HamburgerMenu
hirist

Lead Cyber Threat Intelligence Analyst

TechStar Group
4 - 6 Years
Multiple Locations

Posted on: 06/10/2026

Job Description

Role Summary :

We are seeking a Lead CTI Analyst to work as a Cyber Threat Intelligence (CTI) domain SME supporting AI-driven automation of cybersecurity use cases. The role will focus on CTI data collection, analysis, curation, normalization, enrichment, and quality validation to build high-quality datasets and knowledge sources for AI automation, LLM/RAG solutions, and cybersecurity analytics. The role is for a Lead Engineer who will provide technical leadership, mentor and manage team members, guide solution design and implementation, and ensure timely delivery of project outcomes.

Responsibilities :

- Act as a Cyber Threat Intelligence (CTI) domain SME for AI automation of cybersecurity use cases.

- Collect, analyze, validate, curate, and normalize CTI data from open-source, commercial, and internal sources to support AI automation.

- Apply CTI analysis frameworks such as the CTI lifecycle, Diamond Model, Cyber Kill Chain, and Analysis of Competing Hypotheses (ACH) to structure and assess intelligence.

- Perform MITRE ATT&CK mapping and maintain contextual relationships between threat actors, campaigns, malware, vulnerabilities, techniques, and indicators.

- Handle IoCs using industry best practices, including defanging, hash-type identification, contextual validation, deduplication, and false-positive avoidance.

- Work with TLP 2.0 and PAP markings and ensure appropriate handling and dissemination of CTI data.

- Create, validate, and enrich STIX 2.1 objects and support TAXII 2.1-based CTI exchange and ingestion workflows.

- Operate and manage CTI platforms such as MISP and OpenCTI, including data models, APIs, feed management, PyMISP, and GraphQL.

- Use CTI enrichment services such as VirusTotal, URLScan, AbuseIPDB, Shodan, Censys, OTX, Whois, and PassiveDNS to enrich and validate indicators and entities.

- Apply OSINT tradecraft and security fundamentals while maintaining appropriate operational security (OPSEC).

- Support the creation of high-quality, traceable, and reusable CTI datasets for LLM fine-tuning, RAG, automated analysis, and other AI-driven cybersecurity applications.

- Manage the team of junior analysts and provide technical guidance.

- Collaborate with cybersecurity, data, AI/ML, and engineering teams to translate CTI analyst knowledge into structured data, rules, prompts, evaluation datasets, and automation workflows.

- Stay current with emerging threats, vulnerabilities, threat actor activity, malware, and CTI analysis methodologies.

Communication and Documentation :

- Excellent written and oral communication, presentation, listening and interpersonal skills.

- Collaborating effectively with internal and external team.

- Excellent reporting, time management, analytical & communication skills.

Preferred Skills :

- Experience with commercial Cyber Threat Intelligence (CTI) platforms and vendors.

- Familiarity with detection rule standards such as YARA, Sigma, Snort, and Suricata.

- Exposure to AI/ML, LLM, RAG, data curation, or cybersecurity automation use cases.

- Surface-level malware analysis and DFIR fundamentals.

- Knowledge of cloud security concepts.

- Certifications such as GCTI, GCIH, GCFA, CTIA, eCTHPv2, OSCP, or equivalent would be good to have.

Qualifications and Technical Skills :

- 4 - 6 years of previous experience in Cyber Threat Intelligence, threat research, security analysis, or a related cybersecurity domain.

- Strong knowledge of CTI analysis frameworks including CTI lifecycle, Diamond Model, Cyber Kill Chain, and ACH.

- Hands-on experience with MITRE ATT&CK mapping, TLP 2.0/PAP marking, STIX 2.1/TAXII 2.1, and IoC handling best practices.

- Experience with OSINT tradecraft, security fundamentals, and OPSEC principles.

- Hands-on experience with MISP and/or OpenCTI, including data models, APIs, PyMISP, GraphQL, and feed management.

- Experience using CTI enrichment tools/services such as VirusTotal, URLScan, AbuseIPDB, Shodan, Censys, OTX, Whois, and PassiveDNS.

- Good understanding of detection content standards including YARA, Sigma, Snort, and Suricata.

- Python knowledge, preferably with libraries such as stix2, PyMISP, taxii2-client, and vt-py.

- Working knowledge of SQL and one or more security query/search languages such as KQL, SPL, or Elastic DSL.

- Strong analytical, troubleshooting, problem-solving, and data-curation skills.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...