Lead Cyber Intelligence Analyst

McKesson

Irving (TX)

Hybrid

USD 140,000 - 185,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

McKesson is seeking a Lead Information Security Analyst to strengthen cyber threat intelligence. You will guide intelligence needs, assess threats, translate findings to business insights, and mentor analysts across SOC, threat hunting, and incident response teams.

You will leverage internal telemetry, open-source intel, and AI-driven approaches to scale production and inform risk-based decisions in a healthcare-focused enterprise.

Qualifications

  • 10+ years of cybersecurity or related experience.
  • Experience developing telemetry-to-intelligence model and reducing third-party reliance.
  • Experience with open-source research tools (VirusTotal, DomainTools, Censys, GreyNoise).

Responsibilities

  • Identify and track emerging threats across McKesson telemetry.
  • Deliver time-sensitive behavioral attack chains to support incident response.
  • Lead attribution and threat actor analysis with incident response teams.
  • Author actor profiles for CIRT, Red Team, Threat Hunt, and Detection Engineering.
  • Leverage AI to guide investigations and automation in intel workflows.
  • Mentor mid-level analysts on tradecraft and production standards.
  • Represent the intelligence function in cross-functional planning with SOC and IR.

Skills

Cybersecurity expertise
Threat intelligence
Open source tools
MITRE ATT&CK
Automation scripting
SIEM/EDR
Telemetry to intelligence
Cross-functional collaboration

Education

Bachelor's degree in Cybersecurity/CS/IS or related field

Tools

VirusTotal
DomainTools
Censys
GreyNoise

Job description

McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being of you and those we serve - we care.

What you do at McKesson matters. We foster a culture where you can grow, make an impact, and are empowered to bring new ideas. Together, we thrive as we shape the future of health for patients, our communities, and our people. If you want to be part of tomorrow's health today, we want to hear from you.

About the Role

McKesson is seeking a highly skilled Lead Information Security Analyst to strengthen our cyber threat intelligence capabilities. This role serves as a senior intelligence leader responsible for identifying, analyzing, and communicating cyber threats that may affect the enterprise, its business operations, and the healthcare sector.

As a lead analyst, you will partner with cybersecurity, technology, risk, legal, and business teams to define intelligence needs, assess emerging threats, translate complex findings into relevant business insights, and guide risk-informed decisions. You will also mentor analysts, strengthen analytic tradecraft, and improve how intelligence is collected, produced, and shared.

What You'll Do
  • Identify and track emerging threats by discovering untracked adversary activity, developing new threat clusters into tracked actor groups across McKesson telemetry
  • Deliver time-sensitive behavioral attack chains supporting active incident response and threat hunting operations to drive cross-team detection and protection actions.
  • Lead attribution and threat actor analysis by collecting, modeling, attributing, and documenting intelligence gathered during investigations. Serve as the primary owner for attribution efforts while partnering with incident response teams.
  • Author actor profiles for the CIRT, Red Team, Threat Hunt, and Detection Engineering-- leveraging internal signals, open-source, vendor research, and sharing community reporting
  • Leverage AI to guide investigations and automation (e.g., intel-to-detection pipelines, infrastructure clustering, cross-actor TTP analysis) to scale production beyond manual analysis
  • Provide technical mentorship to mid-level analysts on tradecraft, source evaluation, and production standards
  • Represent the intelligence function in cross-functional planning with SOC, threat hunting, red team, and incident response
  • Contribute to strategic planning on how internal telemetry investments map to intelligence production goals
Basic Requirements
  • 10+ years of cybersecurity, information security, cyber threat intelligence, threat research, or related experience.
  • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Systems, or related field; equivalent experience will be considered.
  • Experience developing a telemetry-to-intelligence model that reduces reliance on third-party feeds and vendors-shifting teams from intel consumers to intel producers
  • Experience with open source research tools, including Virus Total, Domain Tools, Censys, Grey Noise, and other similar tools.
  • Experience in tactical threat intelligence, specifically identifying IOCs, tools, and behavioral fingerprints left by adversaries across our telemetry (endpoint, network, cloud, and identity)
  • Mine SIEM, EDR, NDR, firewall, DNS, proxy, and cloud logging data to identify adversary tradecraft, infrastructure, and behavioral patterns unique McKesson
  • Experience using MITRE ATT&CK, Cyber Kill Chain, or similar frameworks to structure and communicate threat analysis.
  • Experience with threat intelligence platforms, link analysis, data enrichment, or scripting and automation that support intelligence workflows.
Preferred Skills/Experience
  • Advanced cyber threat intelligence experience using TIPs, commercial reporting, OSINT, information-sharing communities, and dark web intelligence sources.
  • Experience building or maturing a cyber threat intelligence program, operating model, or intelligence lifecycle.
  • Knowledge of intelligence collection management, source validation, confidence assessments, and structured analytic techniques. Experience with design, build, and optimize intelligence systems for structured storage, correlation, and analytics of large-scale threat intelligence data sets.
  • Experience supporting regulatory, audit, compliance, or healthcare security environments.
  • Relevant certifications such as CISSP, GCTI, OSCP, GREM, or equivalent intelligence, cybersecurity, or analytic credentials.
  • Experience coaching technical teams and leading cross-functional security initiatives.
Travel / Work Environment / Physical Requirements
  • May require occasional travel (up to 10%) based on business needs.
  • Hybrid or remote work arrangements may be available based on location and business requirements.
  • Ability to work extended hours during critical security incide
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Cyber Intelligence Analyst
Lead Cyber Intelligence Analyst

Mckesson Corporation • Irving (TX)

Hybrid
USD 152,000 - 253,000
Lead Cyber Intelligence Analyst
Lead Cyber Intelligence Analyst

McKesson’s Corporate • Irving (TX)

Hybrid
USD 152,000 - 253,000
Senior Cyber Threat Intelligence Lead (Remote)
Senior Cyber Threat Intelligence Lead (Remote)

McKesson • Irving (TX)

Hybrid
USD 140,000 - 185,000
Senior Cyber Threat Intelligence Lead
Senior Cyber Threat Intelligence Lead

McKesson’s Corporate • Irving (TX)

Hybrid
USD 152,000 - 253,000
Senior Cyber Threat Intelligence Lead — Hybrid/Remote
Senior Cyber Threat Intelligence Lead — Hybrid/Remote

Mckesson Corporation • Irving (TX)

Hybrid
USD 152,000 - 253,000
Senior Information Security Analyst
Senior Information Security Analyst

McKesson Corporation • Irving (TX)

Remote
USD 170,000 - 179,000
Lead Threat Detection Engineer
Lead Threat Detection Engineer

McKesson’s Corporate • Irving (TX), Winslow Township (NJ)

On-site
USD 139,000 - 232,000
Senior Manager, Network Security Engineering
Senior Manager, Network Security Engineering

McKesson • Irving (TX)

On-site
USD 137,000 - 228,000
Senior Manager, Network Security Engineering
Senior Manager, Network Security Engineering

McKesson Corporation • Irving (TX)

On-site
USD 137,000 - 228,000
Senior Manager, Network Security Engineering
Senior Manager, Network Security Engineering

McKesson Corporation • Town of Texas (WI)

On-site
USD 137,000 - 228,000