AI-Driven Threat Intelligence & Security Operations Analyst

Blackstone

New York (NY)

On-site

USD 135,000 - 170,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Blackstone is seeking an Associate Threat Intelligence Analyst within the Cyber Threat Intelligence team to monitor, analyze, and operationalize threats targeting the firm and its portfolio. This hands‑on role emphasizes AI tooling and production of actionable intelligence for security operations.

You will produce finished intelligence products, map campaigns to MITRE ATT&CK, and collaborate with detection engineering and incident response to drive new detections and preventions.

Qualifications

  • 2+ years in cyber threat intelligence, security operations, incident response, or related cybersecurity discipline.
  • Understanding of the cyber threat landscape, including prominent threat actor groups, campaigns, and TTPs.
  • Working knowledge of intelligence frameworks such as MITRE ATT&CK, the Diamond Model, or the Intelligence Cycle.
  • Experience with threat intelligence platforms (TIPs), SIEM tools (e.g., Splunk), OSINT research methodologies, or attack surface management / vulnerability management tooling.
  • Scripting or programming experience (Python preferred) for automating data collection, enrichment, and analytic workflows.
  • Demonstrated, hands‑on experience applying AI tooling (such as LLMs and coding assistants) to real work, and can clearly speak to several projects where you used AI to automate or accelerate a task.
  • Capable of writing clearly and developing visual products (such as diagrams) to communicate complex cyber threats to both technical and non‑technical stakeholders, including executive leadership.
  • Strong analytical reasoning, attention to detail, and capable of prioritizing effectively in a fast‑paced environment.
  • B.S. in Computer Science, Cybersecurity, Intelligence Studies, International Relations, or a related field

Responsibilities

  • Monitor and analyze cyber threat activity targeting the financial sector, alternative asset management, and adjacent industries using open-source, commercial, and internal sources, correlating across them to identify patterns and provide early warning of emerging campaigns
  • Produce finished intelligence products and reports including recurring threat reporting, advisories, campaign profiles, actor dossiers, executive briefings, and visual products such as diagrams, tailored to both technical and non‑technical audiences
  • Map adversary behaviors to the MITRE ATT&CK framework and maintain threat actor profiles covering TTPs, intent, and relevance to Blackstone
  • Extract, validate, enrich, and operationalize indicators of compromise (IOCs) to support detection engineering and incident response workflows
  • Leverage AI and automation tooling to scale collection, enrichment, and operationalization of intelligence
  • Partner with Alert, Detection & Response and Incident Response teams to translate intelligence into production detections (Splunk SPL, Sigma, YARA)
  • Track zero‑day and critical vulnerabilities, assess Blackstone's exposure, and translate findings into new detections and preventions in coordination with detection and security engineering
  • Support threat‑informed vulnerability prioritization (CVSS, EPSS, CISA KEV) and coordinate remediation tracking with asset owners
  • Operate and evolve the firm's external Attack Surface Management (ASM) program, discovering and inventorying internet‑facing assets across Blackstone and its portfolio companies, triaging newly discovered exposures and misconfigurations, and coordinating remediation
  • Support Fusion Center digital‑threat monitoring, including brand, executive, and reputational exposure across OSINT, social media, and dark web sources
  • Contribute to intelligence sharing with trusted industry partners, ISACs (such as FS‑ISAC), government partners (such as JCDC), and peer financial institutions
  • Participate in incident response and the SOC on‑call rotation (occasional, roughly every other month) to respond to escalated security incidents

Skills

MITRE ATT&CK
Diamond Model
Intelligence Cycle
Python
AI tooling
Clear communication
Analytical reasoning
Threat intelligence
OSINT research

Education

B.S. in Computer Science / Cybersecurity / Intelligence Studies

Tools

Splunk
Threat Intelligence Platforms (TIPs)

Job description

Blackstone is seeking an Associate Threat Intelligence Analyst within the Cyber Threat Intelligence team to monitor, analyze, and operationalize threats targeting the firm and its portfolio. This hands‑on role emphasizes AI tooling and production of actionable intelligence for security operations.

You will produce finished intelligence products, map campaigns to MITRE ATT&CK, and collaborate with detection engineering and incident response to drive new detections and preventions.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AI-Driven Cyber Threat Intelligence Lead
AI-Driven Cyber Threat Intelligence Lead

TRM • United States

Hybrid
USD 150,000 - 230,000
Threat Intelligence Engineer: AI Security & Detection
Threat Intelligence Engineer: AI Security & Detection

Anthropic • United States

Remote
USD 120,000 - 180,000
Senior Threat Intel Analyst — AI-Driven Security & Research
Senior Threat Intel Analyst — AI-Driven Security & Research

TENEX.AI • Overland Park (KS)

On-site
USD 100,000 - 130,000
Competitive salary
Opportunity for growth
Cutting-edge technology
Remote Threat Intelligence Investigator (AI Security)
Remote Threat Intelligence Investigator (AI Security)

Neura Market • Northern (KY)

Hybrid
USD 140,000 - 190,000
Relocation assistance
Threat Intelligence Analyst, Associate - Security Operations
Threat Intelligence Analyst, Associate - Security Operations

Blackstone • New York (NY)

On-site
USD 135,000 - 170,000
Threat Intelligence Analyst: Drive AI Security & Threat Insights
Threat Intelligence Analyst: Drive AI Security & Threat Insights

Check Point Software Technologies • Town of Texas (WI)

On-site
USD 65,000 - 90,000
Multilingual
Customer facing
Threat Intelligence Analyst | LockedIn AI at LockedIn AI
Threat Intelligence Analyst | LockedIn AI at LockedIn AI

METRO | 599 • New York (NY)

Hybrid
USD 90,000 - 130,000
Equity in the company
Remote-first culture
Growth opportunities
AI-Driven Threat Hunter & Intelligence Strategist
AI-Driven Threat Hunter & Intelligence Strategist

CrowdStrike • Iowa (LA)

On-site
USD 100,000 - 155,000
Wellness programs
Vacation and holidays
Parental leave
+4
Threat Intel Engineer: Detect & Hunt AI Security (Remote-Friendly)
Threat Intel Engineer: Detect & Hunt AI Security (Remote-Friendly)

Anthropic • New York (NY), San Francisco (CA), Washington

Hybrid
USD 320,000 - 405,000
Equity matching
Generous vacation
Parental leave
+1
Sr Cyber Threat Intelligence Analyst
Sr Cyber Threat Intelligence Analyst

PRI Technology • Austin (TX)

On-site
USD 90,000 - 120,000