Cyber Intelligence Analyst

100 Eli Lilly and Company

Indianapolis (IN)

Hybrid

USD 65,000 - 158,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Lilly is seeking aCyber Intelligence Analyst to join the Global Cyber Defense Operations at its Indianapolis base. The role covers External Threat Response, Threat Intelligence, and Defense Readiness with on-call rotations and cross-functional collaboration.

Ideal candidates will have enterprise cybersecurity detection and analysis experience, strong documentation, and the ability to translate complex issues for non-technical stakeholders. Hybrid work is offered with travel as needed.

Qualifications

  • Bachelor’s degree preferred in CS/IT/Cybersecurity or related field.
  • Experience in enterprise cybersecurity detection/analysis.
  • Excellent documentation skills.

Responsibilities

  • Assist in cybersecurity work across core functions.
  • Analyze cyber threats and incidents.
  • Develop capabilities for core functions and document analyses.
  • Detect and prioritize threats.
  • Respond to incidents and recommend improvements.

Skills

Cyber Threat Intelligence
Endpoint Security
IR/Forensics
Documentation
Networking basics
Programming (Python, PowerShell)
Threat hunting

Education

Bachelor’s degree in CS/IT/Cybersecurity

Tools

PowerShell
Python
KQL/SPL

Job description

At Lilly, the work is demanding because patients are waiting. We unite caring with discovery to help make life better for people around the world, knowing that every decision, every detail, and every day matters. Headquartered in Indianapolis, Indiana, our over 50,000 employees around the globe take on complex challenges to discover and deliver life-changing medicines, strengthen how health is understood and managed, and support the communities we serve. This is hard, urgent, selfless work—but it’s work worth doing. If you’re driven by purpose and ready to bring your best to work that truly matters for patients, we invite you to join us. Do you like to be in the heart of the action, on the front lines of cybersecurity defense, creating a defense system to thwart cyber-attacks? Join us as we do this daily to protect our patients, employees, and shareholders. The Global Cyber Defense Operations (GCDO) team is dedicated to active defense through analysis, innovation, and collaboration. Our mission focuses on unifying detection, analysis, and response strategies to safeguard Lilly's ability to develop life-changing medicines. The threat of cybersecurity attacks has never been greater, and the GCDO’s mission has never been more important.

The Cyber Intelligence Analyst will operate in a functional group focusing on any of the following: Cyber Threat Intelligence, Detection and Automation Operations, Cyber Defense Readiness, External Threat Response, and Insider Threat Response. Analysts typically begin with an assignment in the External Threat Response (ETR) function; however, you may be assigned to any of the core GCDO functions (Cyber Threat Intelligence, Cyber Defense Readiness, Detection and Analysis Operations, Internal Threat Response) based on skills, development needs, and specific needs of the team. The functions of the GCDO are as follows: External Threat Response (ETR): Responsible for the monitoring, detection, analysis, investigation, and response to cybersecurity related events and incidents. Cyber Threat Intelligence (CTI): Leading efforts across the organization to consume, contribute, and produce threat intelligence, both internal and external to Lilly. Maintain, develop, and evangelize to partner functions an understanding of threats, attack campaigns and intrusion sets targeting Lilly. Cyber Defense Readiness (CDR): Responsible for the integration of key initiatives between the GCDO and the rest of Cybersecurity and other business partners. Detection and Analysis Operations (DAO): Responsible for general SecOps and DevOps of GCDO owned capability to empower the organization. Establishing the platform and services to enable the effective detection and monitoring of security events, as well as providing a means to analyze and improve detections. Internal Threat Response (ITR): Responsible for the monitoring, analysis, and investigation of cybersecurity related events and incidents, with a focus on the internal workforce.

How You Will Succeed
  • Supporting: Assisting in various cybersecurity and other work as assigned.
  • Analyzing: Examining cyber threats and incidents.
  • Developing: Creating capability to enable each core function.
  • Documenting: Thorough documentation of your analysis.
  • Detecting: Identifying potential security issues.
  • Prioritizing: Ranking threats based on severity.
  • Responding: Taking action to mitigate threats.
  • Recommending Strategic Changes: Drive security improvements that will increase our ability to defend the Enterprise.

Provide rotational on-call availability for cybersecurity incidents raised outside of normal business working hours.

Basic Qualifications
  • HS Diploma or GED
  • At least 2+ years of demonstrated experience in network operations or engineer and/or system administration, troubleshooting, or similar Information Technology related experience
  • Demonstrated experience and excellence in documentation skills
  • Experience working on Enterprise level cybersecurity detection and analysis
  • Qualified candidates must be legally authorized to be employed in the United States.
  • Lilly does not anticipate providing sponsorship for employment visa status (e.g., H-1B or TN status)
What You Should Bring
  • Bachelor’s Degree in Computer Science/Information Technology/Cybersecurity or related is preferred
  • Experience with monitoring system operations and reacting to events in response to triggers and/or observation of trends or unusual activity.
  • Ability to communicate complex technical issues to non-technical personnel
  • Demonstrated skills in: Use of endpoint security tools to collect information for digital forensics and incident response efforts.
  • Use of strong investigatory principles to surface and pivot on information and insights that are material to a cyber investigation.
  • Auditing firewalls, perimeters, routers, and intrusion detection systems.
  • Relevant programming and query languages (e.g., PowerShell, bash, FQL, KQL, SPL, C++, Python, etc.).
  • Reverse engineering (e.g., software debugging, de-compilation of code, binary literacy, Windows OS internals) to identify function and capability of malicious code.
  • General knowledge of: Risk management processes (e.g., methods for assessing and mitigating risk).
  • Current software and methodologies for active defense and system hardening.
  • Netflow and raw network traffic data; foundational networking protocols such as IP, TCP, UDP, DNS, and HTTP.
  • Malware – static and dynamic analysis techniques, detection methodologies and analysis techniques.
  • Cloud technologies, cloud service models, resource pooling, authentication, and logging capabilities associated with major service providers.
  • Laws, regulations, policies, and ethics as they relate to cybersecurity and privacy.
  • Certifications addressing new attack vectors (emphasis on cloud computing technology, mobile platforms, and tablet computers), new vulnerabilities, existing threats to operating environments, managing, maintaining, troubleshooting, installing, configuring basic network infrastructure.
Location & Work Flexibility

