> Markdown version of [/jobs/ext/1642773-threat-intelligence-analyst-associate-security-operations](https://www.wearedevelopers.com/jobs/ext/1642773-threat-intelligence-analyst-associate-security-operations). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Threat Intelligence Analyst, Associate - Security Operations - **Company:** The Blackstone Group L P - **Location:** New York, NY, United States - **Experience:** Experienced - **Salary:** $135,000.0 - $170,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cyber Security, Computer Programming, Computer Telephony Integration, Cursor (Graphical User Interface Elements), Programming Tools, Intrusion Detection and Prevention, Python (Programming Language), Open Source Technology, Open Source Intelligence, Kusto Query Language, Security Information and Event Management, Software Vulnerability Management, Scripting, Cloud Platform System, GitHub Copilot, Large Language Models, Mitre Att&ck, Cyber Threat Analysis, Information Technology, Cybercrime, Cyber Warfare, Splunk, GPT - **Published:** July 11, 2026 - **Apply:** https://blackstone.wd1.myworkdayjobs.com/Blackstone_Careers/job/New-York/Threat-Intelligence-Analyst--Associate---Security-Operations_43986-1 ## About the Role * 2+ years of experience in cyber threat intelligence, security operations, incident response, or a related cybersecurity discipline * Demonstrated understanding of the cyber threat landscape, including prominent threat actor groups, campaigns, and TTPs * Working knowledge of intelligence frameworks such as MITRE ATT&CK, the Diamond Model, or the Intelligence Cycle * Experience with threat intelligence platforms (TIPs), SIEM tools (e.g., Splunk), OSINT research methodologies, or attack surface management / vulnerability management tooling * Scripting or programming experience (Python preferred) for automating data collection, enrichment, and analytic workflows * Demonstrated, hands-on experience applying AI tooling (such as LLMs and coding assistants) to real work, and can clearly speak to several projects where you used AI to automate or accelerate a task * Capable of writing clearly and developing visual products (such as diagrams) to communicate complex cyber threats to both technical and non-technical stakeholders, including executive leadership * Strong analytical reasoning, attention to detail, and capable of prioritizing effectively in a fast-paced environment * B.S. in Computer Science, Cybersecurity, Intelligence Studies, International Relations, or a related field Preferred Qualifications * Experience in the financial sector or an organization with a global threat landscape * Hands-on experience with Attack Surface Management platforms (e.g., Mandiant ASM, CrowdStrike Falcon Surface, Microsoft Defender EASM, or similar) * Hands-on experience with specific AI developer tooling, such as LLM assistants and APIs (e.g., ChatGPT/OpenAI, Claude/Anthropic, Gemini), coding assistants (e.g., GitHub Copilot, Cursor), or agentic and automation frameworks * Experience with vulnerability management programs, including prioritization frameworks (CVSS, EPSS, CISA KEV) and remediation tracking * Familiarity with structured analytic techniques and intelligence writing standards * Experience with detection content development (Sigma, YARA, Splunk SPL, or KQL) * Active participation in industry working groups, ISACs, or CTI community forums * Relevant certifications (GIAC GCTI, Security+, CTIA, or similar) * Exposure to cloud environments (AWS, Azure) and an understanding of cloud-specific threat vectors ## Description The Cyber Threat Intelligence (CTI) team within Blackstone Security Operations identifies, tracks, and assesses cyber threats relevant to Blackstone and its portfolio companies. The Associate Threat Intelligence Analyst conducts tactical, operational, and strategic analysis to inform defensive operations, risk decisions, and executive awareness. This is a team at the cutting edge of cyber defense: we are pioneering the use of AI and automation to outpace adversaries, we move quickly from idea to production, and we give analysts real ownership to shape how intelligence is practiced rather than slot into a routine. This is hands-on intelligence and engineering work: monitoring the evolving threat landscape, producing finished intelligence products and reports, extracting and enriching indicators of compromise (IOCs), and helping manage the firm's external attack surface and exposure risk. The analyst leverages AI and automation tooling to collect, enrich, and operationalize intelligence at scale, and develops clear visual products such as diagrams to make threats understandable to both technical and non-technical audiences. The role works closely with detection engineering, incident response, and vulnerability management to turn intelligence into new detections and preventions, helping protect one of the world's leading investment platforms where cybersecurity and global finance meet. Responsibilities * Monitor and analyze cyber threat activity targeting the financial sector, alternative asset management, and adjacent industries using open-source, commercial, and internal sources, correlating across them to identify patterns and provide early warning of emerging campaigns * Produce finished intelligence products and reports including recurring threat reporting, advisories, campaign profiles, actor dossiers, executive briefings, and visual products such as diagrams, tailored to both technical and non-technical audiences * Map adversary behaviors to the MITRE ATT&CK framework and maintain threat actor profiles covering TTPs, intent, and relevance to Blackstone * Extract, validate, enrich, and operationalize indicators of compromise (IOCs) to support detection engineering and incident response workflows * Leverage AI and automation tooling to scale collection, enrichment, and operationalization of intelligence * Partner with Alert, Detection & Response and Incident Response teams to translate intelligence into production detections (Splunk SPL, Sigma, YARA) * Track zero-day and critical vulnerabilities, assess Blackstone's exposure, and translate findings into new detections and preventions in coordination with detection and security engineering * Support threat-informed vulnerability prioritization (CVSS, EPSS, CISA KEV) and coordinate remediation tracking with asset owners * Operate and evolve the firm's external Attack Surface Management (ASM) program, discovering and inventorying internet-facing assets across Blackstone and its portfolio companies, triaging newly discovered exposures and misconfigurations, and coordinating remediation * Support Fusion Center digital-threat monitoring, including brand, executive, and reputational exposure across OSINT, social media, and dark web sources * Contribute to intelligence sharing with trusted industry partners, ISACs (such as FS-ISAC), government partners (such as JCDC), and peer financial institutions * Participate in incident response and the SOC on-call rotation (occasional, roughly every other month) to respond to escalated security incidents, * Attending client meetings where you are discussing Blackstone products and/or and client questions; * Marketing Blackstone funds to new or existing clients; * Supervising or training securities licensed employees; * Structuring or creating Blackstone funds/products; and * Advising on marketing plans prepared by a sales team or developing and/or contributing information for marketing materials. Note: The above list is not the exhaustive list of activities requiring securities licenses and there may be roles that require review on a case-by-case basis. Please speak with your Blackstone Recruiting contact with any questions. ## Related Videos - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [ Evaluating AI models for code comprehension](https://www.wearedevelopers.com/videos/1462-evaluating-ai-models-for-code-comprehension) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [The AI Security Survival Guide: Practical Advice for Stressed-Out Developers](https://www.wearedevelopers.com/videos/1015-the-ai-security-survival-guide-practical-advice-for-stressed-out-developers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)