Senior Cyber Intelligence Analyst

State Employees' Credit Union

United States

On-site

USD 140,000 - 190,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

State Employees' Credit Union seeks a Senior Cyber Intelligence Analyst to own intelligence-driven detection and exposure management. You will set the bar for Splunk work, mentor analysts, and brief leadership with defensible analytic calls.

You will lead threat hunting, vulnerability prioritization, and CTEM efforts while coordinating with CISO leadership and industry partners to strengthen detections and risk assessments.

Qualifications

  • 7+ years in cybersecurity with at least 4 years in threat intelligence, detection engineering, or threat hunting.
  • Expert hands-on Splunk skills: SPL, Splunk Enterprise Security, correlation searches, CIM, and search optimization.
  • Experience building detection programs or coverage strategies, not just individual detections.
  • Deep knowledge of MITRE ATT&CK, structured analytic techniques, and analytic standards.
  • Ability translating attacker tradecraft into telemetry and search logic.
  • Strong briefing and executive-facing communication skills.
  • Demonstrated mentoring ability to raise the technical bar for a team.

Responsibilities

  • Lead threat intelligence and analysis.
  • Own the intelligence requirements process and evaluation of feeds.
  • Lead analysis of threat actors, campaigns, malware families, and TTPs mapped to MITRE ATT&CK.
  • Produce decision-ready intelligence products for tactical, operational, and strategic levels.
  • Own vulnerability prioritization and emergency remediation decisions.
  • Lead intelligence support to incident response and post-incident lessons.
  • Represent the organization in industry sharing communities and with vendor/government contacts.
  • Lead detection engineering program in Splunk Enterprise Security with standards and tuning.

Skills

Splunk
SPL
Splunk ES
MITRE ATT&CK
Threat intelligence
Threat hunting
Detection engineering
Python scripting
Vulnerability management
Incident response

Tools

Tenable
SentinelOne
GitHub Advanced Security
Zscaler
Proofpoint
CI/CD tooling

Job description

If you are motivated and believe in the credit union philosophy of "People Helping People," join our team!

About the role

The Senior Cyber Intelligence Analyst is the technical lead for intelligence-driven detection and exposure management. You own the analytic tradecraft, the detection engineering standards, and the intelligence products that shape how the organization prioritizes vulnerabilities, builds detections, and briefs leadership. You set the bar for the team's Splunk work, mentor analysts, and represent threat intelligence to peer teams and executives. This is a senior individual-contributor role with real ownership. You are expected to define how the work gets done, not just do it, and to make defensible analytic calls that leadership will act on.

