Threat Intelligence Analyst, Associate - Security Operations
Core
Conduct tactical, operational, and strategic cyber threat intelligence analysis to inform defensive operations, risk decisions, and executive awareness for Blackstone and its portfolio companies.
Role type
Associate Threat Intelligence Analyst (Security Operations)
Builds
Finished intelligence products, reports, visual diagrams, and production detections (Splunk SPL, Sigma, YARA) to protect global investment platforms.
Domain
Cybersecurity, Financial Services, Alternative Asset Management
Deliverable
production ML models | product features | dashboards & analysis | client delivery
Required skills
Cyber threat intelligence analysis, MITRE ATT&CK framework, IOC extraction and enrichment, OSINT research, Python scripting, AI/LLM tooling application, technical and non-technical communication, vulnerability prioritization (CVSS, EPSS, CISA KEV), Attack Surface Management
Preferred skills
Financial sector experience, specific ASM platforms (Mandiant, CrowdStrike, Microsoft Defender), AI developer tooling (LLM APIs, coding assistants), detection content development, cloud threat vectors (AWS, Azure), structured analytic techniques
Technologies
Splunk, MITRE ATT&CK, Python, LLMs, OSINT tools, Sigma, YARA, CISA KEV, FS-ISAC, JCDC
Responsibilities
Monitor and analyze cyber threat activity targeting the financial sector; Produce finished intelligence products and reports including advisories and executive briefings; Map adversary behaviors to the MITRE ATT&CK framework; Extract, validate, enrich, and operationalize indicators of compromise (IOCs); Leverage AI and automation tooling to scale intelligence collection; Partner with detection teams to translate intelligence into production detections; Track zero-day vulnerabilities and support threat-informed vulnerability prioritization; Operate the external Attack Surface Management (ASM) program; Support Fusion Center digital-threat monitoring; Contribute to intelligence sharing with industry partners and government agencies; Participate in incident response and SOC on-call rotation.
Seniority
Associate, hands-on IC