1

Threat Intelligence Response Analyst Jobs (NOW HIRING)

Cybersecurity Threat Intelligence Analyst

Austin, TX · On-site

$105.05 - $161.80/hr

  • Medical

  • Dental

  • Vision

  • Life

Cybersecurity Threat Intelligence Analyst HP's Cybersecurity Threat Intelligence Analyst advances ... Power investigations by partnering with Incident Response analysts during active investigations ...

New

The Threat Intelligence Analyst will play a crucial role in providing: * Incident Management and ... Fully leverage intelligence capabilities during incident response * Support execution of cyber ...

The Threat Intelligence Analyst will play a crucial role in providing: * Incident Management and ... Fully leverage intelligence capabilities during incident response * Support execution of cyber ...

The Threat Intelligence Analyst will play a crucial role in providing: * Incident Management and ... Fully leverage intelligence capabilities during incident response * Support execution of cyber ...

They are seeking a Threat Intelligence Analyst to provide crucial support in incident management ... response • Support execution of cyber operations through technical analysis and intelligence ...

Support incident response activities with tactical and operational threat intelligence. * Maintain ... Experience analyzing IOCs, TTPs, and campaign data * Familiarity with frameworks such as MITRE ATT ...

Support incident response activities with tactical and operational threat intelligence. * Maintain ... Experience analyzing IOCs, TTPs, and campaign data * Familiarity with frameworks such as MITRE ATT ...

They are seeking a Threat Intelligence Analyst to provide critical support in analyzing advanced ... response • Support execution of cyber operations through technical analysis and intelligence ...

Cyber Threat Intelligence Analyst Duration: 12 months Location: Austin, TX (Onsite-Candidates must ... Collaborate with Incident Response, Security Operations, Vulnerability Management, and ...

next page

Showing results 1-20

Threat Intelligence Response Analyst information

See salary details

$41K

$100.1K

$154.5K

How much do threat intelligence response analyst jobs pay per year?

As of Aug 20, 2026, the average yearly pay for threat intelligence response analyst in the United States is $100,058.00, according to ZipRecruiter salary data. Most workers in this role earn between $77,000.00 and $120,500.00 per year, depending on experience, location, and employer.

What does a Threat Intelligence Response Analyst do?

A Threat Intelligence Response Analyst is responsible for identifying, analyzing, and responding to cyber threats facing an organization. They collect and evaluate data from various sources to detect potential security risks, track threat actors, and provide actionable intelligence to help prevent or mitigate cyber attacks. Their role also involves collaborating with other cybersecurity professionals to develop response strategies, enhance defenses, and ensure the organization's information systems remain secure.

What are the main challenges a Threat Intelligence Response Analyst faces when responding to emerging cyber threats?

Threat Intelligence Response Analysts often encounter the challenge of rapidly evolving threat landscapes, where new attack vectors and tactics emerge frequently. They must quickly assess the credibility and relevance of threat intelligence, prioritize incidents, and coordinate responses across multiple teams. Balancing the need for thorough analysis with the urgency of timely action requires strong decision-making and communication skills. Additionally, staying current with the latest tools and threat actor techniques is essential to effectively mitigate risks.

What are the key skills and qualifications needed to thrive as a Threat Intelligence Response Analyst, and why are they important?

To thrive as a Threat Intelligence Response Analyst, you need strong knowledge of cybersecurity principles, threat analysis, and incident response, often supported by a degree in cybersecurity or related fields. Familiarity with SIEM tools, malware analysis platforms, and certifications like CEH or GIAC are typically required. Critical thinking, attention to detail, and effective communication are valuable soft skills in this role. These competencies enable analysts to detect, assess, and respond to cyber threats quickly, minimizing risk and protecting organizational assets.

What is the difference between Threat Intelligence Response Analyst vs Cybersecurity Analyst?

AspectThreat Intelligence Response AnalystCybersecurity Analyst
Required CredentialsCertifications like GIAC, CISSP, or CEH; relevant degrees in cybersecurity or related fieldsCertifications such as CompTIA Security+, CISSP, or CEH; similar educational background
Work EnvironmentFocuses on analyzing threat data, responding to incidents, and threat hunting within security teamsMonitors networks, investigates security breaches, and implements security measures across organizations
Employer & Industry UsageUsed in security operations centers (SOCs), government agencies, and large enterprisesCommon in IT departments, security firms, and organizations with extensive network infrastructure

While both roles involve cybersecurity, Threat Intelligence Response Analysts primarily focus on analyzing threat data and responding to specific incidents, whereas Cybersecurity Analysts monitor and protect overall network security. The roles often overlap but differ in scope and daily tasks.

More about Threat Intelligence Response Analyst jobs

What cities are hiring for Threat Intelligence Response Analyst jobs?

Cities with the most Threat Intelligence Response Analyst job openings:

What states have the most Threat Intelligence Response Analyst jobs?

States with the most job openings for Threat Intelligence Response Analyst jobs include:

Infographic showing various Threat Intelligence Response Analyst job openings in the United States as of August 2026, with employment types broken down into 2% As Needed, 81% Full Time, 13% Part Time, 3% Contract, and 1% Nights. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $100,058 per year, or $48.1 per hour.

