> Markdown version of [/jobs/ext/2854519-cyber-threat-intelligence-cti-analyst](https://www.wearedevelopers.com/jobs/ext/2854519-cyber-threat-intelligence-cti-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Threat Intelligence (CTI) Analyst - **Company:** IMRI Technology & Engineering Solutions - **Location:** Los Angeles, CA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Cyber Security, Computer Telephony Integration, Intrusion Detection and Prevention, Open Source Intelligence, Mitre Att&ck, Cyber Threat Analysis - **Published:** September 11, 2026 - **Apply:** https://www.thejobnetwork.com/job/7c34c36d-07b2-4159-a00e-b539c5823f2f/cyber-threat-intelligence-cti-analyst ## About the Role * 5+ years of experience as a Cyber Threat Intelligence Analyst. * Strong experience producing intelligence products for various levels of leadership and operational teams. * Familiar with threat actor behavior, TTPs, and indicators tracking. * Solid understanding of CTI frameworks and the full intelligence lifecycle. * 2+ years working with commercial CTI platforms (e.g., Anomali, Recorded Future, ThreatConnect). * Experience with OSINT collection tools and techniques. * Strong problem-solving, critical thinking, and analytical skills. * Ability to communicate complex information clearly to both technical and non-technical stakeholders. * Proven ability to work independently and collaboratively in a fast-paced, high-security environment. * Familiarity with maritime or critical infrastructure sectors is a plus. ## Description * Perform technical threat analysis to identify and produce IOCs and IOAs based on real-time intelligence. * Leverage intelligence platforms and tools (e.g., Anomali) to monitor, analyze, and respond to security threats in support of 8x5 operations and after-hours escalation. * Conduct open-source intelligence (OSINT) gathering using tools like Shodan, Maltego, PassiveTotal, and VirusTotal. * Produce high-quality tactical, operational, and strategic intelligence reports for both internal teams and Port stakeholders. * Monitor, track, and become the subject matter expert (SME) on known adversaries and threat actors; escalate intelligence on active or emerging threats. * Apply analytic models including the Cyber Kill Chain, MITRE ATT&CK Framework, and Diamond Model to assess and report on cyber threat behavior. * Work cross-functionally with incident response, SOC, IT, and security operations teams to provide intelligence support. * Continuously improve detection logic and security controls by feeding intelligence back into detection engineering and threat hunting efforts. * Triage and prioritize threats, focusing on serious, credible intelligence that could impact critical operations. * Maintain detailed, clear documentation and contribute to evolving threat playbooks and response plans. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Real-world Threat Modeling](https://www.wearedevelopers.com/videos/936-real-world-threat-modeling) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Forecasting Cyber Attacks with Glassdoor Reviews - Lianne Potter](https://www.wearedevelopers.com/videos/2143-forecasting-cyber-attacks-with-glassdoor-reviews-lianne-potter) ## Related Articles - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)