The Cyber Threat Intelligence & Exposure Management Analyst
Core
Identify, analyze, and communicate cyber threats and organizational exposures to improve security posture and reduce business risk.
Role type
Cyber Threat Intelligence & Exposure Management Analyst
Builds
Actionable insights for Security Operations, Vulnerability Management, Incident Response, Engineering, and Risk teams
Domain
Cybersecurity, Threat Intelligence, Attack Surface Management
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Cyber Threat Intelligence tradecraft, Attack Surface Management (ASM), Risk-Based Vulnerability Management (RBVM), MITRE ATT&CK, STIX/TAXII, intelligence lifecycle, structured analytic techniques, IOC lifecycle management, cloud security concepts, shadow IT identification, malware analysis principles, Python, automation, APIs, large-scale data analysis
Preferred skills
Experience with Cortex Xpanse, CrowdStrike Exposure Management, Rapid7 Exposure Command, Tenable, Wiz, Microsoft Defender EASM, Bitsight, SecurityScorecard, Anomali, ThreatConnect, ThreatQ, OpenCTI, MISP, Maltego, VirusTotal, Shodan, Censys, GreyNoise, DomainTools, SecurityTrails, URLScan, PassiveTotal, Sigma, YARA, Suricata, Snort, ELK Stack, Databricks, Power BI
Technologies
Cortex Xpanse, CrowdStrike Exposure Management, Rapid7 Exposure Command, Tenable, Wiz, Microsoft Defender EASM, Bitsight, SecurityScorecard, Anomali, ThreatConnect, ThreatQ, OpenCTI, MISP, Maltego, VirusTotal, Shodan, Censys, GreyNoise, DomainTools, SecurityTrails, URLScan, PassiveTotal, Sigma, YARA, Suricata, Snort, ELK Stack, Databricks, Power BI
Responsibilities
Monitor emerging cyber threats, adversary activity, malware campaigns, and vulnerability exploitation trends; Track threat actors and analyze their capabilities, infrastructure, targeting patterns, and TTPs; Conduct intelligence-driven investigations using internal telemetry, threat intelligence platforms, OSINT, and digital footprint analysis; Discover, inventory, and assess internet-facing assets, cloud resources, domains, certificates, and external attack surfaces; Identify, validate, and prioritize security exposures including vulnerabilities, misconfigurations, exposed services, shadow IT, credential exposures, and third-party risks; Correlate threat intelligence with vulnerability, asset, business criticality, and exposure data to provide risk-based remediation recommendations; Analyze exploitability, adversary activity, KEV intelligence, and emerging attack trends to prioritize remediation efforts; Develop threat-informed exposure assessments and risk reports for security, engineering, and business stakeholders; Lead IOC collection, enrichment, validation, and lifecycle management activities; Maintain intelligence records, exposure findings, indicators, and threat artifacts within intelligence and exposure management platforms; Support continuous attack surface monitoring and identify newly discovered assets, services, and externally exposed technologies; Produce tactical, operational, and strategic intelligence products on threats, exposures, and cyber risks; Deliver intelligence and exposure management briefings to leadership, security teams, and business stakeholders; Support incident response activities through adversary analysis, attribution support, infrastructure investigations, and threat hunting; Partner with Security Operations, Vulnerability Management, Cloud Security, Product Security, and Risk Management teams to drive threat-informed risk reduction; Develop metrics and reporting that measure exposure reduction, remediation effectiveness, vulnerability prioritization, and attack surface risk; Identify intelligence gaps, emerging risks, and opportunities to improve organizational resilience and defensive capabilities
Seniority
Mid-Senior, hands-on IC