Cyber Threat Intelligence Analyst

General Motors
Warren, MI, United States
4 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Cyber Security Information Systems Computer Telephony Integration Open Source Technology Phishing Security Information and Event Management Mitre Att&ck Cyber Threat Analysis Information Technology Cybercrime Cyber Warfare

Job description

Experteer Overview In this role you will translate threat and vulnerability data into actionable intelligence to support GM’s cyber defense across IT, OT, and connected-vehicle environments. You’ll work as part of the CTI team to enrich indicators, track adversary TTPs, and support fast decision-making during incidents and RFIs. You’ll operate intelligence tooling (MISP, SIEM) to deliver concise insights for Protect, Detect, and Respond teams. You’ll collaborate with cross-functional partners and external stakeholders to align intelligence with GM’s priority risks and security objectives. This is a hands-on position with a focus on execution and measurable impact on GM’s defenses. Compensation / Benefits * Monitor and triage threat activity and emerging vulnerabilities across GM IT, OT, and connected-vehicle environments; assess impact and priority * Produce actionable intelligence products (bulletins, advisories, actor/campaign summaries) for technical and executive audiences * Maintain and enrich indicators of compromise, threat actor profiles, and integrate them into GM sensors, tools, and detection workflows * Ingest, normalize, and curate intelligence from ISACs, government, law enforcement, commercial feeds, and open sources using MISP and SIEM * Provide time-sensitive intelligence during incidents and complete RFIs with well-reasoned assessments * Collaborate with Cyber Defense, Product Cybersecurity, Manufacturing/OT, Third-Party Cybersecurity to align intelligence with GM priorities * Track adversary TTPs and map activity to MITRE ATT&CK to improve detection coverage and reduce risk * Contribute to CTI process improvements, playbooks, enrichment automation, and metrics to mature intelligence-driven defenses Tasks * 2+ years in cyber threat intelligence, security operations, incident response, threat hunting, or related cybersecurity discipline * Working knowledge of threat-intelligence lifecycle, indicators of compromise, and adversary TTPs; familiarity with MITRE ATT&CK and the Diamond Model * Ability to analyze security and threat data, correlate across sources, and communicate findings clearly to technical and non-technical audiences * Hands-on experience with threat-intelligence and detection tooling (e.g., MISP, SIEM, EDR/NDR) and open-source research techniques * Understanding of attacker techniques, malware behavior, phishing/credential-theft campaigns, and CVE/CVSS concepts * Strong written and verbal communication skills for concise intelligence products and time-sensitive assessments * Bachelor’s degree in Information Security, Computer Science, Information Systems, or equivalent practical experience Key requirements *

Requirements

  • and enrich indicators of compromise, threat actor profiles, and integrate them into GM sensors, tools, and detection workflows * Ingest, normalize, and curate intelligence from ISACs, government, law enforcement, commercial feeds, and open sources using MISP and SIEM * Provide time-sensitive intelligence during incidents and complete RFIs with well-reasoned assessments * Collaborate with Cyber Defense, Product Cybersecurity, Manufacturing/OT, Third-Party Cybersecurity to align intelligence with GM priorities * Track adversary TTPs and map activity to MITRE ATT&CK to improve detection coverage and reduce risk * Contribute to CTI process improvements, playbooks, enrichment automation, and metrics to mature intelligence-driven defenses Tasks * 2+ years in cyber threat intelligence, security operations, incident response, threat hunting, or related cybersecurity discipline * Working knowledge of threat-intelligence lifecycle, indicators of compromise, and adversary TTPs; familiarity with MITRE ATT&CK and the Diamond Model * Ability to analyze security and threat data, correlate across sources, and communicate findings clearly to technical and non-technical audiences * Hands-on experience with threat-intelligence and detection tooling (e.g., MISP, SIEM, EDR/NDR) and open-source research techniques * Understanding of attacker techniques, malware behavior, phishing/credential-theft campaigns, and CVE/CVSS concepts * Strong written and verbal communication skills for concise intelligence products and time-sensitive assessments * Bachelor’s degree in Information Security, Computer Science, Information Systems, or equivalent practical experience Key requirements *

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on us.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber ¡ WWC Europe 2026

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa ¡ LIVE

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa ¡ LIVE

11:26 min

Identifying system risks and collaborative ecosystem legal challenges

Hans-Jßrgen Eidler ¡ LIVE

2:11 min

Securing heterogeneous legacy payment infrastructure against AI

Michele Zuccala Michele Zuccala +4 ¡ WWC Europe 2026

3:24 min

Validating external integration security against cyber vulnerabilities

Torben Schramme ¡ WWC 2021

Videos

See all

Related articles

See all