Manager, Cyber Threat Intelligence & Response

MLB (Job Board Only)

Remote

$113K - $153K/yr

Full-time

Life, Retirement, PTO

Posted yesterday

New


Job description

Major League Baseball is looking for a Manager, Cyber Threat Intelligence & Response to lead MLB's threat intelligence and incident response programs across the League office, the 30 Clubs, and their affiliates. The role manages vulnerability and exploit intelligence, digital risk monitoring, incident coordination, forensic investigation, threat hunting, and the use of intelligence in vSOC detection and response. The manager also owns security awareness programming and uses automation to shorten research, triage, and reporting cycles.

Responsibilities

Threat and Vulnerability Intelligence

  • Own MLB's vulnerability intelligence program. Monitor newly disclosed vulnerabilities, exploit code, proof-of-concept availability, and threat actor weaponization to assess real-world risk across MLB environments
  • Combine severity, exploit intelligence, asset context, and active targeting to set remediation priorities for the vSOC, Clubs, and internal Technology teams
  • Direct research across OSINT, social media, deep and dark web sources, commercial intelligence platforms, and industry information-sharing groups
  • Track threat actors, campaigns, indicators of compromise, and tactics, techniques, and procedures. Maintain documentation that the vSOC can use during investigations, threat modeling, and response
  • Track and report threat intelligence, vulnerability, and response measures, including time to detect, time to contain, time to recover, incident recurrence, playbook use, and corrective action closure
  • Support investigations involving credential exposure, phishing infrastructure, impersonation, fraudulent domains, executive targeting, brand abuse, and other external threats. Coordinate takedown or disruption work when needed

Detection Engineering and Threat Hunting

  • Build and improve automation for vulnerability research, intelligence enrichment, alert correlation, investigation support, and reporting
  • Convert threat and vulnerability intelligence into detection content, alert logic, hunt hypotheses, and tuning recommendations using Sigma, YARA, SIEM queries, EDR logic, and detection-as-code practices where appropriate
  • Develop and lead hypothesis-driven threat hunts across endpoint, identity, cloud, network, email, and application telemetry
  • Use threat and vulnerability intelligence to validate vSOC alerts, support containment decisions, reduce false positives, and identify gaps in detection coverage

Incident Response

  • Support the incident response lifecycle, including triage, severity assessment, escalation, containment, eradication, recovery, and closure
  • Set intelligence priorities and collection requirements for cyber threat intelligence, digital risk protection, social media monitoring, and vulnerability research
  • Serve as incident commander when on-call for security events and lead incident bridges involving the vSOC, Clubs, Legal, Privacy, Communications, Technology, and other stakeholders
  • Exercise delegated authority to direct containment, recovery, forensic response, and cross-functional incident coordination
  • Lead post-incident reviews, document findings, update playbooks and controls, and track corrective actions through completion

Security Awareness and Incident Readiness

  • Lead analysts, contractors, vSOC partners, and external security providers supporting intelligence and response operations
  • Own MLB's security awareness strategy, including training, education, and phishing simulations based on current attacker methods and observed risk
  • Plan and lead League-wide, Club, and internal tabletop exercises to test incident response plans, escalation procedures, communications, and playbooks
  • Develop and maintain incident response plans, escalation paths, procedures, and playbooks for endpoint, identity, cloud, email, third-party, ransomware, and business email compromise scenarios

Qualifications & Skills

  • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Criminal Justice, Criminology, Law, or a related field, or equivalent practical experience
  • Strong knowledge of threat actors, campaigns, indicators of compromise, tactics, techniques, and procedures, including practical use of the MITRE ATT&CK framework
  • Working knowledge of AWS or GCP and scripting, detection, or query languages such as PowerShell, Python, SQL, KQL, SPL, Sigma, or YARA
  • Experience in cyber threat intelligence, incident response, security operations, digital forensics, or a related security role
  • Experience leading security incidents through triage, escalation, containment, eradication, recovery, and post-incident review
  • Experience developing and running threat hunts across endpoint, identity, cloud, network, email, or application data
  • Experience designing or delivering security awareness training and phishing simulation programs is a plus
  • Experience developing or tuning detection content using SIEM queries, EDR logic, Sigma, YARA, or detection-as-code practices
  • Hands-on experience with EDR/XDR, SIEM, and vulnerability assessment platforms
  • Experience using OSINT, social media sources, deep and dark web monitoring, and commercial threat intelligence platforms
  • Experience with security automation and orchestration (SOAR) platforms, including building workflows for threat intel research, enrichment, correlation, and reporting
  • Strong documentation and communication skills, including the ability to explain attack methods, response decisions, and risk to technical and non-technical audiences
  • Ability to handle sensitive information and participate in a rotational after-hours on-call and incident escalation schedule

Preferred Certifications

  • CompTIA Cybersecurity Analyst (CySA+)
  • CompTIA Certified Threat Intelligence Analyst (CTIA)
  • SANS GIAC Cyber Threat Intelligence (GCTI)

Salary Range: $105,000 - $135,000 (Base Salary) + Bonus

As a candidate for this position, your salary and related aspects of compensation will be contingent upon your work experience, education, skills, and any other factors MLB considers relevant to the hiring decision. In addition to your salary, MLB believes in providing a competitive compensation and benefits package for its employees.

Top MLB Perks & Benefits

  • Competitive Benefits Package
  • Company 401K Contribution
  • Paid Time Off and Holidays
  • Paid Parental Leave
  • Access to Free Tickets to Baseball Games & MLB.TV
  • Discounts at MLB Store | MLBShop.com
  • Employee Assistance Programs (EAP)
  • Onsite/Online Training & Development Programs
  • Tuition Reimbursement
  • Disability Benefits (short term and long term)
  • Life and Accidental Death Insurance
  • Pet Insurance