Cyber operations and threat intelligence for U.S. federal agencies
phia is a Northern Virginia-based cyber defense firm serving federal civilian, defense, law enforcement, and intelligence agencies. The stack—CrowdStrike, Palo Alto Networks, Splunk, Elasticsearch, Recorded Future, MITRE ATT&CK—reflects a mature SOC and threat-intel operation, while active projects show a shift from legacy SharePoint toward ServiceNow-based automation and SentinelOne endpoint consolidation. Hiring tilted toward senior security roles signals operational complexity and client-side staffing models.
phia LLC, founded in 2011, operates as a small contractor specializing in cyber operations, incident response, forensic analysis, and cyber intelligence. The firm supports mission-critical teams across multiple U.S. federal agencies and is structured around technical expertise rather than sales-driven growth. The stack emphasizes threat detection (Splunk, Elasticsearch, CrowdStrike), vulnerability intelligence (Recorded Future, Censys, VirusTotal), and information sharing protocols (STIX, TAXII). Current initiatives center on cloud-readiness (Tealeaf UI/SDK, cloud-based analytics) and operational modernization (ServiceNow migration, SentinelOne rollout, log-analysis optimization).
CrowdStrike, Palo Alto Networks, Splunk, Elasticsearch, Recorded Future, SentinelOne, Microsoft Defender suite, ServiceNow, Tealeaf, MITRE ATT&CK, STIX/TAXII, and Proofpoint.
SentinelOne agent deployment, ServiceNow process migration, Tealeaf cloud SDK and UI expansion, AI/LLM automation of threat-analysis activities, Splunk log optimization, and cybersecurity information-sharing operations.
Fairfax, Virginia. The company was founded in 2011 and operates as a privately held business with 11–50 employees.
Other companies in the same industry, closest in size