Mid-Level Cyber Threat Intelligence Analyst
Role details
Job location
Tech stack
Job description
The Mid-Level Cyber Threat Intelligence Analyst is responsible for identifying, analyzing, and communicating cyber threats that may impact the organization, its technology ecosystem, and its third-party partners. This role combines traditional CTI responsibilities with a growing emphasis on Cyber Supply Chain Risk Management (C-SCRM) and the operationalization of intelligence through Splunk Enterprise Security and related security platforms.
The successful candidate will leverage intelligence from internal and external sources to identify adversarial activity, support threat hunting efforts, assess supply chain risks, and improve the organization''s overall security posture., * Monitor, collect, analyze, and disseminate intelligence on cyber threats, threat actors, vulnerabilities, and emerging attack campaigns.
- Track adversary tactics, techniques, and procedures (TTPs) utilizing MITRE ATT&CK and other threat intelligence frameworks.
- Produce intelligence reports, threat assessments, executive summaries, and actionable recommendations.
- Research, validate, and operationalize indicators of compromise (IOCs) and indicators of attack (IOAs).
Supply Chain & Third-Party Risk Analysis
- Monitor cyber threats impacting software vendors, technology providers, service providers, and other critical third parties.
- Assess intelligence related to vendor compromises, ransomware activity, credential exposures, and software supply chain threats.
- Support Cyber Supply Chain Risk Management (C-SCRM) initiatives through analysis and reporting.
- Identify and communicate emerging cyber risks that could impact organizational operations or strategic partners.
Splunk Security Operations & Threat Hunting
- Utilize Splunk Enterprise Security and related technologies to correlate threat intelligence with internal security telemetry.
- Conduct proactive threat hunting activities across endpoint, network, cloud, identity, and application environments.
- Develop, optimize, and tune detection content using intelligence-driven analytics.
- Analyze large data sets to identify suspicious patterns, anomalies, and potential malicious activity.
Security Operations & Incident Support
- Partner with Security Operations Center (SOC), Incident Response, and Security Engineering teams to support investigations and response efforts.
- Provide intelligence context and attribution analysis for security incidents.
- Help improve threat detection and response capabilities through intelligence-driven recommendations.
- Participate in internal and external cybersecurity and intelligence-sharing forums.
- Develop and maintain procedures, intelligence documentation, and operational playbooks.
- Participate in on-call security operations activities as required.
Requirements
- Bachelor''s degree in Cybersecurity, Computer Science, Engineering, Mathematics, Physical Sciences, or a related field, or equivalent experience.
- 4+ years of experience in cybersecurity, threat intelligence, security operations, incident response, or a related discipline.
- Experience analyzing cyber threats, campaigns, and adversary behavior.
- Experience utilizing Splunk for security monitoring, investigation, analytics, or threat hunting.
- Strong understanding of:
- Network security concepts and protocols
- Windows, Linux, and macOS operating systems
- Incident response processes
- MITRE ATT&CK framework
- Adversarial TTPs and threat actor methodologies
- Strong analytical and problem-solving skills.
- Excellent written, verbal, and presentation skills.
- Ability to work independently and collaboratively within a fast-paced security environment., * Experience working within a formal Cyber Threat Intelligence (CTI) program.
- Experience supporting Cyber Supply Chain Risk Management (C-SCRM) initiatives.
- Experience with Splunk Enterprise Security, Threat Intelligence Platforms (TIPs), SOAR tools, and threat hunting programs.
- Cloud security experience in AWS, Azure, or Google Cloud Platform.
- Relevant industry certifications such as GCTI, GCIH, GCIA, CISSP, Security+, or similar.
Benefits & conditions
- Hybrid work model (3 days onsite in the Greater Phoenix area)
- Competitive medical, dental, and vision coverage
- Company-funded HSA contributions and FSA options
- 401(k) with 100% company match on the first 6% contributed
- Flexible Time Off, 11 paid holidays, and a paid volunteer day
- 12 weeks paid parental leave
- Comprehensive family-planning and parenting support, including fertility, adoption, surrogacy, pregnancy, and postpartum resources