> Markdown version of [/jobs/ext/95716-txcc-cybersecurity-analyst-iv-v-cti-senior-analyst](https://www.wearedevelopers.com/jobs/ext/95716-txcc-cybersecurity-analyst-iv-v-cti-senior-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # TXCC - Cybersecurity Analyst IV-V (CTI Senior Analyst) - **Company:** Texas Cyber Command - **Location:** San Antonio, TX, United States - **Experience:** Expert - **Salary:** $135,000.0 - $160,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, CompTIA Security+, Cyber Security, Computer Telephony Integration, Intelligence Analysis, Security Software, Large Language Models, Mitre Att&ck, Computerised Systems, Malware, Cyber Threat Analysis, Cybercrime - **Published:** May 27, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=9b5e43ce5c1787d3 ## About the Role Do you have experience in Threat intelligence?, * Seven (7) years of experience in cyber threat intelligence, all-source intelligence analysis, or a closely related analytic discipline * Demonstrated experience producing written intelligence products for varied audiences, from executive leadership to technical defenders * Working knowledge of adversary tradecraft, intrusion lifecycle concepts, and common analytic frameworks (e.g., MITRE ATT&CK, Diamond Model, kill chain) * Familiarity with indicator types, detection logic, and the lifecycle of technical indicators from discovery to dissemination * Ability to read and interpret technical artifacts (e.g., logs, network data, malware reports, vulnerability disclosures) to develop analytic judgments * Experience using AI-assisted tools in an analytic workflow Preferred Qualifications Experience: * Experience leading or coordinating cyber threat intelligence efforts, projects, or analytic initiatives * Experience producing intelligence for state, local, federal, or military consumers, or for critical infrastructure operators * Regional or actor-specific expertise in one or more of: China, Russia, Iran, or DPRK cyber programs * Sector-specific familiarity with energy, water, elections, public safety, healthcare, or financial services threat landscapes * Experience working alongside SOC, incident response, or threat hunting teams, including during active incidents * Familiarity with CTI platforms, indicator standards (e.g., STIX/TAXII), and detection languages (e.g., YARA, Sigma) sufficient to author or review content * Experience briefing senior executives or elected officials * Experience designing, integrating, or evaluating LLM-based analytic workflows, including prompt development and handling of sensitive data, * Certified Information Security Manager (CISM), and/or * CompTIA Security+ or CySA+ Knowledge, Skills, and Abilities Knowledge of advanced cybersecurity and cyber threat intelligence principles, methodologies, adversary tradecraft, and incident response practices Knowledge of computer systems, networks, operating systems, security technologies, and cybersecurity operational environments Knowledge of computer systems, networks, operating systems, applications, and security technologies, including their capabilities and limitations. Knowledge of intelligence analysis techniques, confidence assessment methodologies, structured analytic techniques, and intelligence reporting standards Skill in leading complex intelligence analysis efforts and producing high-quality intelligence products for executive and operational audiences Skill in synthesizing strategic, operational, and technical information into actionable intelligence and recommendations Skill in briefing, advising, and communicating effectively with technical personnel, executive leadership, and external stakeholders Skill in the use of cybersecurity tools, intelligence platforms, analytic technologies, and AI-assisted capabilities to support intelligence operations Ability to exercise expert judgment in evaluating intelligence, assessing confidence levels, and identifying limitations or gaps in available information Ability to coordinate intelligence activities across multidisciplinary teams and operational environments Ability to work independently with extensive latitude for initiative, prioritization, and decision-making in dynamic and evolving threat environments Ability to lead continuous improvement efforts, mentor personnel, and advance intelligence methodologies, processes, adn operational integration, We are unable to sponsor or take over sponsorship of an employment Visa at this time. Must be a citizen of the United States. ## Description The Senior Cyber Threat Intelligence Analyst performs highly advanced (senior-level) cybersecurity and intelligence analysis work leading complex cyber threat intelligence efforts that support Texas leadership, Texas Cyber Command operations, and external mission partners. The position serves as a senior analytic resource responsible for integrating strategic, operational, and technical intelligence to inform executive decision-making, support cybersecurity operations, and enhance statewide cyber resilience. Work includes leading high-impact intelligence initiatives, coordinating analytic efforts across teams and stakeholders, advancing intelligence tradecraft and methodologies, and providing expert guidance on emerging cyber threats, adversary capabilities, and risk trends affecting Texas government and critical infrastructure. Works under minimal supervision with extensive latitude for the use of initiative and independent judgment., Leads complex cyber threat intelligence analysis efforts and produces high-impact intelligence products supporting executive decision-making, operational planning, and cybersecurity operations. Directs and conducts advanced analysis of threat actors, campaigns, tactics, techniques, and procedures (TTPs), geopolitical developments, and emerging risks affecting Texas government and critical infrastructure. Develops strategic warning products, executive briefings, campaign assessments, actor profiles, and sector-specific intelligence reporting. Identifies long-term threat trends, systemic vulnerabilities, recurring exploit patterns, and emerging operational risks requiring enterprise attention Intelligence Integration, Coordination, and Operational Support Leads the integration of cyber threat intelligence into cybersecurity operations, incident response activities, and organizational decision-making processes. Coordinates intelligence support during active cybersecurity incidents by providing advanced contextual analysis, attribution assessments, and operational intelligence to accelerate detection, response, and recovery efforts. Develops and oversees the dissemination of indicators, detection logic, and intelligence reporting for operational use by cybersecurity teams and mission partners. Collaborates with security operations, incident response, forensics, threat hunting, and partner organizations to refine intelligence priorities, improve information sharing, and enhance operational effectiveness. Stakeholder Engagement, Advisement, Mission Coordination Serves as a senior representative of the organization's intelligence function in engagements with executive leadership, governmental entities, critical infrastructure partners, and external stakeholders. Provides expert advisement and strategic briefings regarding cyber threats, emerging risks, intelligence trends, and operational impacts. Facilitates interagency coordination and information sharing initiatives and supports the development of collaborative intelligence relationships across state, federal, local, and private-sector partners. May provide guidance, mentoring, and technical leadership to analysts and other personnel. Tradecraft, Innovation, and Program Development Leads efforts to strengthen intelligence tradecraft, analytic rigor, and continuous improvement initiatives across intelligence operations. Establishes and promotes standards for sourcing, confidence assessment, structured analytic techniques, and product quality. Evaluates and applies emerging technologies, including artificial intelligence and large language model tools, to improve analytic workflows and intelligence capabilities while ensuring responsible and appropriate use. Identifies opportunities to enhance methodologies, processes, tools, and intelligence integration across the organization. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)