CSIS Intelligence Lead Analyst - Advanced Analytics and Cyber OSINT

Citigroup Inc.

Charlotte (NC)

On-site

USD 117,000 - 176,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Citigroup Inc. in Charlotte, NC seeks an Intelligence Lead Analyst to own and enhance link analysis frameworks while building in-house automation for intelligence collection at scale.

In this senior role you will combine cyber OSINT mastery with software development to surface actionable intelligence, drive detections, and support threat hunting across one of the world’s largest financial institutions. Strong collaboration with global teams and mentoring junior members are expected as you shape

Responsibilities

  • Fulfill cyber OSINT requests with advanced analysis tools
  • Anticipate gaps and develop innovative solutions with stakeholders
  • Design (develop), implement, and maintain in-house solutions for collecting, processing, and analyzing open source data
  • Automate intelligence collection capabilities, leveraging existing link analysis frameworks
  • Apply in-depth disciplinary knowledge to triage, process, and analyze intelligence alerts, reports, and briefings
  • Engage in liaison activities with developers, intelligence communities, law enforcement, industry partners, peer financial institutions, and information sharing communities
  • Manage multiple projects simultaneously with a proactive, self-motivated approach, ensuring timely delivery of high-quality results while collaborating effectively with global teams
  • Complete the daily operational components of the intelligence mission
  • Assume an informal/formal mentor role within teams and assist with the coaching and training of new team members.

Job description

We're looking for a sharp, drivenIntelligence Lead Analystto join a team that doesn't just analyze intelligence — itbuilds the tools that collect it.

In this senior-level role, you'll take ownership of maintaining and enhancing our link analysis frameworks while engineering in-house solutions to automate intelligence collection at scale. Your work will directly shape how we identify, pursue, and neutralize threats across one of the world's largest financial institutions.

This role is fundamentally about two things: CyberOSINT masteryandtechnical innovation. If you thrive at the intersection of intelligence analysis and software development, this is your opportunity.

Job Description

The Intelligence Senior Analyst is an senior-level position responsible for collection/analysis of IoCs and TTPs, maintaining and updating existing link analysis frameworks while also developing in-house solutions to automate intelligence collection. The primary objective of this role is to leverage Open Source Intelligence (OSINT) and development skills to build and operate advanced intelligence capabilities. While familiarity with the cyber domain is welcome, the core focus is on OSINT analysis and the creation of automated collection tools.

Responsibilities
  • Fulfill cyber OSINT requests by applying advanced analysis tools and techniques to surface timely, actionable intelligence.
  • Proactively anticipate gaps in our intelligence posture and develop innovative solutions, collaborating with internal and external stakeholders on open-source methodologies and tooling.
  • Design (develop), implement, and maintain in-house solutions for collecting, processing, and analyzing open source data.
  • Automate intelligence collection capabilities, leveraging existing link analysis frameworks and actively identifying and evaluating alternative solution providers.
  • Apply in-depth disciplinary knowledge to triage, process, and analyze intelligence alerts, reports, and briefings.
  • Engage in liaison activities with developers, intelligence communities, law enforcement, industry partners, peer financial institutions, and information sharing communities.
  • Manage multiple projects simultaneously with a proactive, self-motivated approach, ensuring timely delivery of high-quality results while collaborating effectively with global teams.
  • Complete the daily operational components of the intelligence mission.
  • Assume an informal/formal mentor role within teams and assist with the coaching and training of new team members.
Qualifications
  • 6-10 years of relevant experience
  • Should have a working knowledge in one or more of the following areas: Advanced Persistent Threat, Third Party Risks/Threats, Cybercrime, Extremist Groups and Cyber Terrorists, Hacktivism, Distributed Denial of Service attacks, Fraud, Malware, Mobile Threats
  • Proven track record of operationalizing cyber threat intelligence - translating raw intelligence into detections, hunt packages, and risk-relevant reporting.
  • Consistently demonstrates clear and concise written and verbal communication
  • Proven influencing and relationship management skills
  • Proven analytical skills
Education
  • Bachelor’s degree/University degree or equivalent experience
  • Master’s degree preferred (Advanced degree preferred, ideally in Computer Science, Cybersecurity, Information Security, or a related STEM discipline)
  • Additional valued certifications include: CREST CCTIM, Recorded Future Certified Analyst, CISSP, CEH, or OSCP.
Required Skills
  • Proficiency in the MITRE ATT&CK framework - mapping adversary TTPs, building hunt hypotheses, and driving detection coverage analysis.
  • Hands-on experience with Threat Intelligence Platforms including Recorded Future, Mandiant Advantage, ThreatConnect, MISP, or OpenCTI.
  • Experience with scripting and automation languages including Python, PowerShell, and Bash for intelligence collection, enrichment pipelines, and hunt tooling development.
  • Advanced OSINT tradecraft including dark web monitoring, social media intelligence, infrastructure pivoting, and digital footprint analysis.
  • Experience with link analysis platforms such as Palantir, Maltego, and i2 Analyst's Notebook, including building custom extractors, web scrapers, and automation workflows to support investigative and analytical tasks.
  • Solid understanding of network forensics, log analysis, and reverse engineering in support of hunt operations.
  • Working knowledge of malware analysis (static and dynamic) and adversary infrastructure analysis.
  • Exceptional written and verbal communication skills with the ability to produce intelligence products for both technical and executive audiences, consistently demonstrating clarity, conciseness, and attention to detail.
  • Proven influencing, relationship management, and analytical skills with a track record of driving outcomes across cross-functional teams.

