Threat Intelligence Analyst
SOC 15-1212.00 · ESCO 2519 · OSCA 271133
Role snapshot
Overview
Researches and tracks cyber threat actors, their tools, and their tactics to help organisations prepare for attacks before they happen. Threat Intelligence Analysts collect, process, and analyse information about current and emerging cyber threats to produce actionable briefings and reports. These insights enable security teams to prioritise defences, detect indicators of compromise, and respond effectively to emerging risks and vulnerabilities.
Protects organisations from cyberattacks by proactively identifying, analysing, and communicating threats. This role enables informed decision-making for security investments and incident response, significantly reducing an organisation's attack surface and potential for financial and reputational damage.
On the job
- Monitor open-source intelligence (OSINT) and commercial threat feeds for new threats and vulnerabilities
- Analyse malware, phishing campaigns, and attack patterns to understand adversary tactics, techniques, and procedures (TTPs)
- Produce detailed threat intelligence reports, briefings, and alerts for various audiences, from technical teams to executive leadership
- Develop and refine indicators of compromise (IOCs) and rules for security tools to detect malicious activity
- Collaborate with incident response, security operations, and engineering teams to integrate threat intelligence into defensive strategies
Tools & technology
Average salary
Job outlook
GrowingJob growth is expected to be above average over the next five years.
Education & training
A bachelor's degree in cybersecurity, computer science, or a related field is typically required. Relevant certifications (e.g., CompTIA CySA+, GIAC GCTI) are highly valued.
AI impact outlook
Note — this is our current view. AI is moving fast, so we revisit these ratings.
Show how this was assessed Hide the detail
Note — this is our current view. AI is moving fast, so we revisit these ratings.
Show how this was assessed Hide the detailWhy this role received this rating
Core task exposure
high
How much of the role’s important work could AI perform?
Monitoring vast threat feeds, initial data correlation, and generating basic indicators of compromise can be significantly automated by AI.
End-to-end automation
moderate
Can AI complete the work without substantial human involvement?
While AI can process and link threat data, the synthesis of insights into actionable strategic advice and communication to diverse audiences requires human judgment.
Adoption pressure
high
How likely are employers to introduce AI into this work?
The critical and fast-evolving nature of cybersecurity threats, coupled with a talent shortage, drives high adoption pressure for AI augmentation.
Human dependence
moderate
How much does success depend on human judgement, relationships and accountability?
Success requires critical thinking, understanding adversary psychology, assessing strategic risk, and effective communication of complex threats to leadership.
Protective — a higher rating lowers the overall score.
Role adaptability
low
How easily can the role evolve as AI takes on more tasks?
The role is inherently dynamic, requiring continuous learning and adaptation to new threat landscapes, tools, and analytical methods.
Shown for context — not part of the score.
What AI may take on
These are the parts of the role most likely to be automated or significantly accelerated.
- Automated monitoring and aggregation of open-source and commercial threat feeds
- Initial correlation of threat data to identify potential connections
- Generating basic indicators of compromise (IOCs) from raw data
- Drafting initial summaries of known threat actor tactics, techniques, and procedures (TTPs)
- Vulnerability scanning and preliminary risk assessment
Where people remain essential
These parts continue to depend heavily on human judgement, relationships and accountability.
- Synthesizing fragmented information into comprehensive, actionable intelligence
- Understanding the motivations and strategic intent of cyber adversaries
- Translating technical threat data into strategic implications for executive leadership
- Collaborating with incident response and security operations teams on defensive strategies
- Developing and refining advanced detection rules based on evolving threats
- Assessing the geopolitical and economic context of cyber threats
How the role may evolve
Sifting data by AI. Synthesizing insights and strategy by human.
AI will handle the heavy lifting of data collection and initial pattern recognition, allowing analysts to focus on deeper strategic analysis and human-centric intelligence communication.
Strengthen your future fit
- Advanced analytical and critical thinking for complex threat assessment
- Proficiency in using AI-powered threat intelligence platforms
- Strong communication and presentation skills for diverse audiences
- Understanding of geopolitical and cyber-economic contexts
- Expertise in adversary TTPs and counter-intelligence strategies
- Assessment horizon
- 3–7 years
- Confidence
- High
- Last reviewed
- August 2026
- Methodology
- v1.0
This assessment reflects current AI capabilities and expected adoption patterns. Actual impacts will vary by industry, employer and the way each role is performed.
