Cyber Threat Intelligence III
Listed on 2026-09-25
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
Job Description The Cyber Threat Intelligence (CTI) Analyst is responsible for identifying, analyzing, and communicating cyber threats that may impact the organization, its employees, systems, data, and business operations. This role combines traditional threat intelligence analysis with strong technical cybersecurity aptitude to ensure intelligence is actionable and can be translated into detections, investigations, vulnerability prioritization, and defensive security improvements.
Worker Type Regular
Summary The Cyber Threat Intelligence (CTI) Analyst is responsible for identifying, analyzing, and communicating cyber threats that may impact the organization, its employees, systems, data, and business operations. This role combines traditional threat intelligence analysis with strong technical cybersecurity aptitude to ensure intelligence is actionable and can be translated into detections, investigations, vulnerability prioritization, and defensive security improvements.
Position Responsibilities Cyber Threat Intelligence- Monitor and analyze cyber threat intelligence from commercial, government, open-source, and internal sources.
- Identify emerging threat actors, campaigns, malware, vulnerabilities, tactics, techniques, and procedures (TTPs) relevant to the organization.
- Develop intelligence assessments covering strategic, operational, and tactical cyber threats.
- Maintain threat actor profiles, indicators of compromise (IOCs), TTPs, and intelligence requirements.
- Analyze threats using frameworks such as MITRE ATT&CK and the Cyber Kill Chain.
- Produce executive-level intelligence reports, technical threat reports, alerts, and briefings.
- Evaluate the credibility, relevance, and confidence level of intelligence before dissemination.
- Track threats targeting the organization's industry, technology stack, supply chain, and critical business operations.
- Analyze endpoint, network, identity, cloud, email, and security telemetry to validate threat intelligence.
- Use SIEM/XDR platforms to investigate IOCs, suspicious activity, and threat actor behaviors.
- Perform threat hunting based on intelligence-derived hypotheses and known adversary TTPs.
- Develop and execute searches using technologies such as KQL, XQL, SPL, or similar query languages.
- Analyze IP addresses, domains, URLs, file hashes, certificates, processes, command lines, and other technical indicators.
- Understand common Windows, Linux, network, Active Directory/Entra , cloud, and endpoint attack techniques.
- Work with SOC and security engineering teams to translate intelligence into actionable detections and security controls.
- Assist with developing detection logic, watchlists, blocklists, threat-hunting queries, and alerting rules.
- Monitor emerging vulnerabilities, zero-day vulnerabilities, exploitation activity, and threat actor targeting.
- Correlate vulnerability intelligence with the organization's technology and asset inventory.
- Assist vulnerability management teams with risk-based vulnerability prioritization based on active exploitation, threat intelligence, asset criticality, and business impact.
- Monitor sources such as CISA KEV, vendor advisories, security researchers, and commercial intelligence providers.
- Evaluate whether newly disclosed vulnerabilities represent an immediate threat to the organization.
- Provide threat intelligence support during cybersecurity incidents.
- Research suspected threat actors, malware, infrastructure, and attack techniques during active investigations.
- Enrich security alerts and incidents with relevant threat intelligence.
- Identify related infrastructure, IOCs, TTPs, and historical activity.
- Support incident scoping and attribution where appropriate.
- Document intelligence findings and provide recommendations to incident commanders and security leadership.
- Maintain and improve threat intelligence platforms, feeds, integrations, and intelligence repositories.
- Evaluate intelligence feeds for accuracy, duplication, relevance, and operational value.
- Integrate threat intelligence with SIEM, XDR, SOAR, EDR, vulnerability management, and other security platforms.
- Support automation of IOC ingestion, enrichment, correlation, and response workflows.
- Continuously improve the organization's intelligence collection requirements and processes.
- Bachelor's degree in Cybersecurity, Information Technology,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).