Position SummaryThe Cyber Threat Intelligence (CTI) Analyst is responsible for identifying, analyzing, and communicating cyber threats that may impact the organization. This role supports intelligence collection, threat monitoring, analytic assessments, and intelligence dissemination to enhance organizational awareness and defensive decision-making.
The successful candidate will transform technical threat data into actionable intelligence products for cybersecurity operations, incident response, risk management, and executive stakeholders.
Key ResponsibilitiesIntelligence Collection & Analysis- Monitor open-source, commercial, government, and industry intelligence sources for emerging cyber threats.
- Research threat actors, malware campaigns, vulnerabilities, and geopolitical developments relevant to the organization's risk profile.
- Identify, assess, and contextualize indicators of compromise (IOCs), tactics, techniques, and procedures (TTPs).
- Produce timely assessments regarding threat activity, likelihood, and organizational impact.
Intelligence Production- Develop intelligence reports, briefings, alerts, and situational awareness products.
- Produce tactical, operational, and strategic intelligence products for technical and non-technical audiences.
- Create executive summaries that clearly communicate risk, implications, and recommended actions.
- Maintain intelligence repositories and knowledge management resources.
Operational Support- Support incident response and investigative activities through intelligence enrichment and adversary research.
- Collaborate with Security Operations Center (SOC), Threat Hunting, Detection Engineering, and Forensics teams.
- Provide intelligence-driven recommendations to improve detection and response capabilities.
- Assist with threat actor tracking and long-term campaign monitoring.
Stakeholder Engagement- Brief cybersecurity teams, business leaders, and risk partners on relevant threats and trends.
- Participate in intelligence-sharing communities and industry partnerships.
- Develop strong working relationships with internal stakeholders to understand intelligence requirements.
Continuous Improvement- Contribute to intelligence collection plans and analytic methodologies.
- Evaluate emerging intelligence tools, data sources, and automation opportunities.
- Leverage AI and automation technologies to improve collection, triage, and reporting efficiency.
- Maintain awareness of evolving cyber threats, industry trends, and intelligence tradecraft.
Required Qualifications- 2-5 years of experience in cyber threat intelligence, security operations, incident response, digital forensics, threat hunting, vulnerability management, or a related cybersecurity discipline.
- Bachelor's degree in Cybersecurity, Information Technology, Intelligence Studies, Computer Science, or a related field (or equivalent experience).
- Understanding of cyber threat intelligence frameworks such as: MITRE ATT&CK Diamond Model Intelligence Lifecycle Kill Chain
- Familiarity with common threat actor TTPs and malware trends.
- Strong written and verbal communication skills.
- Demonstrated ability to analyze information from multiple sources and develop actionable assessments.
Preferred Qualifications- Experience with intelligence platforms such as ThreatConnect, Recorded Future, Google Threat Intelligence, Intel471, Mandiant, or similar tools.
- Experience supporting financial services, critical infrastructure, or regulated industries.
- Knowledge of incident response processes and security operations workflows.
- Familiarity with scripting or automation technologies (Python, PowerShell, APIs).
- Intelligence or cybersecurity certifications such as: GIAC Cyber Threat Intelligence (GCTI) CISSP Security+ CySA+ Certified Threat Intelligence Analyst (CTIA)
Key Competencies- Critical Thinking
- Analytical Reasoning
- Intellectual Curiosity
- Attention to Detail
- Executive Communication
- Collaboration and Teamwork
- Risk-Based Decision Making
- Written Intelligence Production
- Presentation and Briefing Skills
Success MeasuresWithin the first year, the analyst should demonstrate the ability to:
- Independently produce high-quality intelligence assessments.
- Deliver concise executive and operational threat briefings.
- Support incident investigations with timely intelligence analysis.
- Establish expertise in designated threat actors, campaigns, or threat domains.
- Improve intelligence processes through automation, research, or collection enhancements.
- Build trusted relationships with cybersecurity, risk, and business stakeholders.
Special Factors
Sponsorship
Vanguard is not offering visa sponsorship for this position.