> Markdown version of [/jobs/ext/524530-cyber-threat-intelligence-analyst-sr-itss-its-department-temporary-full-time](https://www.wearedevelopers.com/jobs/ext/524530-cyber-threat-intelligence-analyst-sr-itss-its-department-temporary-full-time). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Threat Intelligence Analyst (Sr.ITSS) - ITS Department - Temporary Full Time - **Company:** City of Phoenix - **Location:** Phoenix, AZ, United States (Remote available) - **Experience:** Expert - **Salary:** $93,122.0 - $131,040.0 - **Contract:** Temporary contract - **Skills:** Business Systems, CompTIA Security+, Cyber Security, Information Systems, Computer Telephony Integration, Technical Data Management Systems, Cyber Threat Analysis, Information Technology, Cybercrime, Cisco - **Published:** June 10, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=9ed1fb8badd0188e ## About the Role Do you have a valid Driver's License license?, Do you have experience in Research?, Do you have a Bachelor's degree?, Ability to : * Analyze complex procedures and provide feedback for improvements. * Handle high-pressure situations and adapt to rapidly changing environments. * Work independently or within teams of both technical and nontechnical staff. * Identify potential issues and implementing solutions before they escalate. * Communicate effectively with technical and nontechnical stakeholders, including writing clear incident reports and documentation., * Two years of experience as an Information Technology Systems Specialist within a cybersecurity, information security, or information technology environment. * Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Technology, or a related field. * Other combinations of experience and education that meet the minimum requirements may be substituted. * This position is subject to Criminal Justice Information Systems (CJIS) background standards. Candidates who receive a conditional offer of employment must be fingerprinted and will have their fingerprints used to check the Criminal History Records of the State of Arizona Department of Public Safety and the Federal Bureau of Investigation. Any records returned will be reviewed to determine the candidate's suitability for the job. * All finalists for positions are subject to a criminal background check applicable to the department or position. * This position requires the use of personal or City vehicles on City business. Individuals must be physically capable of operating the vehicles safely, possess a valid driver's license and have an acceptable driving record. Use of a personal vehicle for City business will be prohibited if the employee is not authorized to drive a City vehicle or if the employee does not have personal insurance coverage. For information regarding pre-screening and driving positions, The minimum qualifications listed above, plus: * Five years of experience in cyber threat intelligence. * Experience in/with: + Evaluating business systems to identify cybersecurity risks and reporting findings. + Developing defense plans or tactics, using intelligence and other information. + Researching and tracking specific cyber-threat groups or malicious actor behaviors. + Writing and presenting intelligence briefs and threat assessments tailored for leadership, as well as both technical and nontechnical audiences. * Professional certifications supporting Cyber Threat Intelligence, such as CTIA, GCTI, CISSP, CompTIA Security+, CEH, Cisco Certified CyberOps Associate, or Offensive Security Certified Professional (OSCP) ## Description The IT department is seeking a Cyber Threat Intelligence Analyst (SrITSS) to join the Threat Intelligence Team within the Information Security Operations and Intelligence Division. The Cyber Threat Intelligence Analyst (CTI) will serve as a proactive defense strategist safeguarding the City's digital infrastructure. This role will anticipate and analyze the tactics, techniques, and motivations of threat actors targeting major metropolitan environments. The CTI will transform raw intelligence into actionable insights, enabling the City to implement preventative cybersecurity measures before incidents occur. This position is key to bridging technical intelligence and organizational risk, ensuring the City remains resilient against an evolving threat landscape., * Threat Anticipation: Conduct ongoing research into global cyber threats, campaigns, and adversary groups to identify risks relevant to a municipal environment. * Proactive Analysis: Convert unstructured technical data into clear, actionable intelligence reports that support timely decision-making and security resource prioritization. * Strategic Briefing: Present complex threat information to both technical teams and nontechnical stakeholders, including City leadership, to inform long-term cybersecurity strategies. * Defensive Collaboration: Work closely with security engineering and incident response teams to update and enhance defensive controls based on emerging adversary tactics and patterns. Please note: This position requires participation in an on-call rotation which may include nights, weekends, evenings, early mornings, and holidays as needed. This is a hybrid position which is eligible to telework up to four days a week, and requires the ability to attend meetings and trainings in-person at a designated City work location when required, based on operational needs. This position will be funded through June 2027 with a possibility to be made regular in a future budget cycle. The temporary position will have benefits but will not earn city retirement credits or participate financially into the city's retirement program. If the successful candidate is a current City employee, all benefits will still be applicable, and the employee will still contribute to their pension. Temporary positions are not covered under civil service rules, and thus employment is considered "at-will", and employees may be separated at any time. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Forecasting Cyber Attacks with Glassdoor Reviews - Lianne Potter](https://www.wearedevelopers.com/videos/2143-forecasting-cyber-attacks-with-glassdoor-reviews-lianne-potter) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [IT Salaries in Austria](https://www.wearedevelopers.com/magazine/286-it-salaries-in-austria)