Senior Cyber Intelligence Analyst

State Employees' Credit Union

Raleigh (NC)

Hybrid

USD 150,000 - 190,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

State Employees' Credit Union is seeking a Senior Cyber Intelligence Analyst to own threat intelligence, detection engineering, and threat hunting in a financial services context. You will lead analytic tradecraft, establish detection standards, and mentor a team of analysts.

You will oversee MITRE ATT&CK mappings, vulnerability prioritization, and executive-level briefings, collaborating with peers and governance bodies to drive risk-informed decisions.

Qualifications

  • 7+ years in cybersecurity with 4+ years in threat intelligence, detection engineering, or threat hunting; leadership experience.
  • Expert hands-on Splunk skills: SPL, Splunk Enterprise Security, correlation searches, risk-based alerting.
  • Deep knowledge of MITRE ATT&CK, analytic techniques, and intelligence product standards (confidence language, sourcing, analytic rigor).
  • Strong understanding of attacker tradecraft across endpoint, network, identity, cloud, and email, with telemetry/search translation.
  • Experience integrating threat intelligence into vulnerability prioritization using CVSS, VPR, EPSS, CISA KEV, and exploit intelligence.
  • Excellent analytic writing and briefing skills; comfortable presenting to executives and defending assessments.
  • Demonstrated ability to mentor and raise the technical bar for a team.

Responsibilities

  • Lead threat intelligence and analysis; own requirements, campaigns, and MITRE ATT&CK mappings.
  • Lead detection engineering; design high-value detections, risk-based alerting, and SPL standards.
  • Lead threat hunting and exposure management; correlate data across tools to identify exposed assets.
  • Mentor analysts, manage dashboards, and present risk assessments to leadership.
  • Represent the organization in industry groups and coordinate with stakeholders across IT and security.

