State of Iowa

Cyber Threat Intelligence Analyst

State of Iowa$81K — $124K *
Education, Government & Non-Profit
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in cyber threat intelligence or cyber defense analytics.
  • Strong knowledge of threat actor motivations, behaviors, and tactics (TTPs).
  • Proficiency in using CTI platforms and OSINT techniques.
  • In-depth understanding of cybersecurity frameworks like MITRE ATT&CK and the Kill Chain.
  • Ability to translate intelligence findings into actionable recommendations.

Responsibilities

  • Collect and analyze intelligence data from multiple sources.
  • Correlate external threats with existing vulnerabilities.
  • Produce strategic reports for various stakeholders.
  • Identify tactics and trends used by threat actors.
  • Manage intelligence workflows and documentation.
  • Support incident response efforts as a subject-matter expert.
  • Mentor SOC team members on intelligence practices.

Benefits

  • Flexible work environment.
  • Health, dental, and vision insurance.
  • Generous vacation, sick leave, and paid holidays.
  • Life and disability insurance.
  • Retirement savings options (RIC).
  • Flexible Spending Accounts.
Full Job Description
Salary : $81,203.20 - $124,883.20 Annually
Location : Des Moines - 50309 - Polk County, IA
Job Type: Full-time
Job Number: 27-00559
Agency: 532 Iowa Department of Management
Opening Date: 08/25/2026
Closing Date: 9/6/2026 11:59 PM Central
LinkedIn Tag: #LI-POST
Point of Contact:

Job Description
Only applicants who meet the Minimum Qualification Requirements and meet all selective requirements (listed below) will be placed on the eligible list.

The Department of Management's Division of Information Technology (DoIT) is seeking a senior-level Information Technology Specialist 5 (ITS5) - Cyber Threat Intelligence Analyst to serve as the authoritative intelligence resource supporting the Security Operations Center (SOC). This role collects, reviews, and analyzes intelligence data to identify threats targeting state and local government environments and transforms that information into actionable outcomes for SOC analysts, threat hunters, engineering teams, GRC, and leadership. The analyst develops and maintains Priority Intelligence Requirements (PIRs), assesses cyber risks, identifies adversary tactics, and motives, and ensures intelligence is aligned to state security objectives. The role leverages CTI platforms, OSINT sources, and structured analytic methodologies to produce accurate and timely intelligence reports. It also coordinates intelligence exchanges with external partners including CISA and peer government entities. This ITS5 position requires deep technical understanding, high integrity, and the ability to communicate complex intelligence to diverse audiences.

What You Will Do
  • Collect, maintain, and enrich intelligence data from internal telemetry, OSINT, commercial intel feeds, third-party reporting, and government partners.
  • Correlate external threats with SOC alerting and state-specific vulnerabilities.
  • Analyze cyber threat data to assess likelihood, impact, and relevance to state and local government.
  • Identify threat actor TTPs, campaigns, emerging vulnerabilities, and exploitation trends.
  • Produce tactical, operational, and strategic reports for diverse stakeholder groups.
  • Develop, maintain, and refine PIRs aligned to evolving state risks.
  • Manage intelligence workflows including collection planning, source evaluation, assessment documentation, and dissemination tracking.
  • Translate CTI findings into actionable activities including detection recommendations, risk prioritization, threat hunting leads, vulnerability context, and architecture hardening actions.
  • Support incident response as an intelligence subject-matter expert.
  • Coordinate with CISA, law enforcement, and peer government agencies to exchange intelligence, validate trends, and support joint defensive efforts.
  • Maintain and optimize CTI platforms, automation pipelines, and enrichment tools.
  • Mentor SOC team members on intelligence concepts, frameworks, and analytic tradecraft.
  • Present intelligence briefings to technical and non-technical audiences in a clear, concise manner.
  • Document analytic methods, assumptions, and findings following best practices and structured analytic techniques.

What We Are Seeking
  • Cyber Threat Intelligence lifecycle management (PIR development, collection, analysis, dissemination)
  • Strong knowledge of threat actor motivations, targets, behaviors, and TTPs
  • Proficiency with CTI platforms, malware/trend research tools, enrichment feeds, and OSINT techniques
  • In-depth understanding of MITRE ATT&CK, attack surface concepts, incident response, and vulnerability prioritization
  • Ability to translate intelligence into operational actions, detections, and risk-driven recommendations
  • Excellent communication, presentation, and technical writing skills
  • Strong problem-solving, critical-thinking, and independent decision-making ability
  • Five or more years of experience in cyber threat intelligence, cyber defense analytics, or related field
  • Strong understanding of cybersecurity frameworks (MITRE ATT&CK, Kill Chain, Diamond Model)
  • Demonstrated knowledge of attack vectors, penetration methods, and defensive countermeasures
  • Experience with OSINT, intel feeds, CTI platforms, and log or alert correlation
  • Excellent problem-solving, writing, briefing, and documentation skills
  • Ability to work independently with minimal supervision and in a multidisciplinary team
  • Strong integrity, judgment, and professional conduct with sensitive information

Preferred Certifications
  • CISSP, CISA, GSEC, or related cyber/intelligence credentials

What We Offer
  • Flexible work environment
  • Iowa Public Employees' Retirement System (IPERS)
  • Health, dental, and vision insurance
  • Generous vacation, sick leave, and paid holidays
  • Life and disability insurance
  • Retirement savings options (RIC)
  • Flexible Spending Accounts

Working Arrangement
This position occasionally requires onsite work in Des Moines, IA. Employees meeting all expectations of their work responsibilities may request fully remote work and develop a hybrid/remote schedule collaboratively with their manager.

