Threat Intelligence Analyst Jobs
Threat Intelligence Analyst jobs are open across defense contractors, financial services, healthcare, and technology, at every level from junior analyst to principal and director, with specializations in malware analysis, threat hunting, and nation-state actor tracking. Find a role that fits from the openings below and apply directly.
Find JobsOverview
Showing 4 of 80+ Threat Intelligence Analyst jobs









Akira is seeking a Cyber Threat Intelligence (CTI) Analyst to support the U.S. Army Reserve Command (USARC) in cyberspace operations supporting Army and joint requirements. The CTI Analyst will support the CTI function through open-source and classified intelligence collection, analysis, threat hunting, and signature development to inform Blue Team detection priorities and defensive cyberspace operations (DCO) assessment activities. The analyst will produce finished intelligence products and contribute to the signature-development pipeline under the direction of the CTI Lead.
This is an onsite position at Fort Bragg, NC supporting a mission-focused U.S. Army Reserve Command. At minimum, Secret clearance is required; TS/SCI where required by assigned work role or supported network.
Key Responsibilities
- Collect, aggregate, and analyze Open-Source Intelligence (OSINT), commercial threat feeds, Information Sharing and Analysis Center (ISAC) reporting, community intelligence reporting, and Government-Furnished Intelligence (GFI) to identify emerging threats relevant to supported networks.
- Research commercial exploits, zero-day vulnerabilities, adversary tactics, techniques, and procedures (TTPs), and other threats requiring DCO action.
- Integrate threat intelligence findings into supported environments to inform detection priorities and defensive cyber operations.
- Develop, test, and recommend host-based and network-based detection signatures, including YARA, Snort, Suricata, Elastic detection logic, and custom host-based policies, based on identified adversary tradecraft.
- Coordinate signature submissions with the applicable U.S. Army Cyber Command (ARCYBER) signature working group portal to support standardization and dissemination.
- Correlate internal sensor data and incident reports with classified and open-source threat reporting to identify campaign patterns, recurring activity, and persistent adversary behavior.
- Conduct hypothesis-driven and indicator-based threat-hunting missions in coordination with Blue Team Tier 3 analysts.
- Provide tactical DCO integration support when directed, incorporating tactical network sensor events and signature analysis into supported Regional Cyber Center (RCC) DCO processes.
- Support development and maintenance of the DCO test laboratory using Government-approved infrastructure and a commercially leased connection isolated from NIPRNet for malware analysis and OSINT collection.
- Produce Threat Intelligence Reports (TIRs), Indicators of Compromise (IOC) packages, Requests for Information (RFIs), trend analyses, and other finished intelligence products under the direction of the CTI Lead.
- Validate proposed detection signatures for appropriate syntax, functionality, and minimal false positives prior to deployment.
- Conduct signature development, malware analysis, and detection-content testing exclusively on appropriately isolated networks and environments.
- Support monthly DCO-specific internal training sessions, including maintenance of the Program of Instruction (POI), attendee records, and After-Action Reports (AARs).
- Participate in applicable cybersecurity conferences, intelligence events, and training activities as directed.
- Contribute to post-event reports and incorporate relevant findings into CTI processes and operational products.
- Maintain accurate documentation of intelligence collection, analysis, signature development, testing, and operational activities.
- Perform other CTI and DCO support duties as required by the mission.
Required Qualifications
- DoD Manual 8140.03 qualification for DCWF Work Role 171, Cyber Threat Intelligence Analyst, Intermediate.
- Active Secret security clearance at a minimum; TS/SCI eligibility/access where required by the assigned work role or supported network.
- Demonstrated experience with intelligence-analysis tradecraft and OSINT collection methodologies.
- Experience analyzing and mapping adversary tactics, techniques, and procedures (TTPs), including familiarity with the MITRE ATT&CK framework.
- Demonstrated proficiency with signature development and detection-content validation, including YARA, Snort, and/or Suricata.
- Experience analyzing cyber threat information, indicators, vulnerabilities, adversary activity, or related cybersecurity intelligence.
- Ability to correlate intelligence reporting with network, sensor, incident, and other cybersecurity data.
- Strong analytical, research, technical writing, and communication skills.
- Ability to work effectively in a classified, mission-focused operational environment.
- Ability to work onsite at Fort Bragg, NC and support operational requirements.
Preferred Qualifications
- Experience producing finished intelligence products for military, DoD, Government, or enterprise cybersecurity consumers.
- Experience supporting Army, Army Reserve, ARCYBER, or joint cyberspace operations.
- Experience supporting a Security Operations Center (SOC), Blue Team, Defensive Cyberspace Operations (DCO), or Cyber Threat Intelligence mission.
- Experience with Elastic Security, SIEM platforms, network security monitoring, endpoint detection and response (EDR), or related defensive cyber technologies.
- Experience conducting malware analysis or reverse engineering in an isolated laboratory environment.
- Experience developing and validating detection logic, IOCs, YARA rules, network signatures, or host-based detection policies.
- Familiarity with cyber threat intelligence standards, intelligence-sharing communities, and Government cyber threat reporting processes.
- Relevant cybersecurity, intelligence, or CTI certifications are a plus.
Salary Range: $90,000 to $100,000
Akira’s pay range for this position considers various factors including skills, years of experience, training, licenses, certifications, alignment with market data, and internal equity in the organization. This pay range estimate is a general guideline only and not a guarantee of compensation or salary, which Akira believes to be done in good faith in compliance with local laws. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. It is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case.