Skills

Splunk
MITRE ATT&CK
Threat intelligence
Analytic writing
Leadership
Briefings

Education

Bachelor's degree in cybersecurity or related field

Tools

Splunk ES
Tenable
SentinelOne
GitHub
Zscaler
Proofpoint

Job description

## About the roleThe Senior Cyber Intelligence Analyst is the technical lead for intelligence-driven detection and exposure management. You own the analytic tradecraft, the detection engineering standards, and the intelligence products that shape how the organization prioritizes vulnerabilities, builds detections, and briefs leadership. You set the bar for the team's Splunk work, mentor analysts, and represent threat intelligence to peer teams and executives.This is a senior individual-contributor role with real ownership. You are expected to define how the work gets done, not just do it, and to make defensible analytic calls that leadership will act on.## What you will do**Lead threat intelligence and analysis*** Own the intelligence requirements process: define priority intelligence requirements with stakeholders, maintain the collection plan, and evaluate feed and vendor value.* Lead analysis of threat actors, campaigns, malware families, and TTPs relevant to financial services, our technology stack, and our third-party ecosystem, mapped to MITRE ATT&CK.* Produce and quality-review decision-ready intelligence products at the tactical, operational, and strategic levels, including briefings for the CISO and contributions to governance and Board-level reporting.* Own the threat-informed assessment of newly disclosed vulnerabilities (CISA KEV, EPSS, exploit availability, vendor advisories) and drive that assessment into vulnerability prioritization and emergency remediation decisions.* Lead intelligence support to incident response: attribution, campaign context, indicator enrichment, and post-incident lessons that become detections and requirements.* Represent the organization in industry sharing communities (FS-ISAC and peer groups) and build relationships with vendor and government intelligence contacts.**Lead detection engineering*** Own the detection engineering program in Splunk Enterprise Security: standards, lifecycle, coverage measurement, and the tuning process.* Design and build high-value detections, correlation searches, and risk-based alerting (RBA) logic; review and mentor others' detection work.* Maintain the MITRE ATT&CK coverage map, prioritize gaps against current threat intelligence and crown-jewel assets, and drive a roadmap to close them.* Establish detection-as-code practices: version control, peer review, testing against replayed or emulated attack data, and controlled deployment.* Lead purple-team and adversary emulation exercises to validate detections and measure real coverage rather than assumed coverage.* Set standards for SPL quality, data model use, CIM compliance, and search performance; partner with the Splunk platform team on data onboarding and platform direction.**Lead threat hunting and exposure management*** Design and run the threat hunting program: hunt hypotheses tied to priority intelligence requirements, documented methodology, and outcomes that feed detections and remediation.* Lead cross-source analysis correlating vulnerability data (Tenable) with endpoint (SentinelOne), source control (GitHub), network and edge (F5, Check Point, Zscaler), and email (Proofpoint) telemetry to identify exposed, exploitable, and actively targeted assets.* Serve as the threat intelligence lead for the continuous threat exposure management (CTEM) program, ensuring exposure prioritization reflects real adversary behavior and business impact.* Provide threat research and detection strategy for emerging programs in AI security, software supply chain and third-party risk, and application security.**Mentor, influence, and report*** Mentor and technically guide analysts on the team; review analytic products and detections for rigor and clarity.* Own the team's Splunk dashboards and scheduled reporting for intelligence metrics, detection coverage, hunt outcomes, and threat-informed vulnerability metrics that roll up to leadership reporting.* Influence remediation and control decisions across IT operations, application owners, and engineering by presenting evidence-based risk assessments.* Brief executives and governance audiences clearly and credibly, including confidence levels and dissenting assessments.## What you bring**Required*** 7+ years in cybersecurity with at least 4 years in threat intelligence, detection engineering, or threat hunting, including experience leading work streams or projects.* Expert hands-on Splunk skills: advanced SPL, Splunk Enterprise Security, correlation searches, risk-based alerting, data models, CIM, and search optimization.* A track record of building detection programs or coverage strategies, not just individual detections, and measuring their effectiveness.* Deep working knowledge of MITRE ATT&CK, structured analytic techniques, and intelligence product standards (confidence language, sourcing, analytic rigor).* Strong understanding of attacker tradecraft across endpoint, network, identity, cloud, and email, with the ability to translate it into telemetry and search logic.* Experience integrating threat intelligence into vulnerability prioritization using CVSS, VPR, EPSS, CISA KEV, and exploit intelligence.* Excellent analytic writing and briefing skills; comfortable presenting to executives and defending assessments under scrutiny.* Demonstrated ability to mentor and raise the technical bar for a team.**Preferred*** Experience in financial services or another regulated environment, with familiarity in FFIEC, NIST CSF, CIS Controls, and PCI DSS expectations for threat intelligence and monitoring.* Experience with Tenable, SentinelOne, GitHub Advanced Security, Zscaler, Proofpoint, or comparable platforms.* Python for enrichment, automation, and data analysis; experience with security APIs and STIX/TAXII; experience operating a threat intelligence platform (TIP).* Experience with detection-as-code tooling and CI/CD for detections.* Hands-on experience with CTEM or exposure management platforms.* Experience running purple-team or adversary emulation programs.* Certifications such as GCTI, GCDA, GCFA, GREM, Splunk Enterprise Security Certified Admin, or CISSP.* Research or practical experience in AI/ML security, software supply chain security, or application security.SECU provides equal employment opportunity to all qualified persons regardless of race, color, religion, age, sex, sexual orientation, gender identity, national origin, genetic information, disability, veteran status, or other classification protected by law.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Intelligence Analyst
Cyber Intelligence Analyst

State Employees' Credit Union • Raleigh (NC), Northern (KY)

On-site
USD 90,000 - 130,000
Senior Cyber Intelligence Analyst
Senior Cyber Intelligence Analyst

State Employees' Credit Union • United States

On-site
USD 140,000 - 190,000
Cyber Intelligence Analyst
Cyber Intelligence Analyst

SECU • United States

On-site
USD 120,000 - 180,000
Principal Splunk-Threat Detection & Integration Engineer
Principal Splunk-Threat Detection & Integration Engineer

Quzara LLC • United States

On-site
USD 120,000 - 160,000
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Senior Software Engineer, Information Security
Senior Software Engineer, Information Security

COMMURE Incorporated • Mountain View (CA)

On-site
USD 130,000 - 160,000
Senior Threat Hunter
Senior Threat Hunter

SentinelOne • United States

On-site
USD 140,000 - 210,000
Medical cover
Assistance program
Gym reimbursement
+7
Lead Cyber Threat Management Analyst
Lead Cyber Threat Management Analyst

Thomson Reuters Corp. • Richmond (VA)

Hybrid
USD 140,000 - 190,000
Hybrid Work Model
Flex My Way
Grow My Way
Cybersecurity Analyst
Cybersecurity Analyst

EXOS • Indianapolis (IN)

On-site
USD 90,000 - 120,000
Sr. Manager, Threat Engineering
Sr. Manager, Threat Engineering

Tory Burch • Jersey City (NJ)

On-site
USD 110,000 - 160,000
Employee discount
Access to exclusive sales
Free executive coaching
+1