What you will do
  • Lead threat intelligence and analysis
  • Own the intelligence requirements process: define priority intelligence requirements with stakeholders, maintain the collection plan, and evaluate feed and vendor value.
  • Lead analysis of threat actors, campaigns, malware families, and TTPs relevant to financial services, our technology stack, and our third‑party ecosystem, mapped to MITRE ATT&CK.
  • Produce and quality‑review decision‑ready intelligence products at the tactical, operational, and strategic levels, including briefings for the CISO and contributions to governance and Board‑level reporting.
  • Own the threat‑informed assessment of newly disclosed vulnerabilities (CISA KEV, EPSS, exploit availability, vendor advisories) and drive that assessment into vulnerability prioritization and emergency remediation decisions.
  • Lead intelligence support to incident response: attribution, campaign context, indicator enrichment, and post‑incident lessons that become detections and requirements.
  • Represent the organization in industry sharing communities (FS‑ISAC and peer groups) and build relationships with vendor and government intelligence contacts.
  • Lead detection engineering Own the detection engineering program in Splunk Enterprise Security: standards, lifecycle, coverage measurement, and the tuning process.
  • Design and build high‑value detections, correlation searches, and risk‑based alerting (RBA) logic; review and mentor others' detection work.
  • Maintain the MITRE ATT&CK coverage map, prioritize gaps against current threat intelligence and crown‑jewel assets, and drive a roadmap to close them.
  • Establish detection‑as‑code practices: version control, peer review, testing against replayed or emulated attack data, and controlled deployment.
  • Lead purple‑team and adversary emulation exercises to validate detections and measure real coverage rather than assumed coverage.
  • Set standards for SPL quality, data model use, CIM compliance, and search performance; partner with the Splunk platform team on data onboarding and platform direction.
  • Lead threat hunting and exposure management Design and run the threat hunting program: hunt hypotheses tied to priority intelligence requirements, documented methodology, and outcomes that feed detections and remediation.
  • Lead cross‑source analysis correlating vulnerability data (Tenable) with endpoint (SentinelOne), source control (GitHub), network and edge (F5, Check Point, Zscaler), and email (Proofpoint) telemetry to identify exposed, exploitable, and actively targeted assets.
  • Serve as the threat intelligence lead for the continuous threat exposure management (CTEM) program, ensuring exposure prioritization reflects real adversary behavior and business impact.
  • Provide threat research and detection strategy for emerging programs in AI security, software supply chain and third‑party risk, and application security.
  • Mentor, influence, and report Mentor and technically guide analysts on the team; review analytic products and detections for rigor and clarity.
  • Own the team's Splunk dashboards and scheduled reporting for intelligence metrics, detection coverage, hunt outcomes, and threat‑informed vulnerability metrics that roll up to leadership reporting.
  • Influence remediation and control decisions across IT operations, application owners, and engineering by presenting evidence‑based risk assessments.
  • Brief executives and governance audiences clearly and credibly, including confidence levels and dissenting assessments.
What you bring
Required
  • 7+ years in cybersecurity with at least 4 years in threat intelligence, detection engineering, or threat hunting, including experience leading work streams or projects.
  • Expert hands‑on Splunk skills: advanced SPL, Splunk Enterprise Security, correlation searches, risk‑based alerting, data models, CIM, and search optimization.
  • A track record of building detection programs or coverage strategies, not just individual detections, and measuring their effectiveness.
  • Deep working knowledge of MITRE ATT&CK, structured analytic techniques, and intelligence product standards (confidence language, sourcing, analytic rigor).
  • Strong understanding of attacker tradecraft across endpoint, network, identity, cloud, and email, with the ability to translate it into telemetry and search logic.
  • Experience integrating threat intelligence into vulnerability prioritization using CVSS, VPR, EPSS, CISA KEV, and exploit intelligence.
  • Excellent analytic writing and briefing skills; comfortable presenting to executives and defending assessments under scrutiny.
  • Demonstrated ability to mentor and raise the technical bar for a team.
Preferred
  • Experience in financial services or another regulated environment, with familiarity in FFIEC, NIST CSF, CIS Controls, and PCI DSS expectations for threat intelligence and monitoring.
  • Experience with Tenable, SentinelOne, GitHub Advanced Security, Zscaler, Proofpoint, or comparable platforms.
  • Python for enrichment, automation, and data analysis; experience with security APIs and STIX/TAXII; experience operating a threat intelligence platform (TIP).
  • Experience with detection‑as‑code tooling and CI/CD for detections.
  • Hands‑on experience with CTEM or exposure management platforms.
  • Experience running purple‑team or adversary emulation programs.
  • Certifications such as GCTI, GCDA, GCFA, GREM, Splunk Enterprise Security Certified Admin, or CISSP.
  • Research or practical experience in AI/ML security, software supply chain security, or application security.

SECU provides equal employment opportunity to all qualified persons regardless of race, color, religion, age, sex, sexual orientation, gender identity, national origin, genetic information, disability, veteran status, or other classification protected by law.

Disclaimer State Employees' Credit Union reserves the right to fill this role at a higher/lower level based on business need.

State Employees' Credit Union is a not‑for‑profit, member‑owned financial cooperative with a "Do the Right Thing" mission and a goal of helping people in our community.

SECU values the differences in our staff and in our North Carolina communities. We believe that embracing the uniqueness of individuals makes our cooperative stronger, more innovative and better able to serve SECU members.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Intelligence Analyst
Cyber Intelligence Analyst

SECU • United States

On-site
USD 120,000 - 180,000
Senior Cyber Intelligence Analyst
Senior Cyber Intelligence Analyst

State Employees' Credit Union • Raleigh (NC)

Hybrid
USD 150,000 - 190,000
Cyber Intelligence Analyst
Cyber Intelligence Analyst

State Employees' Credit Union • Raleigh (NC), Northern (KY)

On-site
USD 90,000 - 130,000
Lead Cyber Threat Intelligence & Detection Architect
Lead Cyber Threat Intelligence & Detection Architect

State Employees' Credit Union • United States

On-site
USD 140,000 - 190,000
SVP - Cyber Security Ops Center & Assurance
SVP - Cyber Security Ops Center & Assurance

SECU • United States

On-site
USD 150,000 - 200,000
Security Engineer II - Data Protection
Security Engineer II - Data Protection

SECU • North Carolina

On-site
USD 90,000 - 120,000
VP Cyber Security Incident Detection & Response
VP Cyber Security Incident Detection & Response

SECU • United States

On-site
USD 120,000 - 150,000
Hybrid work environment
Equal opportunity employer
Senior Cyber Intelligence & Detection Lead
Senior Cyber Intelligence & Detection Lead

State Employees' Credit Union • Raleigh (NC)

Hybrid
USD 150,000 - 190,000
Threat Intelligence & Detection Engineer
Threat Intelligence & Detection Engineer

State Employees' Credit Union • Raleigh (NC), Northern (KY)

Hybrid
USD 90,000 - 130,000
Principal Splunk-Threat Detection & Integration Engineer
Principal Splunk-Threat Detection & Integration Engineer

Quzara LLC • United States

On-site
USD 120,000 - 160,000