If you are motivated and believe in the credit union philosophy of "People Helping People," join our team!
About the roleThe Senior Cyber Intelligence Analyst is the technical lead for intelligence-driven detection and exposure management. You own the analytic tradecraft, the detection engineering standards, and the intelligence products that shape how the organization prioritizes vulnerabilities, builds detections, and briefs leadership. You set the bar for the team's Splunk work, mentor analysts, and represent threat intelligence to peer teams and executives.
This is a senior individual-contributor role with real ownership. You are expected to define how the work gets done, not just do it, and to make defensible analytic calls that leadership will act on.
What you will doLead threat intelligence and analysis
- Own the intelligence requirements process: define priority intelligence requirements with stakeholders, maintain the collection plan, and evaluate feed and vendor value.
- Lead analysis of threat actors, campaigns, malware families, and TTPs relevant to financial services, our technology stack, and our third-party ecosystem, mapped to MITRE ATT&CK.
- Produce and quality-review decision-ready intelligence products at the tactical, operational, and strategic levels, including briefings for the CISO and contributions to governance and Board-level reporting.
- Own the threat-informed assessment of newly disclosed vulnerabilities (CISA KEV, EPSS, exploit availability, vendor advisories) and drive that assessment into vulnerability prioritization and emergency remediation decisions.
- Lead intelligence support to incident response: attribution, campaign context, indicator enrichment, and post-incident lessons that become detections and requirements.
- Represent the organization in industry sharing communities (FS-ISAC and peer groups) and build relationships with vendor and government intelligence contacts.
Lead detection engineering
- Own the detection engineering program in Splunk Enterprise Security: standards, lifecycle, coverage measurement, and the tuning process.
- Design and build high-value detections, correlation searches, and risk-based alerting (RBA) logic; review and mentor others' detection work.
- Maintain the MITRE ATT&CK coverage map, prioritize gaps against current threat intelligence and crown-jewel assets, and drive a roadmap to close them.
- Establish detection-as-code practices: version control, peer review, testing against replayed or emulated attack data, and controlled deployment.
- Lead purple-team and adversary emulation exercises to validate detections and measure real coverage rather than assumed coverage.
- Set standards for SPL quality, data model use, CIM compliance, and search performance; partner with the Splunk platform team on data onboarding and platform direction.
Lead threat hunting and exposure management
- Design and run the threat hunting program: hunt hypotheses tied to priority intelligence requirements, documented methodology, and outcomes that feed detections and remediation.
- Lead cross-source analysis correlating vulnerability data (Tenable) with endpoint (SentinelOne), source control (GitHub), network and edge (F5, Check Point, Zscaler), and email (Proofpoint) telemetry to identify exposed, exploitable, and actively targeted assets.
- Serve as the threat intelligence lead for the continuous threat exposure management (CTEM) program, ensuring exposure prioritization reflects real adversary behavior and business impact.
- Provide threat research and detection strategy for emerging programs in AI security, software supply chain and third-party risk, and application security.
Mentor, influence, and report
- Mentor and technically guide analysts on the team; review analytic products and detections for rigor and clarity.
- Own the team's Splunk dashboards and scheduled reporting for intelligence metrics, detection coverage, hunt outcomes, and threat-informed vulnerability metrics that roll up to leadership reporting.
- Influence remediation and control decisions across IT operations, application owners, and engineering by presenting evidence-based risk assessments.
- Brief executives and governance audiences clearly and credibly, including confidence levels and dissenting assessments.
Required
- 7+ years in cybersecurity with at least 4 years in threat intelligence, detection engineering, or threat hunting, including experience leading work streams or projects.
- Expert hands-on Splunk skills: advanced SPL, Splunk Enterprise Security, correlation searches, risk-based alerting, data models, CIM, and search optimization.
- A track record of building detection programs or coverage strategies, not just individual detections, and measuring their effectiveness.
- Deep working knowledge of MITRE ATT&CK, structured analytic techniques, and intelligence product standards (confidence language, sourcing, analytic rigor).
- Strong understanding of attacker tradecraft across endpoint, network, identity, cloud, and email, with the ability to translate it into telemetry and search logic.
- Experience integrating threat intelligence into vulnerability prioritization using CVSS, VPR, EPSS, CISA KEV, and exploit intelligence.
- Excellent analytic writing and briefing skills; comfortable presenting to executives and defending assessments under scrutiny.
