Cyber Threat Intelligence Analyst III – Threat Hunting

AV

San Diego (CA)

On-site

USD 75,000 - 114,000

Full time

7 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Medical, dental, vision
401K with company match
9/80 work schedule
Paid holiday shutdown

Job summary

AV is seeking a Cyber Threat Intelligence Analyst to identify, analyze, and communicate cyber threats impacting the organization. The role blends traditional threat intelligence with hands-on cybersecurity to translate intelligence into detections, investigations, and defensive improvements.

The ideal candidate understands threat actors and geopolitical or industry threats while possessing hands-on familiarity with security technologies, telemetry, SIEM/XDR, and common attacker techniques.

Qualifications

  • Bachelor's degree or equivalent professional experience in cybersecurity or related field.
  • 3+ years of cybersecurity, threat intelligence, SOC, incident response, or related experience.
  • Strong understanding of cyber threat intelligence principles and lifecycle processes.
  • Strong technical aptitude with ability to investigate security data beyond reports.
  • Working knowledge of SIEM/XDR, EDR, network security, OS, identity, vulnerability management, and cloud security.
  • Knowledge of MITRE ATT&CK, adversary TTPs, and common attack methodologies.
  • Ability to analyze technical indicators like domains, IPs, hashes, URLs, processes, and network activity.
  • Ability to communicate complex threats to technical and executive audiences.
  • Strong analytical, research, documentation, and critical-thinking skills.

Responsibilities

  • Monitor and analyze cyber threat intelligence from multiple sources.
  • Identify emerging threat actors, campaigns, vulnerabilities, TTPs.
  • Develop intelligence assessments covering strategic, operational, and tactical threats.
  • Maintain threat actor profiles, indicators of compromise (IOCs), TTPs, and intelligence requirements.
  • Analyze threats using MITRE ATT&CK and the Cyber Kill Chain.
  • Produce executive‑level intelligence reports, technical threat reports, alerts, and briefings.
  • Evaluate the credibility, relevance, and confidence level of intelligence before dissemination.
  • Track threats targeting the organization's industry, technology stack, supply chain, and critical business operations.
  • Analyze endpoint, network, identity, cloud, email, and security telemetry to validate threat intelligence.
  • Use SIEM/XDR platforms to investigate IOCs, suspicious activity, and threat actor behaviors.
  • Perform threat hunting based on intelligence‑derived hypotheses and known adversary TTPs.
  • Develop and execute searches using technologies such as KQL, XQL, SPL, or similar query languages.
  • Analyze IP addresses, domains, URLs, file hashes, certificates, processes, command lines, and other technical indicators.
  • Understand common Windows, Linux, network, Active Directory/Entra ID, cloud, and endpoint attack techniques.
  • Work with SOC and security engineering teams to translate intelligence into actionable detections and security controls.
  • Assist with developing detection logic, watchlists, blocklists, threat‑hunting queries, and alerting rules.
  • Monitor emerging vulnerabilities, zero‑day vulnerabilities, exploitation activity, and threat actor targeting.
  • Correlate vulnerability intelligence with the organization's technology and asset inventory.
  • Assist vulnerability management teams with risk‑based vulnerability prioritization based on active exploitation, threat intelligence, asset criticality, and business impact.
  • Monitor sources such as CISA KEV, vendor advisories, security researchers, and commercial intelligence providers.
  • Evaluate whether newly disclosed vulnerabilities represent an immediate threat to the organization.
  • Provide threat intelligence support during cybersecurity incidents.
  • Research suspected threat actors, malware, infrastructure, and attack techniques during active investigations.
  • Enrich security alerts and incidents with relevant threat intelligence.
  • Identify related infrastructure, IOCs, TTPs, and historical activity.
  • Support incident scoping and attribution where appropriate.
  • Document intelligence findings and provide recommendations to incident commanders and security leadership.
  • Maintain and improve threat intelligence platforms, feeds, integrations, and intelligence repositories.
  • Evaluate intelligence feeds for accuracy, duplication, relevance, and operational value.
  • Integrate threat intelligence with SIEM, XDR, SOAR, EDR, vulnerability management, and other security platforms.
  • Support automation of IOC ingestion, enrichment, correlation, and response workflows.
  • Continuously improve the organization's intelligence collection requirements and processes.

Skills

Threat intelligence
Threat analysis
Incident response
Communication with leadership
Analytical thinking
Cross‑functional collaboration

Education

Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Intelligence Studies, or related discipline, or equivalent professional experience

Tools

SIEM/XDR platforms
EDR technologies
Vulnerability management platforms
KQL
Python/PowerShell

Job description

AV is seeking a Cyber Threat Intelligence Analyst to identify, analyze, and communicate cyber threats impacting the organization. The role blends traditional threat intelligence with hands-on cybersecurity to translate intelligence into detections, investigations, and defensive improvements.

The ideal candidate understands threat actors and geopolitical or industry threats while possessing hands-on familiarity with security technologies, telemetry, SIEM/XDR, and common attacker techniques.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cyber Threat Intelligence Analyst
Senior Cyber Threat Intelligence Analyst

AV • Maryland

On-site
USD 75,000 - 114,000
Medical, dental, vision
401K with company matching
9/80 work schedule
+1
Senior Cyber Threat Intelligence Analyst
Senior Cyber Threat Intelligence Analyst

AV • Town of Florida (NY)

On-site
USD 75,000 - 114,000
Medical, dental, vision
401K with company matching
9/80 work schedule
+1
Senior Cyber Threat Intelligence Analyst
Senior Cyber Threat Intelligence Analyst

AV • Dayton (OH)

On-site
USD 75,000 - 114,000
Medical, dental, vision
401K with company match
9/80 work schedule
+1
Senior Cyber Threat Intelligence Analyst
Senior Cyber Threat Intelligence Analyst

AV • Herndon (VA)

On-site
USD 75,000 - 114,000
Medical benefits
Dental benefits
Vision benefits
+3
Senior Cyber Threat Intelligence Analyst
Senior Cyber Threat Intelligence Analyst

AV • Germantown (MD)

On-site
USD 75,000 - 114,000
Medical, dental, vision
401K with company matching
9/80 work schedule
+1
Senior Cyber Threat Hunter III — TS/SCI DoD IC Expert
Senior Cyber Threat Hunter III — TS/SCI DoD IC Expert

Invictus International Consulting, LLC. • Alexandria (VA)

On-site
USD 120,000 - 180,000
Equal Opportunity Employer
Senior Threat Hunter – Advanced Cyber Defense (TS/SCI)
Senior Threat Hunter – Advanced Cyber Defense (TS/SCI)

Invictus International • Colorado Springs (CO)

On-site
USD 130,000 - 190,000
Senior Cyber Threat Hunter III - Lead Hunts (TS/SCI)
Senior Cyber Threat Hunter III - Lead Hunts (TS/SCI)

Invictus International Consulting, LLC • Colorado Springs (CO)

On-site
USD 158,000 - 193,000
Senior Cyber Threat Hunter & SOC Lead
Senior Cyber Threat Hunter & SOC Lead

Invictus International Consulting, LLC. • Colorado Springs (CO)

On-site
USD 130,000 - 190,000
Senior Threat Hunter — TS/SCI | Advanced Cyber Defense Lead
Senior Threat Hunter — TS/SCI | Advanced Cyber Defense Lead

Invictus International Consulting, LLC. • Colorado Springs (CO)

On-site
USD 120,000 - 170,000