Cybersecurity Threat Intelligence Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+7 more
Job description
NiSource is one of the largest fully regulated utility companies in the U.S., serving millions of customers across six states. We’re more than an energy provider-we’re a team committed to innovation, inclusion, and growth. At NiSource, you’ll find a workplace that encourages collaboration, supports professional development, and empowers employees to make an impact.
The Cybersecurity department ensures the confidentiality, integrity, and availability of NiSource assets to achieve the company mission. We excel in engineering sophisticated defenses, architecting resilient systems, and proactively defending the vital cyber infrastructure that is crucial to our business operations. At NiSource, the Cybersecurity Consultants provide the critical bridge between security theory and practice, offering insights that shape our security strategies
The Cybersecurity and Physical Threat Intelligence Team plays a pivotal role in identifying and analyzing cyber and physical threats, emerging risks, and industry developments. Our team partners closely with Cybersecurity Incident Response, Physical Security Operations, Cyber Risk Management, and various other partners to detect and mitigate potential threats to the business across our digital and physical environments. As cyber and physical threats continue to converge, our fused intelligence program drives cohesion, a proactive approach, and strengthens information-sharing practices across the Enterprise Security department.
As a Cybersecurity Threat Intelligence Analyst, you will collect, analyze, and interpret threat data, build strategic intelligence products based on documented trends, employ frameworks such as NIST CSF, and inform security protocols based on actionable intelligence. You will have the opportunity to support and further develop insider risk projects and insider threat investigations. You will work with a range of stakeholders across Enterprise Security to deliver intelligence-led insights for incident response, threat hunting, and cyber defense activities. You will also play a key role in improving intelligence processes, reporting, and automation capabilities while building strong relationships across the organization and with external partners.
Your responsibilities may include, but are not limited to:
- Monitor, analyze, track, and report on evolving threat trends related to the company, industry, or critical infrastructure and national security more broadly
- Conduct advanced open-source intelligence (OSINT) research and investigations into cyber threat actors, origins, motives, TTPs, emerging trends, and geopolitical developments. Assess how geopolitical and societal developments drive cyber activity over time and impact the organization
- Synthesize large volumes of multi-source intelligence and technical processes into concise products and executive-level briefings to ensure that senior leaders get a clear understanding of threat activity, related risks, business implications, and recommended mitigations or controls
- Support tactical intelligence collection and reporting, including monitoring for indicators like IOCs or malicious IPs, leveraging tools for detection, and validation within NiSource systems, and providing actionable intelligence to Incident Response
- Respond and support Cybersecurity or Physical Security teams during high-impact incidents. Compile available intelligence into timely, high-confidence products
- Continue to update key stakeholders throughout a security or crisis event to provide essential information, translate technical information for a business audience, and support overall business response and recovery efforts
- Assist in developing new intelligence reporting thresholds, templates, products, and data collection mechanisms
- Develop and maintain intelligence metrics, dashboards, investigative records, and KPIs to ensure that team activities are measurable and aligned to business objectives
- Utilize intelligence tools and platforms such as Dataminr, Recorded Future, ZeroFox, and other OSINT capabilities to support routine monitoring, investigations, and analysis
- Facilitate and develop new data connections for Power BI dashboards (database development) used for insider risk detection and tracking. Perform regular updates to API connections and dashboards as the Insider Risk and Threat programs evolve
- Collaborate closely with other team members and Cybersecurity verticals to conduct investigations, validate findings, support incident response efforts, and enhance information sharing across the physical and cyber disciplines
- Participate periodically in procedural audits, analytic reviews, lessons-learned sessions, or after-action reports
- Continuously refine sourcing strategies and help evaluate technology needs within the changing AI and information security environment
- Contribute to updating team methodologies and build on intelligence tradecraft through professional development opportunities
- Participate in collaborative benchmarking discussions with internal and external partners, including government and law enforcement agencies
You must possess the below minimum qualifications to be initially considered for this position. Preferred qualifications are in addition to the minimum requirements and are considered a plus factor in identifying top candidates., #Cybersecurity #CyberThreatIntel #ThreatIntelligence #ThreatHunting #IntelligenceAnalysis #ProtectiveIntelligence #WomenInTech #HybridJob #OhioMeansJobs #Columbus #Ohio #OH #NowHiring #BI #BusinessIntelligence #DataAnalysis #DataSci #DataAnalyst #PowerBI #Databricks #AzureDatabricks #SQL #Python #DataVisualization #Chicago
As a public utility, NiSource is required to provide continuous service to customers at all times. To ensure we fulfill that obligation, employees may be required to work outside their normal work hours and perform tasks outside of their normal responsibilities in support of emergency operations.
Work Authorization
Authorized to work in the United States without requiring sponsorship.
Workplace Connection Value inclusion within your day to day responsibilities by respecting others perspectives/convictions, engaging others opinions, creating a safe environment where people, ideas, and opinions are valued within your Team/Customers and external partners.
Respect the unique lived experiences within your Team/Customers and external work partners by valuing different world views, challenges, and cultures that represents all walks of life and all backgrounds.
Treat others with respect and consideration. Actively participate in creating and contributing to a positive work environment., Promote a safe work environment by actively participating in all aspects of our employee safety program. Report any unsafe conditions and take actions to prevent personal injuries. Support our interdependent safety culture by ensuring the safety of your co-workers. Stay focused on the task at hand and promote productivity through good work habits.
Requirements
- Bachelor’s degree or equivalent experience
- 4+ years of experience in Cyber Threat Intelligence, Cyber Security Operations, Incident Response, Intelligence Analysis, or related fields in the public or private sectors
- 4+ years of experience applying the intelligence lifecycle, MITRE ATT&CK framework, cybercrime analysis, threat actor tactics and techniques, or cyber risk management principles
- 4+ years of experience producing all-source intelligence reports, briefings, and assessments for both technical and senior business audiences
- 4+ years of experience utilizing threat intelligence platforms and OSINT tools such as Dataminr, Recorded Future, ZeroFox, Flashpoint, CrowdStrike, or Google SecOps/CTI
- 2+ years of experience in database and dashboard development, ideally with the Azure Databricks Lakehouse platform and Power BI
- Proficiency in Python (PySpark) and Spark SQL for large-scale data transformation, * Advanced degree or industry certifications such as GCTI, CTIA, CISSP, GIAC, SANS, or equivalent
- 5+ years in a strategic Cyber Threat Intelligence role with experience developing a wide array of analytic intelligence products for senior leaders and iterating on intelligence processes, methodologies, and program KPIs
- Excellent writing, verbal, and interpersonal skills
- Ability to adapt to a fast-paced and innovative work environment
- Strong analytical, problem-solving, and communication skills, with the ability to translate complex cyber issues into clear and actionable insights
- Experience with the utility or energy industry
- Experience with AI and ML technologies in Cybersecurity, NiSourceparticipates in the U.S. Department of Homeland Security’s E-Verify program. As part of this process, we provide the following notices to all job applicants: These documents inform you of your rights and responsibilities under U.S. law. You can view or download them using the links below:
- E-Verify Poster(English and Spanish) E-Verify Participation Poster English and Spanish
- Right to Work Poster(English and Spanish) If you have the right to work, don’t let anyone take it away
Salary Range*: $96,600.00 - $144,900.00
*The salary offered to a candidate is based on several factors including but not limited to the candidate’s skills, job-related knowledge, and relevant experience, as well as internal pay equity.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Software Developer Salary in The Netherlands [2023]
Highest Paying Tech Companies for Developers
Best Companies in the Netherlands: Top 25 Companies in 2023Â
Average Salary in The Netherlands