Dragos has accumulated. So what comes next? Last week, Accenture spent $4.175 billion to take a majority stake in Dragos and acquire runZero and NetRise. It is rolling those two acquisitions into the Dragos platform. Jodi Schatz, Chief Product Officer, Dragos, said, "The initial launch of EmberAI is solely for the Dragos Platform today. As we integrate runZero and NetRise technology and capabilities into the Platform over the next 6-12 months (following official closing of the deal) then EmberAI will expand to include support for them as well." What customers, especially those of the two companies, will want to know is how this integration will work. Will it bring over all the tools? If not, what will it deprecate? Which tools and technologies does it see as an immediate benefit to EmberAI? How will it standardise and incorporate all the data, threat intelligence and incident reports from those companies? Integration is never easy. There are some obvious overlaps, but also some areas where the two companies bring additional technology to Dragos. Will it seek to add those elements quickly, while it plans for the next release of EmberAI? Enterprise times: what does this mean? The OT security market is growing fast, with MarketsandMarkets estimating that it could be worth almost $60 billion by 2026. That growth means that other vendors are going to be investing heavily in this space. The launch of EmberAI and the integration of runZero and NetRise will make for a very busy time at Dragos. It will also be aware that while Accenture has said it will give it time, that is a very short commodity in the market. What is clear is that EmberAI is a significant boost for security analysts and SecOps teams. Keeping the "human-in-the-loop" is what customers want, especially around OT. But a key element of its success will be the workflows that Dragos is building. For analysts, this will determine if it is just another chatbot or a fully capable tool to speed up workflows. Take-up may also be limited by cost. EmberAI sits on the Dragos Intelligence Platform. It means that customers have to buy the whole platform before they can use it. For smaller critical infrastructure operators, especially manufacturers, that cost could be a barrier. The last question for customers will be integration with their existing tools, data and incident systems. Can they extend EmberAI to point at what they hold? Will it be able to bring customer-specific data points into its analysis and reasoning? There are technical issues to overcome here, but if EmberAI can access everything on a customer site, this will set the bar for the industry.