Join our eliteApplied Cyber Threat Research (ACTR)team within theCybersecurity Intelligence Groupand be at the forefront of innovative security strategies. In this dynamic role, you'll harness cutting-edge technology and intelligence to protect our digital landscape, making a real-world impact on global cybersecurity. Your expertise will shape the future of secure operations, safeguarding critical assets and fortifying our cyber defenses.
As aCybersecurity Intelligence Senior AssociateinCybersecurity & Technology Controls, you will be an integral member of the team that safeguards the firm's digital assets and infrastructure from cyber threats. Utilizing your extensive knowledge of cybersecurity, you will proactively identify and assess global and industry-specific attack vectors, emerging trends, and potential risks. You will fuse intelligence from multiple sources, map adversary behavior to the MITRE ATT&CK framework to expose control gaps, and produce finished intelligence assessments for stakeholders across the enterprise — applying AI-assisted approaches and automation to scale the work.
Your expertise in threat assessment, intelligence analysis, and security research is vital for providing insights and recommendations to enhance the firm's security posture and protect its clients. By collaborating with cross-functional teams and deeply analyzing the threat landscape, your insights will inform and shape JPMorganChase's cybersecurity strategy.
Job Responsibilities
- Conducts all-source analysis — fusing multiple intelligence and data sources (e.g., threat reporting, OSINT, technical telemetry, incident data, and vendor intelligence) into a coherent, corroborated intelligence picture and narrative.
- Builds and visualizes attack flows using the MITRE ATT&CK framework — mapping adversary TTPs to security controls and attack surface, highlighting control gaps, and framing findings and priorities against the current threat landscape.
- Develops finished intelligence assessments for a range of stakeholders at the tactical, operational, and strategic levels — spanning specific technologies and applications as well as new business contexts such as mergers and acquisitions targets and unfamiliar industries — to identify vulnerabilities, characterize relevant threats and adversary interest, and inform strategies to mitigate cyber risk across the organization and its systems.
- Conducts open-source collection across the surface, deep, and dark web and social media platforms, then reviews, corroborates, and validates collected data for reliability and analytic value before use.
- Proactively monitors and analyzes global cyber threats and performs in-depth research that supports broader cyber operations objectives (e.g., Threat Hunting, Red Team, Purple Team).
- Designs and improves tools and automations using reuse-first, AI-assisted approaches to accelerate intelligence collection and triage workflows.
- Uses enterprise-authorized AI capabilities to accelerate threat research synthesis and threat assessment, grounding outputs in evidence and validating results before use.
Required qualifications, capabilities, and skills
- 4+ years of experience in cyber intelligence, threat assessment, or security research, focusing on cyber threat research and analysis.
- Ability to operationalize MITRE ATT&CK — converting adversary TTPs into attack flows, mapping techniques to controls and attack surface, and framing gaps and priorities against the current threat landscape.
- Proficiency with open-source intelligence (OSINT) collection across diverse sources — including the surface, deep, and dark web as well as social media platforms — and the ability to review, corroborate, and validate collected data for reliability and analytic value before use.
- Practical experience with modern integrated development environments (e.g., VS Code) and AI-assisted / agentic coding tools (e.g., Claude Code, GitHub Copilot) to accelerate the rapid prototyping, building, and testing of tools and automations — paired with the judgment to validate and review AI-generated outputs before use.
Preferred qualifications, capabilities, and skills
- Proficiency in scripting languages (Python, Bash, JavaScript, PowerShell) with experience in automating threat detection, analysis, and response.
- Experience within the Intelligence Community, Defense Intelligence Enterprise, or the broader Military Intelligence community, U.S. Government agencies, and interagency partners (e.g., DHS, DoD, DOJ, and other federal/interagency organizations) — bringing insight into adversary operations, intelligence tradecraft, and state-sponsored threats.
- Understanding of and ability to action the intelligence lifecycle.
- Experience with SIEM/EDR tools, log analysis, and network traffic analysis to detect and investigate malicious or anomalous activity.
#CTC