Threat Intelligence Analyst

Resolve Tech Solutions

Irving (TX)

On-site

USD 120,000 - 180,000

Full time

6 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Resolve Tech Solutions is seeking a Threat Intelligence Analyst to track threat actors, campaigns, and TTPs, turning raw indicators into actionable intelligence for SOC, IR, and leadership. You will translate complex findings into concise guidance and work with detection engineering to augment defenses.

The role requires familiarity with the intelligence cycle, malware/Ioc analysis, and strong communication skills, enabling effective briefings and clear reporting.

Qualifications

  • Bachelor's degree or equivalent experience in a relevant field.
  • Familiarity with MITRE ATT&CK, the intelligence cycle, and structured analytic techniques.
  • Experience analyzing malware behavior, IOCs, and adversary infrastructure at a working level.
  • Familiarity with SIEM, EDR, and threat intelligence platform tooling.
  • Strong written and verbal communication skills, with the ability to translate technical findings for non-technical audiences.
  • Ability to prioritize and manage multiple concurrent intelligence requirements under time pressure.
  • Sound analytic judgment, including the ability to state confidence levels and acknowledge uncertainty in assessments.

Responsibilities

  • Collect and analyze threat intelligence.
  • Monitor OSINT, dark web sources, ISAC/ISAO feeds, and commercial threat feeds.
  • Track threat actor groups, campaigns, malware families, and TTPs mapped to MITRE ATT&CK.
  • Analyze indicators of compromise, malware samples, and adversary infrastructure to assess relevance and risk.
  • Correlate external threat data with internal telemetry, logs, and detections to identify targeting or exposure.
  • Produce and disseminate finished intelligence.
  • Write finished intelligence products, including threat advisories, actor profiles, campaign briefs, and trend reports.
  • Deliver tailored intelligence briefings to SOC analysts, IR, and leadership.
  • Maintain a prioritized threat landscape view specific to industry and tech stack.
  • Track and report on TI program KPIs, such as timeliness and actionability.
  • Support detection, response, and vulnerability prioritization.
  • Translate intelligence into detection logic and hunting hypotheses with detection engineering.
  • Provide threat context during incident response to support scoping and containment.
  • Prioritize vulnerability remediation using exploitation likelihood and active exploitation data.
  • Support red/purple team exercises with current TTPs and actor-based scenarios.
  • Manage intelligence infrastructure and sources.
  • Tune and manage the TIP, including feed integration and IOC lifecycle management.
  • Evaluate, onboard, and manage feeds and vendor relationships.
  • Maintain intelligence collection requirements and refine them over time.
  • Apply structured analytic techniques to reduce bias and improve confidence in assessments.
  • Build relationships with ISACs and agencies for information sharing.
  • Contribute to TI strategy, standards, and playbooks.
  • Train SOC/IR/Vulnerability teams on TI products.
  • Brief leadership on emerging threats and geopolitical developments.

Skills

Threat analysis
MITRE ATT&CK familiarity
Written communication

Education

Bachelor's degree in Cybersecurity, Intelligence Studies, or related field
Industry certifications: GCTI, GCFA, CTIA, CISSP

Tools

SIEM tooling
EDR tooling

Job description

You track, analyze, and report on threat actors, campaigns, and emerging attack techniques relevant to the organization and its industry. You turn raw indicators and open-source, commercial, and internal telemetry into intelligence that Security Operations, Incident Response, Vulnerability Management, and executive stakeholders can act on. You maintain the organization's understanding of its adversaries, attack surface exposure, and threat landscape, and you help prioritize defenses based on likelihood and impact.

