Cyber Threat Intelligence Analyst Jobs
Cyber Threat Intelligence Analyst jobs are open across defense, financial services, healthcare, and technology, from junior analyst to senior and principal levels, with specializations in threat hunting, malware analysis, and adversary tracking. Find a role that fits below and apply directly.
Find JobsOverview
Showing 5 of 41+ Cyber Threat Intelligence Analyst jobs









Akira is seeking a Cyber Threat Intelligence (CTI) Analyst to support the U.S. Army Reserve Command (USARC) in cyberspace operations supporting Army and joint requirements. The CTI Analyst will support the CTI function through open-source and classified intelligence collection, analysis, threat hunting, and signature development to inform Blue Team detection priorities and defensive cyberspace operations (DCO) assessment activities. The analyst will produce finished intelligence products and contribute to the signature-development pipeline under the direction of the CTI Lead.
This is an onsite position at Fort Bragg, NC supporting a mission-focused U.S. Army Reserve Command. At minimum, Secret clearance is required; TS/SCI where required by assigned work role or supported network.
Key Responsibilities
- Collect, aggregate, and analyze Open-Source Intelligence (OSINT), commercial threat feeds, Information Sharing and Analysis Center (ISAC) reporting, community intelligence reporting, and Government-Furnished Intelligence (GFI) to identify emerging threats relevant to supported networks.
- Research commercial exploits, zero-day vulnerabilities, adversary tactics, techniques, and procedures (TTPs), and other threats requiring DCO action.
- Integrate threat intelligence findings into supported environments to inform detection priorities and defensive cyber operations.
- Develop, test, and recommend host-based and network-based detection signatures, including YARA, Snort, Suricata, Elastic detection logic, and custom host-based policies, based on identified adversary tradecraft.
- Coordinate signature submissions with the applicable U.S. Army Cyber Command (ARCYBER) signature working group portal to support standardization and dissemination.
- Correlate internal sensor data and incident reports with classified and open-source threat reporting to identify campaign patterns, recurring activity, and persistent adversary behavior.
- Conduct hypothesis-driven and indicator-based threat-hunting missions in coordination with Blue Team Tier 3 analysts.
- Provide tactical DCO integration support when directed, incorporating tactical network sensor events and signature analysis into supported Regional Cyber Center (RCC) DCO processes.
- Support development and maintenance of the DCO test laboratory using Government-approved infrastructure and a commercially leased connection isolated from NIPRNet for malware analysis and OSINT collection.
- Produce Threat Intelligence Reports (TIRs), Indicators of Compromise (IOC) packages, Requests for Information (RFIs), trend analyses, and other finished intelligence products under the direction of the CTI Lead.
- Validate proposed detection signatures for appropriate syntax, functionality, and minimal false positives prior to deployment.
- Conduct signature development, malware analysis, and detection-content testing exclusively on appropriately isolated networks and environments.
- Support monthly DCO-specific internal training sessions, including maintenance of the Program of Instruction (POI), attendee records, and After-Action Reports (AARs).
- Participate in applicable cybersecurity conferences, intelligence events, and training activities as directed.
- Contribute to post-event reports and incorporate relevant findings into CTI processes and operational products.
- Maintain accurate documentation of intelligence collection, analysis, signature development, testing, and operational activities.
- Perform other CTI and DCO support duties as required by the mission.
Required Qualifications
- DoD Manual 8140.03 qualification for DCWF Work Role 171, Cyber Threat Intelligence Analyst, Intermediate.
- Active Secret security clearance at a minimum; TS/SCI eligibility/access where required by the assigned work role or supported network.
- Demonstrated experience with intelligence-analysis tradecraft and OSINT collection methodologies.
- Experience analyzing and mapping adversary tactics, techniques, and procedures (TTPs), including familiarity with the MITRE ATT&CK framework.
- Demonstrated proficiency with signature development and detection-content validation, including YARA, Snort, and/or Suricata.
- Experience analyzing cyber threat information, indicators, vulnerabilities, adversary activity, or related cybersecurity intelligence.
- Ability to correlate intelligence reporting with network, sensor, incident, and other cybersecurity data.
- Strong analytical, research, technical writing, and communication skills.
- Ability to work effectively in a classified, mission-focused operational environment.
- Ability to work onsite at Fort Bragg, NC and support operational requirements.
Preferred Qualifications
- Experience producing finished intelligence products for military, DoD, Government, or enterprise cybersecurity consumers.
- Experience supporting Army, Army Reserve, ARCYBER, or joint cyberspace operations.
- Experience supporting a Security Operations Center (SOC), Blue Team, Defensive Cyberspace Operations (DCO), or Cyber Threat Intelligence mission.
- Experience with Elastic Security, SIEM platforms, network security monitoring, endpoint detection and response (EDR), or related defensive cyber technologies.
- Experience conducting malware analysis or reverse engineering in an isolated laboratory environment.
- Experience developing and validating detection logic, IOCs, YARA rules, network signatures, or host-based detection policies.
- Familiarity with cyber threat intelligence standards, intelligence-sharing communities, and Government cyber threat reporting processes.
- Relevant cybersecurity, intelligence, or CTI certifications are a plus.
Salary Range: $90,000 to $100,000
Akira’s pay range for this position considers various factors including skills, years of experience, training, licenses, certifications, alignment with market data, and internal equity in the organization. This pay range estimate is a general guideline only and not a guarantee of compensation or salary, which Akira believes to be done in good faith in compliance with local laws. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. It is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case.