- Demonstrated ability to mentor and raise the technical bar for a team.
Preferred
- Experience in financial services or another regulated environment, with familiarity in FFIEC, NIST CSF, CIS Controls, and PCI DSS expectations for threat intelligence and monitoring.
- Experience with Tenable, SentinelOne, GitHub Advanced Security, Zscaler, Proofpoint, or comparable platforms.
- Python for enrichment, automation, and data analysis; experience with security APIs and STIX/TAXII; experience operating a threat intelligence platform (TIP).
- Experience with detection-as-code tooling and CI/CD for detections.
- Hands-on experience with CTEM or exposure management platforms.
- Experience running purple-team or adversary emulation programs.
- Certifications such as GCTI, GCDA, GCFA, GREM, Splunk Enterprise Security Certified Admin, or CISSP.
- Research or practical experience in AI/ML security, software supply chain security, or application security.
SECU provides equal employment opportunity to all qualified persons regardless of race, color, religion, age, sex, sexual orientation, gender identity, national origin, genetic information, disability, veteran status, or other classification protected by law.
Disclaimer
State Employees' Credit Union reserves the right to fill this role at a higher/lower level based on business need.
Skills Required
- 7+ years of cybersecurity experience, including at least 4 years in threat intelligence, detection engineering, or threat hunting
- Experience leading workstreams or projects
- Expert hands-on Splunk skills, including advanced SPL, Splunk Enterprise Security, correlation searches, risk-based alerting, data models, CIM, and search optimization
- Experience building detection programs or coverage strategies and measuring effectiveness
- Deep knowledge of MITRE ATT&CK, structured analytic techniques, and intelligence product standards
- Understanding of attacker tradecraft across endpoint, network, identity, cloud, and email
- Experience integrating threat intelligence into vulnerability prioritization using CVSS, VPR, EPSS, CISA KEV, and exploit intelligence
- Excellent analytic writing and briefing skills, including executive presentations
- Demonstrated ability to mentor analysts and raise technical standards
- Experience in financial services or another regulated environment
- Familiarity with FFIEC, NIST CSF, CIS Controls, and PCI DSS expectations
- Experience with Tenable, SentinelOne, GitHub Advanced Security, Zscaler, Proofpoint, or comparable platforms
- Python experience for enrichment, automation, and data analysis
- Experience with security APIs and STIX/TAXII
- Experience operating a threat intelligence platform
- Experience with detection-as-code tooling and CI/CD for detections
- Hands-on experience with CTEM or exposure management platforms
- Experience running purple-team or adversary emulation programs
- Certifications such as GCTI, GCDA, GCFA, GREM, Splunk Enterprise Security Certified Admin, or CISSP
- Research or practical experience in AI/ML security, software supply chain security, or application security
SECU Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about SECU and has not been reviewed or approved by SECU.
-
Retirement Support — Immediate 100% vesting and a 200% employer match on employee 401(k) contributions from 1–5% of pay (up to a 10% employer match) stand out. This level of support is described as unusually rich among financial‑services employers.
-
Leave & Time Off Breadth — 11 paid holidays plus 16 floating‑holiday hours, paid parental and caregiver leave, bereavement and volunteer time, and PTO that can reach 32 days per year with carryover up to 280 hours. These provisions provide predictable time off and flexibility across life events.
-
Healthcare Strength — Medical (PPO or HDHP) with HSA/FSA options, dental including a minor‑child orthodontia option, and vision are available for employees and eligible dependents. Employer‑paid basic life/AD&D and short‑term disability, with subsidized long‑term disability, add robust income protection.
SECU Insights
What We Do
Even though we're North Carolina's largest credit union, we're still just "people helping people." We currently serve over 2.6 million members through more than 270 branch offices - and growing! Members have 24/7 access to account services from over 1,100 ATMs, as well as via phone, our website, and the SECU Mobile App. Since 1937, we've provided financial services to employees of the State of North Carolina, public boards of education, and employees of associations formed for the benefit of State employees, as well as their immediate family members. We are the trusted provider of financial services for millions of members. And, according to Forbes Magazine, we're the best credit union in North Carolina. State Employees' Credit Union (SECU) is an Equal Housing Opportunity lender and federally insured by NCUA. SECU provides equal employment opportunity to all qualified persons regardless of race, color, religion, age, sex, sexual orientation, gender identity, national origin, genetic information, disability, veteran status, or other classification protected by law.