Responsibilities
  • Collect and analyze threat intelligence
  • Monitor open-source intelligence (OSINT), closed forums, dark web sources, ISAC/ISAO feeds, and commercial threat feeds for relevant activity
  • Track threat actor groups, campaigns, malware families, and TTPs mapped to MITRE ATT&CK
  • Analyze indicators of compromise (IOCs), malware samples, and adversary infrastructure to assess relevance and risk
  • Correlate external threat data with internal telemetry, logs, and detections to identify targeting or exposure
  • Produce and disseminate finished intelligence
  • Write finished intelligence products, including threat advisories, actor profiles, campaign briefs, and trend reports
  • Deliver tailored intelligence briefings to SOC analysts, incident responders, and executive and board-level stakeholders
  • Maintain a prioritized threat landscape view specific to the organization's industry, geography, and technology stack
  • Track and report on threat intelligence program KPIs, such as report timeliness, actionability, and stakeholder feedback
  • Support detection, response, and vulnerability prioritization
  • Translate intelligence into detection logic, hunting hypotheses, and SIEM/EDR content in partnership with detection engineering
  • Provide threat context during incident response to support scoping, attribution, and containment decisions
  • Prioritize vulnerability remediation using exploitation likelihood, threat actor interest, and active exploitation data
  • Support red team, purple team, and adversary emulation exercises with current TTP and actor-based scenarios
  • Manage intelligence infrastructure and sources
  • Administer and tune the threat intelligence platform (TIP), including feed integration and IOC lifecycle management
  • Evaluate, onboard, and manage commercial and open-source intelligence feeds and vendor relationships
  • Maintain intelligence collection requirements and refine them based on stakeholder needs and changes in the threat landscape
  • Apply structured analytic techniques and the intelligence cycle to reduce bias and improve confidence levels in assessments
  • Build and maintain relationships with industry ISACs, law enforcement, and peer intelligence teams for information sharing
  • Contribute to the organization's threat intelligence strategy, standards, and playbooks
  • Train SOC, IR, and Vulnerability Management teams on how to consume and apply intelligence products
  • Brief leadership on emerging threats, sector-specific risk, and geopolitical developments that may affect the organization
Qualifications
  • Bachelor's degree in Cybersecurity, Computer Science, Intelligence Studies, or related field, or equivalent experience
  • Working knowledge of MITRE ATT&CK, the intelligence cycle, and structured analytic techniques
  • Experience analyzing malware behavior, IOCs, and adversary infrastructure at a working level
  • Familiarity with SIEM, EDR, and threat intelligence platform tooling
  • Strong written and verbal communication skills, with the ability to translate technical findings for non-technical audiences
  • Ability to prioritize and manage multiple concurrent intelligence requirements under time pressure
  • Sound analytic judgment, including the ability to state confidence levels and acknowledge uncertainty in assessments
Required Skills
  • Bachelor’s degree in Cybersecurity, Intelligence Studies, or related field
  • Industry certifications such as GCTI, GCFA, CTIA, or CISSP
Preferred Skills
  • Convenience Retail
  • Fuel Operations
  • Supply Chain
Pay range and compensation package

Expected output: This is a full-time, on-site position based in Irving, TX. Occasional after-hours support may be required.

Equal Opportunity Statement

We are committed to diversity and inclusivity in our hiring practices.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Threat Intelligence Analyst
Threat Intelligence Analyst

Motion Recruitment • Irving (TX)

On-site
USD 90,000 - 150,000
Analyst, Threat Intelligence
Analyst, Threat Intelligence

Altice USA • Norwalk (CT)

On-site
USD 85,000 - 115,000
Sr Cyber Threat Intelligence Analyst
Sr Cyber Threat Intelligence Analyst

PRI Technology • Austin (TX)

On-site
USD 90,000 - 120,000
Cyber Threat Intelligence Analyst
Cyber Threat Intelligence Analyst

Digital Global Connectors • McLean (VA)

Hybrid
USD 120,000 - 170,000
Associate Analyst, Threat Intelligence
Associate Analyst, Threat Intelligence

Altice USA • Norwalk (CT)

On-site
USD 60,000 - 80,000
Cyber Threat Intelligence (CTI) Analyst
Cyber Threat Intelligence (CTI) Analyst

Open Systems Technologies Corporation • Huntsville (AL)

On-site
USD 110,000 - 150,000
PTO 3 weeks
Holiday pay 2 weeks
Medical/dental/vision coverage
+5
Senior Associate, Cyber Threat Intelligence
Senior Associate, Cyber Threat Intelligence

Jobtailor • New York (NY)

On-site
USD 85,000 - 120,000
Cyber Threat Intelligence Analyst
Cyber Threat Intelligence Analyst

Check Point Software Technologies • Dallas (TX)

On-site
USD 65,000 - 90,000
Threat Intelligence Lead
Threat Intelligence Lead

Page Mechanical Group, Inc. • Camp Springs (MD)

On-site
USD 150,000 - 165,000
Comprehensive medical plan options
401(k) retirement savings plan with company match
Paid time off and holidays
+1
Threat Intelligence Analyst (Sr., Jr. Multiple Roles)
Threat Intelligence Analyst (Sr., Jr. Multiple Roles)

Fabergent • Herndon (VA)

On-site
USD 110,000 - 140,000