General Description of Benefits
Akira offers its employees multiple options for medical plans (some with Health Savings Account), dental plans, and vision coverage, and a 401(k) plan with employer match. To promote work/life balance, Akira offers paid time off, including vacation and sick time, holidays, paid parental leave, military leave, bereavement leave, and jury duty leave. We also offer short and long-term disability benefits to protect employee income in the event of sickness or injury, life insurance, accidental death and dismemberment insurance, and critical illness insurance. Akira also offers tuition, training, and certification reimbursement for professional development and career advancement.
Akira regularly reviews our total rewards package to ensure our offerings remain competitive and reflect the values and needs expressed by our employees.
About Akira Technologies
Akira strives to meet and exceed the mission and objectives of US federal agencies. As a leading small business cloud modernization and data analytics services provider, we deliver trusted and highly differentiated solutions and technologies that serve the needs of our customers and citizens. Akira serves as a valued partner to essential government agencies across the intelligence, cyber, defense, civilian, and health markets. Every day, our employees deliver transformational outcomes, solving the most daunting challenges facing our customers.
Akira is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.
Threat Intelligence Analyst Jobs by Experience Level
See All 80 Threat Intelligence Analyst Jobs
Find roles that match your experience and apply in just a few clicks.
Find JobsThreat Intelligence Analyst Job Market
Who's Hiring



Top Industries Hiring
- Technology & Software
- Retail
- Cybersecurity
- Science & Research
- Aerospace & Defense
What Employers Look For
The qualifications that appear most often in threat intelligence analyst jobs.
- Bachelor's degree in cybersecurity, computer science, information systems, or a related field
- Proficiency with threat intelligence platforms such as Recorded Future, ThreatConnect, or MISP
- Experience applying the MITRE ATT&CK framework to analyze and attribute adversary behavior
- Familiarity with malware analysis, reverse engineering tools, or YARA rule development
- Active or eligibility for a U.S. security clearance, particularly for federal and defense roles
- Industry certifications such as GIAC GCTI, GCFE, or CompTIA CySA+ preferred or required
Tips for Your Threat Intelligence Analyst Job Search
Tailor your resume to threat types
Hiring managers scan for whether you've worked on specific threat categories like APT groups, ransomware campaigns, or insider threats. Name the threat actors and campaigns you've analyzed rather than listing generic security tasks.
Certify before targeting cleared roles
Many defense and federal contractor postings require or prefer a current security clearance alongside certifications like GIAC GREM or GCTI. Clarify your clearance level and certification status in your resume header so screeners don't have to dig.
Apply early to roles that fit
Migrate Mate lists threat intelligence analyst openings from across the United States in one place, so you can find roles that match and apply directly to each listing.
Show your intelligence production samples
Analysts who can share sanitized finished intelligence reports, threat briefs, or YARA rules get callbacks faster. Build a portfolio of redacted work product that demonstrates how you structure analysis and communicate findings to non-technical stakeholders.
Match your tool stack to the job description
Postings vary sharply between platforms like Recorded Future, Mandiant Advantage, MISP, and OpenCTI. Skim the tools listed in each posting and lead with the ones you've used in your cover letter and skills section.
Prepare for a structured analytical exercise
Many final-round interviews include a live or take-home exercise where you pivot on an indicator of compromise and present findings. Practice narrating your process aloud, not just arriving at the right answer, since interviewers score your reasoning as much as your conclusion.
Threat Intelligence Analyst Jobs: Frequently Asked Questions
Which companies are hiring the most threat intelligence analysts?
The companies hiring the most threat intelligence analysts right now include Google, Leidos, and Amazon, with the largest share of openings in Virginia, Texas, and Maryland, based on current listings on Migrate Mate as of September 2026. Defense contractors, large financial institutions, and managed security service providers consistently make up the bulk of active hiring.
How many threat intelligence analyst jobs are remote?
About 50% of threat intelligence analyst openings are fully remote or hybrid as of September 2026, though positions requiring a security clearance are almost always on-site or in secure facilities. Strategic intelligence roles focused on open-source research and finished reporting tend to offer the most remote flexibility compared to hands-on malware analysis or incident response-adjacent positions.
How do you become a threat intelligence analyst?
Start by building a foundation in networking, operating systems, and security fundamentals through coursework or entry-level security operations center work. Develop hands-on skills in threat hunting, indicator analysis, and the MITRE ATT&CK framework. Pursue certifications like GIAC GCTI or CompTIA CySA+, build a portfolio of sanitized analysis samples, and target junior analyst or SOC tier-two roles that include an intelligence component to earn your first dedicated posting.
Can you get a threat intelligence analyst job with little experience?
Yes, but you need to compensate with demonstrable analytical output. Contribute to open-source threat intelligence communities, publish blog posts attributing publicly documented campaigns, or complete capture-the-flag competitions with a forensics or threat analysis focus. Many employers will consider candidates from adjacent roles like security operations center analyst or incident responder who can show they've already done intelligence work as part of their day job.
What does the threat intelligence analyst interview process look like?
Most processes run three to four rounds. A recruiter screen covers your background and clearance status, followed by a technical interview where you walk through a past investigation or attribution case. A practical exercise, either take-home or live, asks you to pivot on indicators and present findings. Final rounds often include a panel with senior analysts or a hiring manager focused on how you communicate intelligence to non-technical audiences.
Where can I find and apply to threat intelligence analyst jobs?
You can find and apply to threat intelligence analyst jobs on Migrate Mate, which lists current openings from employers across the United States. Search the listings to find roles that match your experience, clearance level, and specialization, then apply directly to each one that fits.
See All 80 Threat Intelligence Analyst Jobs
Find roles that match your experience and apply in just a few clicks.
Find Jobs