Cyber Threat Intelligence Analyst

Posted 2 Days Ago
Be an Early Applicant
Austin, TX, USA
In-Office
Senior level
Information Technology • Security • Consulting • Cybersecurity
The Role
Monitor, analyze, and operationalize threat intelligence; triage alerts and create incidents; administer threat intelligence platforms and feed ingestion; integrate intelligence with SIEM and ServiceNow; distribute CVE advisories; produce reports and briefings; support incident response, remediation, and intelligence-driven forecasting.
Summary Generated by Built In

This is an onsite position; only local candidates will be considered.

The Cyber Threat Intelligence Analyst will support the Texas Department of Transportation (TxDOT) on the Cybersecurity Operations Center (CSOC) threat intelligence program. This role is responsible for monitoring, analyzing, and operationalizing cyber threat intelligence across enterprise environments to reduce cybersecurity risk and improve organizational awareness. The analyst will administer threat intelligence platforms, support incident response activities, and integrate intelligence capabilities into existing security operations processes. This position works closely with Incident Response, Security Operations, Vulnerability Management, and Infrastructure teams to support threat investigations and remediation efforts across TxDOT systems, vendors, and business functions.

Responsibilities:

  • Triage threat intelligence alerts generated from intelligence platforms and external intelligence sources.
  • Create security incidents and route them to appropriate teams for investigation and resolution.
  • Analyze, validate, and distribute Critical and Zero-Day CVE advisories to impacted stakeholders.
  • Administer threat intelligence platforms, including tuning, scoping, content management, reporting, and platform optimization.
  • Upload, validate, and maintain TxDOT organizational data within intelligence platforms, including user account inventories, technology asset information, business partner listings, and third-party vendor data.
  • Manage intelligence feed subscriptions and ensure threat intelligence data is properly integrated into cybersecurity monitoring systems.
  • Verify threat intelligence feed ingestion into SIEM platforms and troubleshoot feed-related issues.
  • Integrate threat intelligence platforms with TxDOT systems, including SIEM, ServiceNow, ticketing workflows, and reporting solutions.
  • Develop operational reports, threat trend summaries, and executive-level intelligence briefings.
  • Conduct threat analysis and forecasting to identify emerging risks affecting TxDOT systems, vendors, and business functions.
  • Maintain documentation, procedures, and intelligence workflows supporting cybersecurity operations.


Requirements

Minimum Qualifications:

  • 5 years of experience performing cyber threat intelligence analysis within a Security Operations Center (SOC) or Cybersecurity Operations environment.
  • 5 years of experience with threat intelligence platforms such as Recorded Future, CrowdStrike Intelligence, Anomali, Mandiant, Flashpoint, or equivalent.
  • 5 years of experience analyzing Indicators of Compromise (IOCs), adversary TTPs, malware campaigns, and vulnerability intelligence.
  • 5 years of experience creating and managing security incidents, case management workflows, and incident escalation processes.
  • 5 years of experience with SIEM technologies and intelligence feed integration.
  • 5 years of knowledge of cybersecurity frameworks including MITRE ATT&CK, NIST Cybersecurity Framework, and CIS Controls.
  • 5 years of experience communicating cybersecurity risks and intelligence findings to technical and non-technical stakeholders.
  • 5 years of strong written communication, documentation, reporting, and analytical skills.

Preferred Qualifications:

  • Certified Threat Intelligence Analyst (CTIA) certification.
  • GIAC Cyber Threat Intelligence (GCTI) certification.
  • Experience administering Recorded Future platforms and intelligence modules.
  • Experience integrating threat intelligence with Splunk, Microsoft Sentinel, QRadar, or equivalent SIEM platforms.
  • Experience integrating cybersecurity tools with ServiceNow.
  • Experience managing third-party risk intelligence or vendor intelligence programs.
  • Experience with TAXII/STIX frameworks and automated intelligence sharing.
  • Knowledge of vulnerability management, CVE monitoring, and zero-day response processes.
  • Experience with scripting and automation using PowerShell or Python.
  • Familiarity with state government cybersecurity operations and compliance requirements.
Additional Requirements:
  • Local candidates only; must currently live within 50 miles of the Austin, Texas work location.
  • May be required to work outside normal business hours.

Work Location and Schedule:

Location: 125 E 11th St, Austin, TX 78701
Schedule: Monday through Friday, 8:00 a.m. to 5:00 p.m., excluding Texas state holidays.
Work Arrangement: Onsite


Skills Required

  • 5 years of experience performing cyber threat intelligence analysis within a Security Operations Center (SOC) or Cybersecurity Operations environment
  • 5 years of experience with threat intelligence platforms such as Recorded Future, CrowdStrike Intelligence, Anomali, Mandiant, Flashpoint, or equivalent
  • 5 years of experience analyzing Indicators of Compromise (IOCs), adversary TTPs, malware campaigns, and vulnerability intelligence
  • 5 years of experience creating and managing security incidents, case management workflows, and incident escalation processes
  • 5 years of experience with SIEM technologies and intelligence feed integration
  • 5 years of knowledge of cybersecurity frameworks including MITRE ATT&CK, NIST Cybersecurity Framework, and CIS Controls
  • 5 years of experience communicating cybersecurity risks and intelligence findings to technical and non-technical stakeholders
  • 5 years of strong written communication, documentation, reporting, and analytical skills
  • Certified Threat Intelligence Analyst (CTIA) certification
  • GIAC Cyber Threat Intelligence (GCTI) certification
  • Experience administering Recorded Future platforms and intelligence modules
  • Experience integrating threat intelligence with Splunk, Microsoft Sentinel, QRadar, or equivalent SIEM platforms
  • Experience integrating cybersecurity tools with ServiceNow
  • Experience managing third-party risk intelligence or vendor intelligence programs
  • Experience with TAXII/STIX frameworks and automated intelligence sharing
  • Knowledge of vulnerability management, CVE monitoring, and zero-day response processes
  • Experience with scripting and automation using PowerShell or Python
  • Familiarity with state government cybersecurity operations and compliance requirements
  • Must currently live within 50 miles of the Austin, Texas work location (local candidates only)
  • May be required to work outside normal business hours
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company

What We Do

Air InfoSec is a veteran-owned and led cybersecurity consulting and staffing firm based in Austin, Texas, focused on enhancing government security through expert staff placement.

Similar Jobs

General Motors Logo General Motors

Cyber Threat Intelligence Analyst

Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Hybrid
2 Locations
165000 Employees

General Motors Logo General Motors

Cyber Threat Intelligence Analyst

Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Hybrid
2 Locations
165000 Employees
In-Office
9 Locations
127K-149K Annually

Similar Companies Hiring

Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account