ECS

Threat Intelligence Analyst

ECS$80K — $110K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3-5 years of experience in cyber threat intelligence or related cybersecurity roles
  • Working knowledge of cyber threat actors and malware
  • Experience in collecting and analyzing threat information from diverse sources
  • Familiarity with SOC operations and incident investigation processes
  • Strong written communication skills for actionable intelligence products
  • Ability to assess source reliability and operational relevance

Responsibilities

  • Collect and evaluate cyber threat information from various sources
  • Support the development of intelligence requirements aligned with organizational risks
  • Monitor threat actor activity and vulnerability disclosures
  • Analyze threat reporting to assess credibility and impact
  • Produce intelligence products like threat briefs and executive summaries
  • Validate and enrich indicators of compromise for operational use
  • Support SOC analysts during incident response and investigation

Benefits

  • Professional development opportunities
  • Access to cutting-edge cybersecurity tools
  • Collaborative work environment with cross-functional teams
  • Engagement in continuous learning and improvement initiatives
  • Opportunities to contribute to intelligence sharing and knowledge bases
Full Job Description
The Threat Intelligence Analyst supports cybersecurity operations by collecting, analyzing, producing, and disseminating actionable intelligence on cyber threats, adversary tactics, vulnerabilities, campaigns, and emerging risks relevant to the organization. This role helps transform internal and external threat information into timely context that supports SOC monitoring, threat hunting, incident response, vulnerability management, and leadership decision-making.

The ideal candidate has strong analytical and writing skills, understands adversary behavior and cybersecurity operations, and can evaluate threat information from multiple sources to produce clear, prioritized, and actionable intelligence for technical and non-technical stakeholders.

Key Responsibilities

Threat Intelligence Collection & Requirements
  • Collect and evaluate cyber threat information from open-source, commercial, government, industry, and internal security sources
  • Support development and refinement of intelligence requirements aligned to organizational mission, assets, technology, and risk priorities
  • Monitor threat actor activity, malware trends, exploitation activity, vulnerability disclosures, campaigns, and sector-specific threat reporting
  • Maintain awareness of current threat landscape developments that may affect enterprise, cloud, identity, endpoint, network, or operational environments

Analysis & Production
  • Analyze threat reporting, indicators, tactics, techniques, and procedures to assess relevance, credibility, confidence, and potential impact
  • Produce intelligence products such as threat briefs, situational awareness reports, actor profiles, vulnerability intelligence notes, and executive summaries
  • Map observed or reported adversary behavior to recognized frameworks such as MITRE ATT&CK
  • Identify trends, patterns, knowledge gaps, and intelligence priorities that support security operations and risk management

Indicator & Context Management
  • Validate, enrich, and manage indicators of compromise and other threat artifacts for operational use
  • Provide context around indicators, including associated campaigns, malware, infrastructure, confidence levels, and recommended handling
  • Coordinate with SOC, threat hunting, and engineering teams to support detection logic, alert enrichment, watchlists, and monitoring use cases
  • Recommend tuning, suppression, or prioritization guidance when intelligence indicates changes in threat relevance or confidence

SOC, Threat Hunting & Incident Support
  • Support SOC analysts with threat context during alert triage, investigation, escalation, and incident response activities
  • Provide intelligence inputs to threat hunting hypotheses, hunt priorities, and post-incident analysis
  • Assist with research on suspicious activity, adversary tradecraft, malicious infrastructure, malware families, and exploitation techniques
  • Document intelligence findings, assumptions, confidence levels, and recommended follow-up actions clearly and defensibly

Reporting, Briefing & Collaboration
  • Prepare written and verbal intelligence briefings for technical teams, program leadership, and other stakeholders
  • Translate complex threat information into clear operational and business risk language
  • Collaborate with SOC analysts, threat hunters, forensics personnel, security engineers, Splunk teams, and program leadership
  • Contribute to knowledge bases, intelligence repositories, recurring reports, and lessons-learned materials

Continuous Improvement
  • Help improve intelligence workflows, source evaluation practices, reporting templates, tagging standards, and dissemination processes
  • Track intelligence usefulness, stakeholder feedback, recurring intelligence gaps, and opportunities to improve operational impact
  • Stay current with adversary tradecraft, intelligence analysis methods, security operations practices, and relevant frameworks


  • 3-5 years of experience in cyber threat intelligence, security operations, incident response, threat hunting, intelligence analysis, or related cybersecurity roles
  • Working knowledge of cyber threat actors, malware, vulnerabilities, attack lifecycle concepts, and adversary tactics, techniques, and procedures
  • Experience collecting, evaluating, analyzing, and summarizing threat information from multiple sources
  • Familiarity with SOC operations, SIEM workflows, indicators of compromise, detection concepts, and incident investigation processes
  • Strong written communication skills, including the ability to produce concise, accurate, and actionable intelligence products
  • Ability to assess source reliability, analytic confidence, operational relevance, and potential impact

About ECS

ECS is a leading provider of digital solutions and services to the federal government. The company was founded in 2001 by Roy Kapani and has since grown to become a trusted partner to a wide range of government agencies. ECS offers a broad range of services, including cloud computing, cybersecurity, and artificial intelligence. The company has been recognized for its innovative solutions and has won numerous awards, including the AWS Public Sector Partner of the Year award.
Learn more about ECS
Size
2,000 employees
Industry

Similar Jobs

More Jobs at ECS

More Information Technology Jobs

Find similar Threat Intelligence Analyst jobs: