1

Cyber Threat Intelligence Jobs (NOW HIRING)

This position provides cyber threat intelligence analysis, proactive threat hunting, malware triage support, and analytical reporting. The Cyber Threat Analyst will analyze cyber threat activity ...

Our partner is looking for a Cyber Threat Intelligence Analyst based in Netherlands. This remote opportunity is designed for professionals and aspiring analysts looking to build practical experience ...

Showing results 41-60

Cyber Threat Intelligence information

See salary details

$64.5K

$109.8K

$156K

How much do cyber threat intelligence jobs pay per year?

As of Sep 4, 2026, the average yearly pay for cyber threat intelligence in the United States is $109,848.00, according to ZipRecruiter salary data. Most workers in this role earn between $87,500.00 and $130,000.00 per year, depending on experience, location, and employer.

What is cyber threat intelligence?

Cyber Threat Intelligence (CTI) is the process of collecting, analyzing, and interpreting information about current and potential cyber threats that could impact an organization. CTI professionals use data from various sources to identify threat actors, their tactics, techniques, and motivations. This intelligence helps organizations anticipate, prepare for, and defend against cyber attacks, improving their overall security posture. CTI is vital for proactive cybersecurity and informed decision-making.

How does a cyber threat intelligence analyst typically collaborate with other teams within an organization?

Cyber Threat Intelligence (CTI) analysts work closely with various departments, including IT, incident response, and risk management teams, to share insights on emerging threats and vulnerabilities. They regularly participate in cross-functional meetings to translate technical threat data into actionable recommendations for both technical and non-technical stakeholders. Effective collaboration ensures that security strategies are up-to-date and that incident response teams are prepared to act swiftly on credible threats.

What are the key skills and qualifications needed to thrive as a cyber threat intelligence analyst, and why are they important?

To thrive as a Cyber Threat Intelligence Analyst, you need strong analytical skills, deep knowledge of cybersecurity principles, and experience with threat analysis, often supported by a degree in computer science or cybersecurity and certifications like CISSP or GCTI. Familiarity with threat intelligence platforms (TIPs), SIEM systems, and open-source intelligence (OSINT) tools is essential. Excellent problem-solving, attention to detail, and effective communication skills help analysts interpret complex data and share actionable insights with stakeholders. These skills are crucial for proactively identifying, assessing, and mitigating cyber threats to protect organizational assets and information.

What is the difference between Cyber Threat Intelligence vs Cyber Security Analyst?

AspectCyber Threat IntelligenceCyber Security Analyst
Primary FocusGathering, analyzing, and interpreting threat data to anticipate cyber threatsMonitoring, detecting, and responding to security incidents
Skills & CertificationsThreat analysis, intelligence platforms, certifications like CTI certificationsSecurity tools, incident response, certifications like CompTIA Security+
Work EnvironmentResearch-focused, often in threat intelligence teamsOperational, monitoring security systems and responding to alerts
Industry UsageUsed by security teams to inform defense strategiesUsed by security teams to maintain system integrity

While both roles are vital in cybersecurity, Cyber Threat Intelligence focuses on proactively analyzing threats to prevent attacks, whereas Cyber Security Analysts respond to security incidents and manage ongoing security operations. Understanding these differences helps organizations build comprehensive security strategies.

How to get a job in cyber threat intelligence?

To pursue a career in cyber threat intelligence, candidates typically need a strong background in cybersecurity, computer science, or related fields, along with skills in threat analysis, malware analysis, and knowledge of security tools like SIEM systems. Earning relevant certifications such as GIAC Cyber Threat Intelligence (GCTI) or CISSP can improve job prospects. Gaining experience through internships, participating in cybersecurity communities, and staying updated on emerging threats are also valuable steps.

Is threat intelligence a good career?

Threat intelligence is a valuable career in cybersecurity, focusing on analyzing and understanding cyber threats to protect organizations. It often requires skills in research, analysis, and familiarity with security tools and frameworks, with certifications like CISSP or GIAC enhancing job prospects.

What does cyber threat intelligence do?

Cyber threat intelligence involves collecting, analyzing, and sharing information about cyber threats and adversaries to help organizations understand potential risks and improve their security posture. Professionals in this field use tools like threat databases and analysis techniques to identify emerging threats and support incident response efforts.
More about Cyber Threat Intelligence jobs

What cities are hiring for Cyber Threat Intelligence jobs?

Cities with the most Cyber Threat Intelligence job openings:

What are the most commonly searched types of Cyber Threat Intelligence jobs?

The most popular types of Cyber Threat Intelligence jobs are:

What states have the most Cyber Threat Intelligence jobs?

States with the most job openings for Cyber Threat Intelligence jobs include:

Infographic showing various Cyber Threat Intelligence job openings in the United States as of August 2026, with employment types broken down into 89% Full Time, 8% Part Time, and 3% Contract. Highlights an 85% Physical, 4% Hybrid, and 11% Remote job distribution, with an average salary of $109,848 per year, or $52.8 per hour.

OpenSource Cyber Threat Intelligence Analyst

Peraton

Arlington, VA • On-site

Full-time

Posted 9 days ago


Key responsibilities

  • Serve as the primary OSINT collector and analyst for the I&W mission, performing targeted opensource research across various environments and sources.

  • Track and analyze advanced persistent threat (APT) actors, their infrastructure, exploitation methods, malware, and behavioral signatures.

  • Produce high-quality written and verbal assessments, including reports, actor profiles, trend analyses, and briefings for technical and nontechnical audiences.


Peraton rating

8.3

Company rating: 8.3 out of 10

Based on 56 frontline employees who took The Breakroom Quiz

52nd of 226 rated it services


Job description

Responsibilities

Peraton is hiring an experienced OpenSource Cyber Threat Intelligence Analyst for our Federal Strategic Cyber Programs.

Location: Northern VA. Full-time, on-site role. 

  • Travel: For this role, you must be able to travel up to two weeks at a time, both foreign and domestically.

Description:

The OpenSource Cyber Threat Intelligence Analyst will serve as a dedicated OSINT specialist within the Indications & Warnings (I&W) branch, supporting proactive early warning of cyber threats targeting Department of State personnel, systems, and information assets. This role is ideal for an analyst who excels in opensource investigations, threat actor tracking, and fusing multisource intelligence into highvalue assessments.

In this role, you will:

  • Serve as the primary OSINT collector and analyst for the I&W mission, performing targeted opensource research across surface/deep/dark web environments, social media, threat forums, and global reporting sources.
  • Track advanced persistent threat (APT) actors, their infrastructure, exploitation methods, malware,  development, targeting trends, and behavioral signatures using OSINT, vendor, and classified feeds.
  • Conduct pattern, trend, link, and behavioral analysis to identify malicious cyber activity aimed at Department personnel, networks, and mission equities.
  • Maintain structured analytic records and metadata to catalog active campaigns, actor infrastructure changes, and IOCs.
  • Identify and triage Indicators of Compromise (IOCs) using SIEM tools and other security platforms; pivot from IOCs to external opensource leads to identify additional malicious infrastructure.
  • Act as a core participant in I&W's fusion cell, integrating OSINT findings with technical telemetry and intelligence reporting to enhance situational awareness and inform mitigation recommendations.
  • Liaise with Intelligence Community (IC) partners, privatesector researchers, and internal CTAD teams to validate findings and close intelligence gaps.
  • Monitor geopolitical developments, emerging technologies, hacktivist activity, and cybercriminal ecosystems to anticipate cyber threat shifts affecting Department operations.
  • Produce highquality written and verbal assessments, including rapid-turn spot reports, actor profiles, trend analyses, and briefings tailored for both technical and nontechnical audiences.
  • Correlate external threat intelligence with internal events to identify vulnerabilities, preintrusion indicators, and opportunities for proactive defense.
  • Support I&W's mission to provide actionable analysis that informs Department cybersecurity policy, configuration changes, and mitigation actions.
  • Potential to travel to support cyber security briefings and consultations.

#DSCM

Qualifications

Minimum requirements are: 

  • Bachelors degree and a minimum of 9 years of experience; 7 years with Masters degree; and 4 years with PhD. 
    • An additional 4 years of experience may be substituted in lieu of the bachelor's degree requirement.
  • Must either possess and maintain, or obtain prior to start date, one of the following professional certifications:
    • CASP+ CE; CCNP Security; CEH; CFR; CHFI; CISA; CISSP (or Associate); Cloud+;CND;CySA+; GCED; GCIH; GICSP; SSCP
  • Cyber Threat Intelligence & APT Analysis: Demonstrated experience in cyber threat intelligence, including tracking and analyzing Advanced Persistent Threat (APT) actors, adversary operations, tactics, techniques, and procedures (TTPs), and pivoting from indicators of compromise (IOCs) to identify related infrastructure.
  • Threat Intelligence Tools & Methodologies: Experience with SIEMs, threat intelligence and threat detection platforms, and established threat modeling frameworks such as MITRE ATT&CK, Lockheed Martin Cyber Kill Chain, or Diamond Model.
  • Threat Analysis & Incident Support: Experience providing intelligence support before, during, and after cyber incidents, including attribution analysis, adversary profiling, correlating disparate events, conducting post-incident reviews, identifying lessons learned, and improving threat detection capabilities.
  • Cybersecurity & Predictive Analysis: Knowledge of cloud security and threats targeting cloud environments, network protocols and systems, and experience developing predictive models or assessments to anticipate emerging cyber threats and recommend preemptive mitigation measures.
  • Analytical & Communication Skills: Strong analytical, critical thinking, and problem-solving skills with demonstrated ability to work independently and collaboratively. Excellent written communication skills with the ability to convey highly technical information in an analytic format; familiarity with ICD-203 Intelligence Community tradecraft standards and finished intelligence products is desirable.
  • Environment, Clearance & Travel: Experience working in fast-paced classified environments supporting government, military, or Intelligence Community organizations.
  • U.S citizenship required. 
  • An active Top Secret security clearance with SCI eligibility.
  • Active U.S. Passport and the ability to travel up to two weeks at a time, both foreign and domestically.
Peraton Overview

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can't be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we're keeping people around the world safe and secure.

Target Salary Range$104,000 - $166,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual's experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.EEOEEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.Employment Type: FULL_TIME

What Peraton employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Peraton logo

About Peraton

Sourced by ZipRecruiter

At Peraton, we re at the forefront of delivering the next big thing every day. We re the partner of choice to help solve some of the world s most daunting challenges, delivering bold, new solutions to keep people around the world safer and more secure.

Industry

It services

Company size

10,000+ Employees

Headquarters location

Herndon, VA, US

Year founded

2017