> Markdown version of [/jobs/ext/2024444-cyber-threat-intelligence-analyst](https://www.wearedevelopers.com/jobs/ext/2024444-cyber-threat-intelligence-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Threat Intelligence Analyst - **Company:** Neos Consulting - **Location:** Austin, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Program Optimization, Cyber Security, Monitoring of Systems, Intelligence Analysis, Python (Programming Language), Windows PowerShell, Security Software, Security Information and Event Management, Systems Integration, Software Vulnerability Management, Mitre Att&ck, QRadar, Cyber Threat Analysis, Microsoft Sentinel, CIS Benchmarks, Splunk, Servicenow - **Published:** August 11, 2026 - **Apply:** https://www.dice.com/job-detail/a50ae4fe-c168-495b-a22c-e5f988b6af55 ## About the Role * 5 years Experience performing cyber threat intelligence analysis within a Security Operations Center (SOC) or Cybersecurity Operations environment. * 5 years Experience with threat intelligence platforms such as Recorded Future, CrowdStrike Intelligence, Anomali, Mandiant, Flashpoint, or equivalent. * 5 years Experience analyzing Indicators of Compromise (IOCs), adversary TTPs, malware campaigns, and vulnerability intelligence. * 5 years Experience creating and managing security incidents, case management workflows, and incident escalation processes. * 5 years Experience with SIEM technologies and intelligence feed integration. * 5 years Knowledge of cybersecurity frameworks including MITRE ATT&CK, NIST Cybersecurity Framework, and CIS Controls. * 5 years Experience communicating cybersecurity risks and intelligence findings to technical and non-technical stakeholders. * 5 years Strong written communication, documentation, reporting, and analytical skills. Preferred Skills and Qualifications * Certified Threat Intelligence Analyst (CTIA) certification. * GIAC Cyber Threat Intelligence (GCTI) certification. * Experience administering Recorded Future platforms and intelligence modules. * Experience integrating threat intelligence with Splunk, Microsoft Sentinel, QRadar, or equivalent SIEM platforms. * Experience integrating cybersecurity tools with ServiceNow. * Experience managing third-party risk intelligence or vendor intelligence programs. * Experience with TAXII/STIX frameworks and automated intelligence sharing. * Knowledge of vulnerability management, CVE monitoring, and zero-day response processes. * Experience with scripting and automation using PowerShell or Python. * Familiarity with state government cybersecurity operations and compliance requirements. ## Description The Cybersecurity Operations Center (CSOC) Threat Intelligence Analyst is responsible for monitoring, analyzing, and operationalizing cyber threat intelligence across enterprise environments. This role ensures actionable intelligence is identified, prioritized, and disseminated to appropriate stakeholders to reduce cybersecurity risk and improve organizational awareness. The selected individual will be responsible for administering threat intelligence platforms, supporting incident response activities, and integrating intelligence capabilities into existing security operations processes. Team member will provide services in the following areas: * Triage threat intelligence alerts generated from intelligence platforms and external intelligence sources. * Create Security Incidents and route them to appropriate teams for investigation and resolution. * Analyze, validate, and distribute Critical and Zero-Day CVE advisories to impacted stakeholders. * Administer threat intelligence platforms, including tuning, scoping, content management, reporting, and platform optimization. * Upload, validate, and maintain TxDOT organizational data within intelligence platforms, including user account inventories, technology asset information, business partner listings, and third-party vendor data. * Manage intelligence feed subscriptions and ensure threat intelligence data is properly integrated into cybersecurity monitoring systems. * Verify threat intelligence feed ingestion into SIEM platforms and troubleshoot feed-related issues. * Integrate threat intelligence platforms with TxDOT systems, including SIEM, ServiceNow, ticketing workflows, and reporting solutions. * Develop operational reports, threat trend summaries, and executive-level intelligence briefings. * Collaborate with Incident Response, Security Operations, Vulnerability Management, and Infrastructure teams to support threat investigations and remediation activities. * Conduct threat analysis and forecasting to identify emerging risks affecting TxDOT systems, vendors, and business functions. * Maintain documentation, procedures, and intelligence workflows supporting cybersecurity operations. ## Related Videos - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) - [Forecasting Cyber Attacks with Glassdoor Reviews - Lianne Potter](https://www.wearedevelopers.com/videos/2143-forecasting-cyber-attacks-with-glassdoor-reviews-lianne-potter) - [Robots are coming into the wild! Full-Stack Robotics Engineers, be ready!](https://www.wearedevelopers.com/videos/479-robots-are-coming-into-the-wild-full-stack-robotics-engineers-be-ready) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)