This role is based at our Corporate Center in Indianapolis, IN. We offer a flexible hybrid work model, with three days onsite and two days working remotely each week, supporting both collaboration and work-life balance. Some travel may be required.

Lilly is dedicated to helping individuals with disabilities to actively engage in the workforce, ensuring equal opportunities when vying for positions.

Equality & Inclusion

Lilly is proud to be an EEO Employer and does not discriminate on the basis of age, race, color, religion, gender identity, sex, gender expression, sexual orientation, genetic information, ancestry, national origin, protected veteran status, disability, or any other legally protected status.

Our employee resource groups (ERGs) offer strong support networks for their members and are open to all employees. Our current groups include: Africa, Middle East, Central Asia (AMECA), Black Employees at Lilly (BE@Lilly), Chinese Culture Network (CCN), EnAble, Evolve, Lilly Indian Network (LIN), Organization of Latinx at Lilly (OLA), Pride (LGBTQ+ Allies), Veterans Leadership Network (VLN) and Women’s Initiative for Leading at Lilly (WILL).

Actual compensation will depend on a candidate’s education, experience, skills, and geographic location.

The anticipated wage for this position is $64,500 - $158,400

Full-time equivalent employees also will be eligible for a company bonus (depending, in part, on company and individual performance).

In addition, Lilly offers a comprehensive benefit program to eligible employees, including:

  • eligibility to participate in a company-sponsored 401(k)
  • pension
  • vacation benefits
  • eligibility for medical, dental, vision and prescription drug benefits
  • flexible benefits (e.g., healthcare and/or dependent day care flexible spending accounts)
  • life insurance and death benefits
  • certain time off and leave of absence benefits
  • well-being benefits (e.g., employee assistance program, fitness benefits, and employee clubs and activities)

Lilly reserves the right to amend, modify, or terminate its compensation and benefit programs in its sole discretion and Lilly’s compensation practices and guidelines will apply regarding the details of any promotion or transfer of Lilly employees.

At Lilly we strive to ensure our employees are part of a team that cares about them and our shared purpose of making life better for those around the world. How do we do this? We continue to look for ways to include, innovate, accelerate and deliver while maintaining integrity, excellence and respect for people. We hope that you seek to join us on our journey as we create medicine and deliver improved outcomes for patients across the globe!

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Threat Mitigation Lead - Cloud Security
Threat Mitigation Lead - Cloud Security

Initial Therapeutics, Inc. • Indiana (PA)

On-site
USD 135,000 - 214,000
401(k) and pension benefits
Medical, dental, and vision benefits
Flexible spending accounts
+2
Sr. Engineer – Cyber Intelligence Analyst (R2 – R4)
Sr. Engineer – Cyber Intelligence Analyst (R2 – R4)

Initial Therapeutics, Inc. • Indianapolis (IN)

Hybrid
USD 61,000 - 119,000
Comprehensive benefits program
401(k) and pension options
Flexible spending accounts
Cybersecurity Analyst (R1-R4)
Cybersecurity Analyst (R1-R4)

Socket.dev • Indianapolis (IN)

Hybrid
USD 62,000 - 104,000
Sr Director - Enterprise Connectivity & Network Services
Sr Director - Enterprise Connectivity & Network Services

100 Eli Lilly and Company • Indianapolis (IN)

Hybrid
USD 157,500 - 231,000
Cybersecurity Analyst (R1-R4)
Cybersecurity Analyst (R1-R4)

Initial Therapeutics, Inc. • Indianapolis (IN)

On-site
USD 61,000 - 104,000
401(k) retirement plan
Comprehensive health benefits
Paid vacation
Associate Director – Integrated Risk Data Engineer
Associate Director – Integrated Risk Data Engineer

Initial Therapeutics, Inc. • Indianapolis (IN)

On-site
USD 124,500 - 182,600
Company bonus
401(k)
Pension
+2
Sr Principal Cybersecurity Architect
Sr Principal Cybersecurity Architect

Initial Therapeutics, Inc. • Indianapolis (IN)

On-site
USD 126,000 - 224,000
Bonus program
401(k) matching
Comprehensive benefits
Sr Director - Enterprise Connectivity & Network Services
Sr Director - Enterprise Connectivity & Network Services

Eli Lilly and Company • Indianapolis (IN)

Hybrid
USD 157,500 - 231,000
Sr Principal Cybersecurity Architect
Sr Principal Cybersecurity Architect

100 Eli Lilly and Company • Indianapolis (IN)

On-site
USD 126,000 - 224,000
401(k)
Pension
Vacation benefits
+7
Manager - Validation Lead – Technical Support & Operations – Global Services
Manager - Validation Lead – Technical Support & Operations – Global Services

100 Eli Lilly and Company • Indianapolis (IN)

On-site
USD 65,000 - 152,000
401(k) plan
Excellent medical benefits
Bonus potential