General Description of Benefits
Akira offers its employees multiple options for medical plans (some with Health Savings Account), dental plans, and vision coverage, and a 401(k) plan with employer match. To promote work/life balance, Akira offers paid time off, including vacation and sick time, holidays, paid parental leave, military leave, bereavement leave, and jury duty leave. We also offer short and long-term disability benefits to protect employee income in the event of sickness or injury, life insurance, accidental death and dismemberment insurance, and critical illness insurance. Akira also offers tuition, training, and certification reimbursement for professional development and career advancement.
Akira regularly reviews our total rewards package to ensure our offerings remain competitive and reflect the values and needs expressed by our employees.
About Akira Technologies
Akira strives to meet and exceed the mission and objectives of US federal agencies. As a leading small business cloud modernization and data analytics services provider, we deliver trusted and highly differentiated solutions and technologies that serve the needs of our customers and citizens. Akira serves as a valued partner to essential government agencies across the intelligence, cyber, defense, civilian, and health markets. Every day, our employees deliver transformational outcomes, solving the most daunting challenges facing our customers.
Akira is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.
Cyber Threat Intelligence Analyst Jobs by Experience Level
See All 41 Cyber Threat Intelligence Analyst Jobs
Find roles that match your experience and apply in just a few clicks.
Find JobsCyber Threat Intelligence Analyst Job Market
Who's Hiring



Top Industries Hiring
- Technology & Software
- Retail
- E-Commerce & Online Marketplaces
What Employers Look For
The qualifications that appear most often in cyber threat intelligence analyst jobs.
- Proficiency with MITRE ATT&CK framework and structured analytic techniques
- Experience producing finished intelligence reports for technical and executive audiences
- Hands-on use of SIEM platforms, threat intelligence platforms, or sandbox environments
- Active or adjudicated Secret or Top Secret security clearance
- Relevant certifications such as GCTI, CTI, or CISSP
- Bachelor's degree in cybersecurity, computer science, or a related technical field
Tips for Your Cyber Threat Intelligence Analyst Job Search
Tailor your resume to threat intel frameworks
Hiring managers scan for MITRE ATT&CK, Diamond Model, and kill chain references. Map your past work to these frameworks explicitly so your resume speaks the same language as the job description before a recruiter ever reads it.
Showcase finished intelligence products you have authored
Listing tools you have used is not enough. Describe specific threat reports, actor profiles, or tactical briefs you produced, who consumed them, and what decisions they informed. Concrete deliverables separate mid-career analysts from entry-level candidates.
Apply early to roles that fit
Migrate Mate lists cyber threat intelligence analyst openings from across the United States in one place, so you can find roles that match and apply directly to each listing.
Target openings by clearance requirement first
Many postings require an active TS or TS/SCI clearance and will not move uncleared candidates forward. Filter by clearance level before applying so you focus your time on roles where you are already eligible and can start quickly.
Prepare to demonstrate a live analysis exercise
Many interviews include a take-home or whiteboard scenario where you pivot on an indicator of compromise in real time. Practice walking through your analytic process out loud, from raw data collection through a finished assessment, using a sanitized past case.
Negotiate your access to tooling and data feeds
Offer quality in threat intel depends heavily on the vendor feeds and internal telemetry a team has licensed. Before accepting, ask what commercial feeds, sandbox environments, and SIEM integrations are in place so you know what you are actually working with.
Cyber Threat Intelligence Analyst Jobs: Frequently Asked Questions
Which companies are hiring the most cyber threat intelligence analysts?
The most active employers for cyber threat intelligence analysts right now are Leidos, Booz Allen Hamilton, and Peraton, and the most openings are in Virginia, Texas, and Maryland, based on current listings on Migrate Mate as of September 2026. Defense contractors, major financial institutions, and large healthcare systems account for a significant share of total demand.
How many cyber threat intelligence analyst jobs are remote?
About 50% of cyber threat intelligence analyst openings are fully remote or hybrid as of September 2026, though roles tied to classified networks or government contracts are almost always on-site. Strategic and finished-intelligence roles that do not require access to classified systems or sensitive internal telemetry tend to have the most remote flexibility.
How do you become a cyber threat intelligence analyst?
Start by building foundational skills in networking, operating systems, and log analysis, then develop hands-on experience with threat hunting or incident response to understand how adversaries behave. Earn a recognized certification such as GCTI or complete a dedicated CTI training program. Build a portfolio of written analytic products, even from open-source exercises, and apply to junior analyst or all-source intelligence roles to gain professional experience.
Can you get a cyber threat intelligence analyst job with little experience?
Yes, entry-level positions exist, particularly at managed security service providers and companies with large security operations centers that need analysts to triage raw indicators. Candidates with strong open-source intelligence skills, published threat research, CTF participation, or a background in military or law enforcement intelligence have the most success breaking in without a lengthy commercial resume.
What does the cyber threat intelligence analyst interview process look like?
Most processes include an initial screen with a recruiter, a technical phone interview covering analytic tradecraft and tool familiarity, and a final round that typically includes a scenario exercise where you pivot on a threat actor or indicator of compromise. Some employers add a take-home intelligence report assignment. Senior roles often include a presentation to leadership where you defend your analytic conclusions and sourcing.
Where can I find and apply to cyber threat intelligence analyst jobs?
You can find and apply to cyber threat intelligence analyst jobs on Migrate Mate, which lists current openings from employers across the United States. Search the available roles, find the ones that match your background and clearance level, and apply directly to each listing.
See All 41 Cyber Threat Intelligence Analyst Jobs
Find roles that match your experience and apply in just a few clicks.
Find Jobs