> Markdown version of [/jobs/ext/70772-senior-cyber-threat-intel-analyst](https://www.wearedevelopers.com/jobs/ext/70772-senior-cyber-threat-intel-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cyber Threat Intel Analyst - **Company:** Financial Industry Regulatory Authority, Inc. - **Location:** Philadelphia, PA, United States - **Experience:** Expert - **Salary:** $114,200.0 - $248,700.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Computer Forensics, Intelligence Analysis, Cisco Nexus Switches, Web Intelligence, Mitre Att&ck, Cyber Threat Analysis, Data Analytics - **Published:** May 13, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=57e2dd9ea0fafae8 ## About the Role Do you have experience in Securities law?, Do you have a Bachelor's degree?, * Bachelor's degree or equivalent combination of education and experience * Intermediate securities, compliance, or financial regulatory experience * Advanced experience in cybersecurity risks, threat intelligence, or operational resilience Knowledge: * Intermediate knowledge of FINRA's eleven risk fundamentals * Intermediate knowledge of securities rules and regulations * Advanced-to-expert knowledge of cyber risks, threat landscapes, and intelligence analysis specific to your specialization Skills: * Advanced-to-expert written and oral communication skills-you can translate complex threats into clear, actionable guidance * Advanced-to-expert negotiation skills and ability to build collaborative relationships with diverse stakeholders * Advanced-to-expert organizational, planning, and prioritization skills * Advanced-to-expert resiliency-you adapt and thrive under pressure and uncertainty, * Major in Accounting, Finance, Economics, Business Administration, Cybersecurity, Computer Forensics, Data Analytics, or related fields * Advanced degree or professional certification (e.g., CISSP, CISM, CRISC, GIAC certifications) * Series 99 license * Strong technical background with demonstrated expertise in cyber threat intelligence platforms (e.g., MISP, ThreatConnect, Recorded Future), threat analysis frameworks (e.g., MITRE ATT&CK, Diamond Model), and risk assessment methodologies ## Description Are you a cyber threat intelligence expert ready to make a meaningful impact on the financial industry's resilience? As a Senior Principal Risk Specialist on FINRA's Cyber & Operational Resilience (CORE) team, you'll be at the nexus of cybersecurity intelligence and regulatory oversight-transforming threat data into actionable insights that protect member firms and, ultimately, millions of investors. In this role, you'll serve as a critical bridge between the rapidly evolving cyber threat landscape and the securities industry. You'll monitor emerging threats, analyze intelligence from diverse sources, and translate complex risk scenarios into clear guidance that helps firms strengthen their defenses. This isn't a desk-bound analyst position-you'll lead high-complexity examinations, consult directly with member firms, and share your expertise through training, conferences, and industry events. If you're energized by the challenge of staying ahead of sophisticated threat actors while building collaborative relationships across the industry, this role offers the perfect blend of technical depth, strategic influence, and mission-driven impact. What You'll Do * Drive Cyber Intelligence & Risk Analysis: Monitor and analyze cyber threat intelligence from multiple sources-including threat feeds, vendor reports, dark web intelligence, and incident data. Produce timely cyber event risk assessments and disseminate actionable insights to member firms to enhance their defensive posture. * Assess Vendor & Concentration Risks: Monitor vendor risk reports to identify concentration risks and vulnerabilities in key business functions across the industry. Integrate CORE findings into FINRA's internal risk assessment frameworks. * Serve as a Trusted Consultant: Respond to complex inquiries from Regulatory Operations teams, providing expert guidance on cyber risks with minimal supervision. * Educate & Influence the Industry: Share your expertise through conference panels, training seminars, boot camps, and district compliance events. Develop staff training materials, podcasts, and specialized content that elevates cybersecurity awareness across FINRA and the industry. * Embody FINRA's Values: Collaborate both in-person and virtually to advance investor protection and market integrity in everything you do., FINRA's Code of Conduct imposes restrictions on employees' investments and requires financial disclosures that are uniquely related to our role as a securities regulator. FINRA employees are required to disclose to FINRA all brokerage accounts that they maintain, and those in which they control trading or have a financial interest (including any trust account of which they are a trustee or beneficiary and all accounts of a spouse, domestic partner or minor child who lives with the employee) and to authorize their broker-dealers to provide FINRA with duplicate statements for all of those accounts. All of those accounts are subject to the Code's investment and securities account restrictions, and new employees must comply with those investment restrictions-including disposing of any security issued by a company on FINRA's Prohibited Company List or obtaining a written waiver from their Executive Vice President-by the date they begin employment with FINRA. Employees may only maintain securities accounts that must be disclosed to FINRA at one or more securities firms that provide an electronic feed (e-feed) of data to FINRA, and must move securities accounts from other securities firms to a firm that provides an e-feed within three months of beginning employment. You can read more about these restrictions here. As standard practice, employees must also execute FINRA's Employee Confidentiality and Invention Assignment Agreement without qualification or modification and comply with the company's policy on nepotism. Search Firm Representatives ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [PySpark - Combining Machine Learning & Big Data](https://www.wearedevelopers.com/videos/44-pyspark-combining-machine-learning-big-data) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [How Data is Shaping our Games](https://www.wearedevelopers.com/videos/176-how-data-is-shaping-our-games) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in Switzerland](https://www.wearedevelopers.com/magazine/276-data-analyst-salary-in-switzerland) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)