Threat Intelligence Analyst
Core
Analyzing cyber incidents, attributing threats to intrusion sets, and generating tactical and operational intelligence to protect client organizations from cyber threats.
Role type
Threat Intelligence Analyst
Builds
Intelligence reports and preventative security recommendations for clients
Domain
Cybersecurity / Threat Intelligence
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery
Required skills
Threat intelligence platforms (ThreatQ, OpenCTI, MISP), SIEM platforms (Splunk, Elastic), malware reverse engineering, forensic analysis, structured analytic techniques (AHP, diamond model), OSINT collection, TTP analysis, intrusion set development, malware reverse engineering fundamentals, programming (C, Python, Golang, Rust), API navigation, computer forensics, incident response, meta-analysis, trend analysis, detection development (Yara, KQL)
Preferred skills
Knowledge of information security policy and compliance, current events in cybersecurity, business processes in IT/security
Technologies
CobaltStrike, Sliver, VirusTotal, VMRay, Hybrid-Analysis, C, Python, Golang, Rust, Yara, KQL
Responsibilities
Analyze incidents and attribute them to threat types and intrusion sets; Identify, prioritize, and report on external cyber threats relevant to an organization's industry and footprint; Generate and exploit tactical and operational threat intelligence; Provide structured analysis of adversary intent, opportunity, and capability; Seek and validate new sources of threat intelligence; Write intelligence reports (strategic, tactical, and/or operational); Provide recommendations for preventative controls based on incident response findings.
Seniority
Mid-level (2+ years experience), hands-on IC