Principal Targeting Analyst-TS Required
SixGen, Inc.
| Company | SixGen, Inc. |
| Category | Security |
| Location | Ft Meade |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Senior |
| Salary | Not stated by the employer |
| Posted | 28 Jul 2026 |
| Last verified | 9 Aug 2026 |
| Source | Employer ATS (greenhouse) |
Description
Principal Targeting Analyst
Target development for cyber operations, red-team engagements, and applied R&D
Position Overview:
Position: Principal Targeting Analyst
Job Type: Full-time
Location: Ft. Meade, MD (Hybrid)
Clearance Requirements: US Citizen &TS/SCI
Experience: 8+ years
What You'll Do
SIXGEN is seeking a Principal Targeting Analyst to build and lead an organic targeting and collection capability that strengthens our offensive cyber, red-team, and adversary-emulation missions. This is a hands-on technical leadership role for an analyst-engineer hybrid who enjoys solving hard collection problems, developing targets from a cold start, and turning operational experience into automated, mission-ready capability.
As a Principal Targeting Analyst, you'll pair deep OSINT and managed-attribution tradecraft with professional foreign-language proficiency, applied AI engineering, and real software-development ability. You'll partner with operators, engineers, and program teams to deliver timely targeting and access intelligence, mature SIXGEN's collection methodologies and tooling, and mentor analysts as the capability grows.
Whether you're developing a target for a critical customer mission, automating collection at scale, or shaping the technical direction of a new capability, your operational credibility and technical judgment will help drive mission success across the organization.
Key Responsibilities
Target Development and Key Operations
Conduct end-to-end target development against threat actors, and adversary infrastructure — from initial requirement through finished, decision-ready intelligence.
Direct collection across the surface, deep, and dark web, closed forums, encrypted messaging platforms, and regional ecosystems beyond the coverage of commercial data sources.
Perform authorized threat-actor engagement and elicitation; track initial-access brokers, exploit sellers, and access markets relevant to mission objectives.
Conduct lawful analysis of credential, breach, and infostealer-log datasets, plus cryptocurrency tracing and target deanonymization, to identify access vectors and attribute infrastructure and operators.
Deliver timely targeting updates and access intelligence in support of red-team and operational engagements; author finished intelligence and brief senior stakeholders and customers.
Persona Lifecycle & Attribution-Resistant Infrastructure
Establish and govern durable, non-attributable personas spanning multiple regions — programmatic creation, automated aging and backstopping, sustainment, and OPSEC-safe access control.
Design and maintain managed-attribution infrastructure: VPS estates, egress and redirector architectures, fingerprint control, and compartmented access paths.
Manage OPSEC-compliant procurement and resourcing practices that support persona creation, infrastructure acquisition, and operational sustainment in a controlled, auditable manner.
Author and enforce the governing SOPs and defensive operating standards that keep the capability secure and compliant.
AI Engineering, Software Development & Automation
Design and deploy agentic AI workflows and Model Context Protocol (MCP) servers that automate discovery, monitoring, collection, and enrichment across the capability.
Apply LLMs and multimodal models to real-time translation, entity extraction, data labeling, and semantic summarization of text, image, and video at scale — with evaluation harnesses that keep automated output accurate and auditable.
Build production-grade collection tooling, scrapers, and API integrations in Python, JavaScript/TypeScript, and Bash; architect ingestion pipelines that move raw collection into structured, queryable platforms.
Stand up cloud and serverless infrastructure (AWS or equivalent) and analyst-facing applications that reduce triage time and operational friction.