Please note, candidates for this position must reside in the state of Iowa at the time of starting the role.

Selectives

990 Cyber Security Planning:
A minimum of 18 months of full-time work experience in cyber security planning at a professional level that included the following major functions: participating in and leading a company-/agency-wide cyber security planning program including the identification of cyber security risks, development of prevention and response plans to minimize cyber-attack damages including mass care and consequences management, and the development of continuation of business operation plans; participating in national cyber security planning initiatives and exercises; responding to and participating in the recovery work from cyber security incidents; and working across governments, private sectors, and non-profit organizations collaboratively on cyber security planning activities and plans for response.

AND

980 Strategic Planning:
6 months' experience, 12 semester hours, or a combination of both. Generally, an administrative position (mid to upper level of the management team) is assigned this as one function of their overall job. However, there are some specialists who deal only in strategic planning. Some colleges and universities may now carry this as a major or area of emphasis as part of their business administration or public policy programs. For experience to count, the applicant must have had the responsibility either for coordinating or developing the organization's strategic plan. Sometimes an administrative assistanttype is responsible for a lower level of coordination, i.e., distributing information to managers, collecting what they develop, and putting it into one document; that is not what is sought here. This has to be experience to the point that the individual knows the following: • What a good strategic plan looks like • How to prepare a plan • How to monitor progress and ancillary planning • How to speak knowledgably for the organization about the plan

AND

717 Security Administration:
6 months' experience, 12 semester hours, or a combination of both in building and maintaining skillset and knowledge base for security issues that impact information technology systems. Applicants may refer to themselves as Security Administrator. System Administrator is not the same.

AND

727 Risk Assessment:
6 months' experience, 12 semester hours, or a combination of both in analyzing and identifying risks and the corresponding potential impact to information and information technology systems.

Minimum Qualification Requirements
Applicants must meet at least one of the following minimum requirements to qualify for positions in this job classification:

1) Graduation from an accredited four-year college or university with a degree in any field, and experience equal to three years of full-time work in application development and database management, business analysis, systems and network administration, technical training and reporting, IT vendor and purchasing management, IT project management, IT product management, system testing and quality assurance, mainframe and platform administration, and/or information technology security.
2) Graduation from an accredited four-year college or university with a degree in computer science, computer applications, software engineering, computer engineering, management information systems, business analytics, or cyber security, and experience equal to two years of full-time work in application development and database management, business analysis, systems and network administration, technical training and reporting, IT vendor and purchasing management, IT project management, IT product management, system testing and quality assurance, mainframe and platform administration, and/or information technology security.

3) All of the following (a and b):

a. Three years of full-time work experience in application development and database management, business analysis, systems and network administration, technical training and reporting, IT vendor and purchasing management, IT project management, IT product management, system testing and quality assurance, mainframe and platform administration, and/or information technology security; and

b. A total of four years of education and/or full-time experience (as described in part a), where thirty semester hours of accredited college or university coursework in any field equals one year of full-time experience.

4) All of the following (a and b):

a. Five years of full-time work experience in application development and database management, business analysis, systems and network administration, technical training and reporting, IT vendor and purchasing management, IT project management, IT product management, system testing and quality assurance, mainframe and platform administration, and/or information technology security; and

b. Either of the following:

i. Certification from an authorized educational institution/major computer or software producer in one or more of the specialty areas listed in part a; or

ii. Eighteen semester hours from an accredited college or university in one or more of the specialty areas listed in part a.
5) Current, continuous experience in the state executive branch that includes six months of full-time work as an Information Technology Specialist 4.

About State of Iowa

The State of Iowa is a government entity responsible for providing services and programs to the residents of Iowa. The state government is divided into three branches: the executive branch, the legislative branch, and the judicial branch. The executive branch is headed by the Governor of Iowa, who is responsible for implementing and enforcing state laws. The legislative branch is responsible for making laws, while the judicial branch is responsible for interpreting laws and administering justice. The State of Iowa was admitted to the Union on December 28, 1846, and has since become known for its agriculture, manufacturing, and renewable energy industries.
Learn more about State of Iowa
Size
18,000 employees
Industry

Similar Jobs

More Jobs at State of Iowa

More Education, Government & Non-Profit Jobs

Find similar Cyber Threat Intelligence Analyst jobs: