Cyber Threat Intelligence Analyst - Remote

CSAA Insurance Group

$122K — $164K *
US-AnywhereRemote in Arizona, US
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 6+ years of experience in Cyber Threat Intelligence, SOC, Incident Response, Threat Hunting, or related cybersecurity roles
  • Bachelor's degree in computer science, Information Technology, or a related field, or equivalent experience
  • Experienced in operating and optimizing Threat Intelligence Platforms (TIPs)
  • Proficient in leveraging commercial threat intelligence providers
  • Strong knowledge of the intelligence lifecycle
  • Advanced understanding of the MITRE ATT&CK framework
  • Experience managing and enriching IOCs effectively

Responsibilities

  • Monitor and analyze intelligence from various sources to assess threats
  • Maintain and utilize Threat Intelligence Platforms to support operations
  • Integrate intelligence across security tools
  • Collect and manage actionable IOCs for detection and mitigation
  • Provide real-time intelligence context during incidents
  • Analyze vulnerability intelligence for risk prioritization
  • Respond to ad hoc intelligence requests from stakeholders

Benefits

  • Flexibility to work remotely from anywhere in the U.S. (except Hawaii and Alaska)
  • Opportunity to participate in a company-wide annual discretionary bonus program
  • Support for continuous learning and knowledge sharing
  • Participation in employee resource groups and community volunteering
  • Involvement in a collaborative company culture promoting relationship building
Full Job Description

External candidates: In order for your application to be correctly processed please sign-in before you apply

Internal candidates: Please go to Workday and click "Find Jobs" link under Career

Thank you for considering opportunities with us!

Job Title

Cyber Threat Intelligence Analyst - Remote

Requisition Number

R7811 Cyber Threat Intelligence Analyst - Remote (Open)

Location

Arizona - Home Teleworkers

Additional Locations

Alabama - Home Teleworkers, Alabama - Home Teleworkers, Arkansas - Home Teleworkers, California - Home Teleworkers, Colorado - Home Teleworkers, Connecticut - Home Teleworkers, Delaware - Home Teleworker, District of Columbia - Home Teleworkers, Florida - Home Teleworkers, Georgia - Home Teleworkers, Idaho - Home Teleworkers, Illinois - Home Teleworkers, Indiana - Home Teleworkers, Iowa - Home Teleworkers, Kansas - Home Teleworker, Kentucky - Home Teleworkers, Louisiana - Home Teleworkers, Maine Home Teleworkers, Maryland - Home Teleworkers, Massachusetts - Home Teleworkers, Michigan - Home Teleworkers, Minnesota - Home Teleworkers, Mississippi - Home Teleworker, Missouri - Home Teleworker, Montana - Home Teleworkers {+ 21 more}

Your Role: We are seeking an experienced Cyber Threat Intelligence (CTI) Analyst to help mature the CSAA CTI program. This handson role focuses on operationalizing the Threat Intelligence Platform (TIP), tracking priority threats, and delivering actionable, detectiondriven intelligence to security teams and leadership. The ideal person is a wellrounded security professional who is comfortable working across teams, proactively identifying risk, and translating intelligence into prevention, detection, and response actions.

Your Work: The CSAA Cyber Threat Intelligence Team is responsible for identifying, analyzing, and tracking cyber threats that may impact the organization. We collect intelligence from a wide range of internal and external sources and use that information to understand threat actors, campaigns, vulnerabilities, and attacker tradecraft relevant to our environment.

The successful candidate will be responsible for analyzing and contextualizing threat intelligence, identifying potential risks, and supporting security operations through actionable insights. They will help improve insight into emerging threats, support investigative efforts, and contribute to the continued development and maturity of the CTI program.

  • Monitor and analyze intelligence from commercial, industry, and OSINT sources to track threat actors, campaigns, and vulnerabilities, and assess their relevance, impact, and risk to the organization

  • Maintain and use Threat Intelligence Platforms (TIP) and related tools to support intelligence operations, including ingestion, enrichment, tagging, and data quality

  • Integrate intelligence across security tools (SIEM, SOAR, case management) to support operations

  • Collect, enrich, and manage actionable IOCs to drive detection, blocking, and mitigation efforts across security operations

  • Provide realtime intelligence context during investigations and incidents (e.g., adversary behavior, infrastructure, objectives)

  • Analyze vulnerability intelligence, including KEV listings and active exploitation trends, to support riskbased vulnerability prioritization

  • Respond to ad hoc and timesensitive intelligence requests from stakeholders

  • Support threat hunting by developing indicators, behaviors, and hypotheses

  • Produce and deliver intelligence reports and briefings for technical and nontechnical audiences

  • Improve intelligence workflows, intake processes, RFIs, and documentation

Required Experience, Education and Skills
  • 6+ years of experience in Cyber Threat Intelligence, SOC, Incident Response, Threat Hunting, or related cybersecurity roles

  • Bachelors degree in computer science, Information Technology, or a related field, or an equivalent combination of education and experience

  • Deep experience operating and optimizing industry leading Threat Intelligence Platforms (TIPs)

  • Proven experience leveraging commercial threat intelligence providers such as Flashpoint, Recorded Future, Intel 471, ZeroFox, or comparable services to support operational intelligence requirements

  • Strong mastery of the intelligence lifecycle, with demonstrated ability to operationalize intelligence from collection through dissemination and action

  • Advanced working knowledge of the MITRE ATT&CK framework, with experience applying it to threat analysis, detection engineering, and reporting

  • Demonstrated experience managing and enriching IOCs, with a focus on translating intelligence into measurable detection, blocking, and mitigation outcomes

  • Solid understanding of SIEM, SOAR, EDR, and case management platforms, and how intelligence integrates into and enhances investigative workflows

  • Experience analyzing vulnerability and exploit intelligence to assess realworld risk, likelihood of exploitation, and potential business impact

  • Strong written and verbal communication skills, with the ability to clearly articulate complex threat and risk concepts to both technical and nontechnical stakeholders

What would make us excited about you?

  • A teammate who values collaboration and knowledge sharing

  • Ability to think critically and operate effectively in ambiguous or evolving situations

  • Strong communication skills

  • A strong passion for continuous learning, with curiosity to stay current on emerging threats, techniques, and evolving security trends

  • A selfstarter who takes initiative, operates effectively with minimal direction, and proactively sees opportunities to improve security outcomes

  • Actively shapes our company culture (e.g., participating in employee resource groups, volunteering, etc.)

  • Lives into cultural norms (e.g., willing to have cameras when it matters: helping onboard new team members, building relationships, etc.)

  • Travels as needed for role, including divisional / team meetings and other in-person meetings

  • Fulfills business needs, which may include investing extra time, helping other teams, etc

Please note we are hiring for this role remote anywhere in the United States with the following exceptions: Hawaii and Alaska.

If you apply and are selected to continue in the recruiting process, we will schedule a preliminary call with you to discuss the role and will disclose during that call the available salary/hourly rate range based on your location. Factors used to determine the actual salary offered may include location, experience, or education.

CSAA does not provide visa sponsorship for this role. Applicants must have authorization to work indefinitely in the US. Please do not apply for this role if at any time (now or in the future) you will need immigration support (i.e., H-1B, TN, STEM OPT Training Plans, etc.).

#LI-SB1

.

The national average salary range for this position is $122,850.00-$136,500.00. However, we have a location-based compensation structure. Our salary ranges vary and are calculated based on work location. The starting pay range for this position across all the states we hire in is $122,850.00-$164,000.00. This role also includes an opportunity for a company-wide annual discretionary bonus, through our Annual Incentive Plan (AIP), of up to 10% of eligible pay.

This job posting will be unposted on Fri, 31 Jul 2026.

Similar Jobs

More Jobs at CSAA Insurance Group

More Information Technology Jobs

Find similar Cyber Threat Intelligence Analyst - Remote jobs: