> Markdown version of [/jobs/ext/1460149-cyber-threat-intelligence-engineer-iv](https://www.wearedevelopers.com/jobs/ext/1460149-cyber-threat-intelligence-engineer-iv). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Threat Intelligence Engineer IV - **Company:** Edward D. Jones & Co., L.P. - **Location:** St. Louis, MO, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Data Analysis, Computer Telephony Integration, Data Sharing, Intrusion Detection and Prevention, Python (Programming Language), Open Source Intelligence, Red Team (Cyber Security), Security Information and Event Management, SQL Databases, Software Vulnerability Management, Mitre Att&ck, Cyber Threat Analysis, Purple Team (Cyber Security) - **Published:** July 27, 2026 - **Apply:** https://sjobs.brassring.com/TGnewUI/Search/home/HomeWithPreLoad?partnerid=26235&siteid=5374&PageType=JobDetails&jobid=1420337 ## About the Role * 5+ years of experience in cyber threat intelligence, SOC, incident response, or a closely related security discipline. * Solid working knowledge of the MITRE ATT&CK framework and experience mapping adversary behavior to it. * Familiarity with threat intelligence platforms and OSINT collection/analysis techniques. * Experience working with SIEM/EDR tooling to pivot on and validate intelligence. * Understanding of vulnerability management and exposure management concepts. * Strong written and verbal communication skills, with the ability to tailor technical intelligence for both analysts and executives. * Analytical mindset with sound tradecraft: structured analytic techniques, confidence levels, and source reliability assessment. What Could Set You Apart: * Familiarity with scripting or data analysis (Python, SQL) for intelligence automation or enrichment. * Experience with STIX/TAXII or other structured threat data sharing standards. * Prior experience in a fusion-center or cross-functional security model bridging detection, red teaming, and exposure/vulnerability management. ## Description We're looking for a Cyber Threat Intelligence (CTI) Analyst to join our security organization and serve as a connective force across our Security Operations Center (SOC), Detection Engineering, Red Team, and Exposure Management functions. This is a highly cross functional role for someone who wants their intelligence work to directly shape what we detect, what we test, and what we prioritize fixing. You'll translate raw threat data into decisions: which adversary behaviors get new detections, which techniques the red team should emulate next, and which exposures matter most given who's actually targeting organizations like ours. What You'll Do: * Track threat actors, campaigns, and TTPs relevant to our industry, geography, and technology stack, and translate findings into actionable intelligence products (briefs, actor profiles, trend reports). * Partner with the SOC to enrich alerts and investigations with threat context, helping analysts triage faster and more accurately during active incidents. * Work with Detection Engineering to identify coverage gaps against known adversary behavior (e.g., mapped to MITRE ATT&CK) and help prioritize new detections based on real world threat relevance. * Collaborate with the Red Team to shape threat informed emulation plans, ensuring exercises reflect the tactics of adversaries most likely to target the organization. * Feed intelligence into Exposure Management to help prioritize vulnerabilities, misconfigurations, and attack surface findings based on active exploitation trends and threat actor intent. * Monitor open-source intelligence (OSINT), dark web sources, ISACs, and commercial threat feeds; assess relevance and reliability of incoming intelligence. * Produce and maintain adversary tracking documentation, including TTP matrices, campaign timelines, and indicator repositories. * Deliver both tactical (IOC/TTP-level) and strategic (executive-level trend and risk) intelligence outputs tailored to different stakeholders. * Participate in incident response as a threat intelligence liaison, providing attribution context and likely adversary next-steps. * Contribute to purple team exercises by bridging red team findings with detection and intelligence perspectives. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Data Science in Retail](https://www.wearedevelopers.com/videos/586-data-science-in-retail) - [Smart City, Smart Mobility](https://www.wearedevelopers.com/videos/954-smart-city-smart-mobility) - [Real-world Threat Modeling](https://www.wearedevelopers.com/videos/936-real-world-threat-modeling) - [Data Science on Software Data](https://www.wearedevelopers.com/videos/162-data-science-on-software-data) - [Building Accountability in Agentic AI](https://www.wearedevelopers.com/videos/100046-building-accountability-in-agentic-ai) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Data Analyst Salary in Switzerland](https://www.wearedevelopers.com/magazine/276-data-analyst-salary-in-switzerland) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)