> Markdown version of [/jobs/ext/2298831-csis-intelligence-lead-analyst-advanced-analytics-and-cyber-osint](https://www.wearedevelopers.com/jobs/ext/2298831-csis-intelligence-lead-analyst-advanced-analytics-and-cyber-osint). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # CSIS Intelligence Lead Analyst - Advanced Analytics and Cyber OSINT - **Company:** Citi - **Location:** Charlotte, NC, United States - **Experience:** Expert - **Salary:** $117,440.0 - $176,160.0 - **Contract:** Permanent contract - **Skills:** Bash Shell, Cyber Security, Intelligence Analysis, Python (Programming Language), Link Analysis, Log Analysis, Network Forensics, Open Source Technology, Open Source Intelligence, Windows PowerShell, Reverse Engineering, Software Engineering, Mitre Att&ck, Malware, Cyber Threat Analysis, Information Technology, Cybercrime - **Published:** August 29, 2026 - **Apply:** https://www.dice.com/job-detail/4527b68c-cbd9-4f36-a71c-d6ca3f2b37bd ## About the Role * 6-10 years of relevant experience * Should have a working knowledge in one or more of the following areas: Advanced Persistent Threat, Third Party Risks/Threats, Cybercrime, Extremist Groups and Cyber Terrorists, Hacktivism, Distributed Denial of Service attacks, Fraud, Malware, Mobile Threats * Proven track record of operationalizing cyber threat intelligence - translating raw intelligence into detections, hunt packages, and risk-relevant reporting. * Consistently demonstrates clear and concise written and verbal communication * Proven influencing and relationship management skills * Proven analytical skills, * Bachelor's degree/University degree or equivalent experience * Master's degree preferred (Advanced degree preferred, ideally in Computer Science, Cybersecurity, Information Security, or a related STEM discipline) * Additional valued certifications include: CREST CCTIM, Recorded Future Certified Analyst, CISSP, CEH, or OSCP., * Proficiency in the MITRE ATT&CK framework - mapping adversary TTPs, building hunt hypotheses, and driving detection coverage analysis. * Hands-on experience with Threat Intelligence Platforms including Recorded Future, Mandiant Advantage, ThreatConnect, MISP, or OpenCTI. * Experience with scripting and automation languages including Python, PowerShell, and Bash for intelligence collection, enrichment pipelines, and hunt tooling development. * Advanced OSINT tradecraft including dark web monitoring, social media intelligence, infrastructure pivoting, and digital footprint analysis. * Experience with link analysis platforms such as Palantir, Maltego, and i2 Analyst's Notebook, including building custom extractors, web scrapers, and automation workflows to support investigative and analytical tasks. * Solid understanding of network forensics, log analysis, and reverse engineering in support of hunt operations. * Working knowledge of malware analysis (static and dynamic) and adversary infrastructure analysis. * Exceptional written and verbal communication skills with the ability to produce intelligence products for both technical and executive audiences, consistently demonstrating clarity, conciseness, and attention to detail. * Proven influencing, relationship management, and analytical skills with a track record of driving outcomes across cross-functional teams. ## Description We're looking for a sharp, driven Intelligence Lead Analyst to join a team that doesn't just analyze intelligence - it builds the tools that collect it. In this senior-level role, you'll take ownership of maintaining and enhancing our link analysis frameworks while engineering in-house solutions to automate intelligence collection at scale. Your work will directly shape how we identify, pursue, and neutralize threats across one of the world's largest financial institutions. This role is fundamentally about two things: Cyber OSINT mastery and technical innovation. If you thrive at the intersection of intelligence analysis and software development, this is your opportunity., The Intelligence Senior Analyst is an senior-level position responsible for collection/analysis of IoCs and TTPs, maintaining and updating existing link analysis frameworks while also developing in-house solutions to automate intelligence collection. The primary objective of this role is to leverage Open Source Intelligence (OSINT) and development skills to build and operate advanced intelligence capabilities. While familiarity with the cyber domain is welcome, the core focus is on OSINT analysis and the creation of automated collection tools., * Fulfill cyber OSINT requests by applying advanced analysis tools and techniques to surface timely, actionable intelligence. * Proactively anticipate gaps in our intelligence posture and develop innovative solutions, collaborating with internal and external stakeholders on open-source methodologies and tooling. * Design (develop), implement, and maintain in-house solutions for collecting, processing, and analyzing open source data. * Automate intelligence collection capabilities, leveraging existing link analysis frameworks and actively identifying and evaluating alternative solution providers. * Apply in-depth disciplinary knowledge to triage, process, and analyze intelligence alerts, reports, and briefings. * Engage in liaison activities with developers, intelligence communities, law enforcement, industry partners, peer financial institutions, and information sharing communities. * Manage multiple projects simultaneously with a proactive, self-motivated approach, ensuring timely delivery of high-quality results while collaborating effectively with global teams. * Complete the daily operational components of the intelligence mission. * Assume an informal/formal mentor role within teams and assist with the coaching and training of new team members. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Old tools, new tricks](https://www.wearedevelopers.com/videos/1916-old-tools-new-tricks) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [MCP doesn’t suck — your agent does](https://www.wearedevelopers.com/videos/100202-mcp-doesn-t-suck-your-agent-does) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Top 6 Hackathons for Developers in 2023](https://www.wearedevelopers.com/magazine/263-top-6-hackathons-for-developers-in-2023)