This job description provides a high-level review of the types of work performed. Other job-related duties may be assigned as required.

#LI-EL1

Job Family Group

Technology

Job Family

Information Security

Time Type

Full time

Primary Location

NC-CHARLOTTE (BALLANTYNE)

Primary Location Full Time Salary Range

$117,440.00 - $176,160.00

In addition to salary, Citi's offerings may also include, for eligible employees, discretionary and formulaic incentive and retention awards. Citi offers competitive employee benefits, including: medical, dental & vision coverage; 401(k); life, accident, and disability insurance; and wellness programs. Citi also offers paid time off packages, including planned time off (vacation), unplanned time off (sick leave), and paid holidays. For additional information regarding Citi employee benefits, please visit citibenefits.com. Available offerings may vary by jurisdiction, job level, and date of hire.

Anticipated Posting Close Date

Sep 02, 2026

Automated Processing and AI

We use automated processing, including artificial intelligence, for our legitimate business interests (or our reasonable and appropriate business purposes) to identify and align the candidate's skills and abilities with a specific job opening. Additionally, if you so choose, or consent, we can match your skills and abilities to other suitable roles at Citi.

Importantly, all our hiring processes and decisions, including determining your suitability for a role, are conducted, checked, and decided by individuals. Our automated processing and AI do not involve relying on automatic or autonomous decision-making. Please refer to any Jurisdictional Considerations, with specific provisions for your country (where relevant) for further details.

EEO Statement

Citi is an equal opportunity employer, and qualified candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other characteristic protected by law.

Accessibility

If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review Accessibility at Citi. View Citi’s EEO Policy Statement and the Know Your Rights poster.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

CSIS Intelligence Lead Analyst - Advanced Analytics and Cyber OSINT
CSIS Intelligence Lead Analyst - Advanced Analytics and Cyber OSINT

Citi • Charlotte (NC)

On-site
USD 117,000 - 176,000
CSIS Intelligence Lead Analyst - Advanced Analytics and Cyber OSINT
CSIS Intelligence Lead Analyst - Advanced Analytics and Cyber OSINT

Citibank (Switzerland) AG • Charlotte (NC), Northern (KY)

Hybrid
Confidential
Medical, dental & vision coverage
401(k)
Life, accident, and disability ins.
+2
Cybersecurity Insider Threat, Director
Cybersecurity Insider Threat, Director

Citigroup Inc. • Tampa (FL)

On-site
USD 170,000 - 300,000
Medical, dental, vision benefits
401(k) retirement plan
Paid time off and holidays
+1
Cyber Defense Analyst VP
Cyber Defense Analyst VP

Citi • Irving (TX)

On-site
USD 126,000 - 189,000
Medical, dental & vision coverage
401(k)
Life, accident, and disability保险
+2
Cybersecurity Insider Threat Lead
Cybersecurity Insider Threat Lead

Citi • Tampa (FL)

On-site
USD 141,000 - 212,000
Medical, dental & vision coverage
401(k)
Life, accident, and disability保险
+3
Cybersecurity Insider Threat Lead
Cybersecurity Insider Threat Lead

Citigroup Inc. • Tampa (FL)

On-site
USD 141,000 - 212,000
Artificial Intelligence (AI) Offensive Security Analyst
Artificial Intelligence (AI) Offensive Security Analyst

Citi • Tampa (FL)

On-site
USD 87,000 - 212,000
Cybersecurity Insider Threat Lead
Cybersecurity Insider Threat Lead

Citibank (Switzerland) AG • Tampa (FL)

On-site
Confidential
Medical, dental & vision coverage
401(k)
Life, accident, and disability ins.
+2
Cyber Defense Analyst VP
Cyber Defense Analyst VP

Citigroup Inc. • Irving (TX)

On-site
USD 126,000 - 189,000
Medical, dental & vision
401(k)
Paid time off
Intelligence Lead Analyst Vice President
Intelligence Lead Analyst Vice President

Citi • San Antonio (TX)

On-site
USD 114,000 - 171,000
Medical, dental & vision coverage
401(k) plan
Paid time off