Cyber Threat Intelligence Analyst
Listed on 2026-08-30
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Only applicants who meet the Minimum Qualification Requirements and meet all selective requirements (listed below) will be placed on the eligible list.
The Department of Management’s Division of Information Technology (DoIT) is seeking a senior-level Information Technology Specialist 5 (ITS5) – Cyber Threat Intelligence Analyst to serve as the authoritative intelligence resource supporting the Security Operations Center (SOC). This role collects, reviews, and analyzes intelligence data to identify threats targeting state and local government environments and transforms that information into actionable outcomes for SOC analysts, threat hunters, engineering teams, GRC, and leadership.
The analyst develops and maintains Priority Intelligence Requirements (PIRs), assesses cyber risks, identifies adversary tactics, and motives, and ensures intelligence is aligned to state security objectives. The role leverages CTI platforms, OSINT sources, and structured analytic methodologies to produce accurate and timely intelligence reports. It also coordinates intelligence exchanges with external partners including CISA and peer government entities. This ITS5 position requires deep technical understanding, high integrity, and the ability to communicate complex intelligence to diverse audiences.
You Will Do
- Collect, maintain, and enrich intelligence data from internal telemetry, OSINT, commercial intel feeds, third-party reporting, and government partners.
- Correlate external threats with SOC alerting and state-specific vulnerabilities.
- Analyze cyber threat data to assess likelihood, impact, and relevance to state and local government.
- Identify threat actor TTPs, campaigns, emerging vulnerabilities, and exploitation trends.
- Produce tactical, operational, and strategic reports for diverse stakeholder groups.
- Develop, maintain, and refine PIRs aligned to evolving state risks.
- Manage intelligence workflows including collection planning, source evaluation, assessment documentation, and dissemination tracking.
- Translate CTI findings into actionable activities including detection recommendations, risk prioritization, threat hunting leads, vulnerability context, and architecture hardening actions.
- Support incident response as an intelligence subject-matter expert.
- Coordinate with CISA, law enforcement, and peer government agencies to exchange intelligence, validate trends, and support joint defensive efforts.
- Maintain and optimize CTI platforms, automation pipelines, and enrichment tools.
- Mentor SOC team members on intelligence concepts, frameworks, and analytic tradecraft.
- Present intelligence briefings to technical and non-technical audiences in a clear, concise manner.
- Document analytic methods, assumptions, and findings following best practices and structured analytic techniques.
- Cyber Threat Intelligence lifecycle management (PIR development, collection, analysis, dissemination)
- Strong knowledge of threat actor motivations, targets, behaviors, and TTPs
- Proficiency with CTI platforms, malware/trend research tools, enrichment feeds, and OSINT techniques
- In-depth understanding of MITRE ATT&CK, attack surface concepts, incident response, and vulnerability prioritization
- Ability to translate intelligence into operational actions, detections, and risk-driven recommendations
- Excellent communication, presentation, and technical writing skills
- Strong problem-solving, critical-thinking, and independent decision-making ability
- Five or more years of experience in cyber threat intelligence, cyber defense analytics, or related field
- Strong understanding of cybersecurity frameworks (MITRE ATT&CK, Kill Chain, Diamond Model)
- Demonstrated knowledge of attack vectors, penetration methods, and defensive countermeasures
- Experience with OSINT, intel feeds, CTI platforms, and log or alert correlation
- Excellent problem-solving, writing, briefing, and documentation skills
- Ability to work independently with minimal supervision and in a multidisciplinary team
- Strong integrity, judgment, and professional conduct with sensitive information
- CISSP, CISA, GSEC, or related cyber/intelligence credentials
- Flexible…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).