> Markdown version of [/jobs/ext/3066557-cybersecurity-intelligence-senior-associate-applied-cyber-threat-research-actr](https://www.wearedevelopers.com/jobs/ext/3066557-cybersecurity-intelligence-senior-associate-applied-cyber-threat-research-actr). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Intelligence Senior Associate - Applied Cyber Threat Research (ACTR) - **Company:** JPMorgan Chase & Co. - **Location:** Tampa, FL, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Artificial Intelligence, Bash Shell, Cyber Security, Integrated Development Environments, Python (Programming Language), Log Analysis, Network Forensics, Open Source Technology, Open Source Intelligence, Windows PowerShell, Rapid Prototyping Process, Red Team (Cyber Security), Security Information and Event Management, Scripting, GitHub Copilot, Mitre Att&ck, Cyber Threat Analysis, Cybercrime, Purple Team (Cyber Security), Cyber Warfare - **Published:** September 25, 2026 - **Apply:** https://www.jobmonkeyjobs.com/career/28054279/Cybersecurity-Intelligence-Senior-Associate-Applied-Cyber-Threat-Research-Actr-Florida-Tampa-7463 ## About the Role * 4+ years of experience in cyber intelligence, threat assessment, or security research, focusing on cyber threat research and analysis. * Ability to operationalize MITRE ATT&CK - converting adversary TTPs into attack flows, mapping techniques to controls and attack surface, and framing gaps and priorities against the current threat landscape. * Proficiency with open-source intelligence (OSINT) collection across diverse sources - including the surface, deep, and dark web as well as social media platforms - and the ability to review, corroborate, and validate collected data for reliability and analytic value before use. * Practical experience with modern integrated development environments (e.g., VS Code) and AI-assisted / agentic coding tools (e.g., Claude Code, GitHub Copilot) to accelerate the rapid prototyping, building, and testing of tools and automations - paired with the judgment to validate and review AI-generated outputs before use. Preferred qualifications, capabilities, and skills * Proficiency in scripting languages (Python, Bash, JavaScript, PowerShell) with experience in automating threat detection, analysis, and response. * Experience within the Intelligence Community, Defense Intelligence Enterprise, or the broader Military Intelligence community, U.S. Government agencies, and interagency partners (e.g., DHS, DoD, DOJ, and other federal/interagency organizations) - bringing insight into adversary operations, intelligence tradecraft, and state-sponsored threats. * Understanding of and ability to action the intelligence lifecycle. * Experience with SIEM/EDR tools, log analysis, and network traffic analysis to detect and investigate malicious or anomalous activity. ## Description * Conducts all-source analysis - fusing multiple intelligence and data sources (e.g., threat reporting, OSINT, technical telemetry, incident data, and vendor intelligence) into a coherent, corroborated intelligence picture and narrative. * Builds and visualizes attack flows using the MITRE ATT&CK framework - mapping adversary TTPs to security controls and attack surface, highlighting control gaps, and framing findings and priorities against the current threat landscape. * Develops finished intelligence assessments for a range of stakeholders at the tactical, operational, and strategic levels - spanning specific technologies and applications as well as new business contexts such as mergers and acquisitions targets and unfamiliar industries - to identify vulnerabilities, characterize relevant threats and adversary interest, and inform strategies to mitigate cyber risk across the organization and its systems. * Conducts open-source collection across the surface, deep, and dark web and social media platforms, then reviews, corroborates, and validates collected data for reliability and analytic value before use. * Proactively monitors and analyzes global cyber threats and performs in-depth research that supports broader cyber operations objectives (e.g., Threat Hunting, Red Team, Purple Team). * Designs and improves tools and automations using reuse-first, AI-assisted approaches to accelerate intelligence collection and triage workflows. * Uses enterprise-authorized AI capabilities to accelerate threat research synthesis and threat assessment, grounding outputs in evidence and validating results before use. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Old tools, new tricks](https://www.wearedevelopers.com/videos/1916-old-tools-new-tricks) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [MCP doesn’t suck — your agent does](https://www.wearedevelopers.com/videos/100202-mcp-doesn-t-suck-your-agent-does) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)