Career pathways
WHERE YOU COULD GO
CURRENT ROLE
Threat Intelligence Analyst
IT Operations & Security
ADJACENT MOVES
STARTING POINTS
Who thrives here
Interest profile
conventional · CIR
Individuals who thrive on systematic analysis, meticulous research, and the practical application of technical knowledge to solve complex problems are well-suited for this role.
Personality characteristics
Analytical
Possesses a strong desire to explore complex data, uncover patterns, and understand the root causes of cyber threats.
Meticulous
Exhibits a high degree of conscientiousness, ensuring accuracy and thoroughness in threat research and report generation.
Independent
Comfortable working autonomously on detailed research and analysis, often preferring focused individual work.
Objective
Approaches information with a critical and unbiased perspective, prioritising facts and evidence in threat assessments.
Calm under pressure
Maintains composure and clear thinking when dealing with critical and rapidly evolving cyber threats.
Best for
- Individuals who enjoy detective work, piecing together clues to understand and predict adversary actions.
- Professionals who are detail-oriented, systematic, and committed to producing high-quality, actionable intelligence.
- Those who are passionate about cybersecurity and eager to protect organisations from sophisticated digital threats.
Watch out for
- The work can be highly technical and requires continuous self-education to stay ahead of evolving threats.
- While collaborative, much of the core analysis is independent, which may not suit those who prefer constant team interaction.
- Occasional weekend work may be required during critical incident response or urgent threat analysis.
A week in the life
A representative working week for a Threat Intelligence Analyst — where the deep work, meetings, and admin actually land.
Real people. Real results.
Thousands of people
can't be wrong.
Similar roles
Frequently asked questions about Threat Intelligence Analyst roles
What does a Threat Intelligence Analyst do?
A Threat Intelligence Analyst researches and tracks cyber threat actors, their tools, and their tactics to help organisations prepare for attacks before they happen. Threat Intelligence Analysts collect, process, and analyse information about current and emerging cyber threats to produce actionable briefings and reports. These insights enable security teams to prioritise defences, detect indicators of compromise, and respond effectively to emerging risks and vulnerabilities. Protects organisations from cyberattacks by proactively identifying, analysing, and communicating threats. This role enables informed decision-making for security investments and incident response, significantly reducing an organisation's attack surface and potential for financial and reputational damage.
How much does a Threat Intelligence Analyst earn?
A Threat Intelligence Analyst earns a median of $110,000 per year in the US, typically ranging from $85,000 to $145,000.
What qualifications do you need to become a Threat Intelligence Analyst?
To become a Threat Intelligence Analyst, a bachelor's degree in cybersecurity, computer science, or a related field is typically required. Relevant certifications (e.g., CompTIA CySA+, GIAC GCTI) are highly valued.
What personality suits a Threat Intelligence Analyst?
Threat Intelligence Analyst roles tend to suit people who are highly conscientious — precise, organised and strong on follow-through (Conscientiousness 82/100) and open and curious — drawn to variety, ideas and new approaches (Openness 70/100). The traits that matter most in the role are Analytical, Meticulous, Independent and Objective. Possesses a strong desire to explore complex data, uncover patterns, and understand the root causes of cyber threats. On interests, Threat Intelligence Analyst maps to a CIR Holland Code profile — individuals who thrive on systematic analysis, meticulous research, and the practical application of technical knowledge to solve complex problems are well-suited for this role.
Who does a Threat Intelligence Analyst role suit?
A Threat Intelligence Analyst role is usually a strong fit for these reasons. A strong Investigative affinity means you'll enjoy deep research into threat actors and their methods. The role's Conventional nature rewards systematic processes, detailed analysis, and structured reporting. A significant portion of the week involves focused deep work, ideal for those who thrive on complex problem-solving.
What are the downsides of being a Threat Intelligence Analyst?
Threat Intelligence Analyst roles come with trade-offs worth weighing up. The work can be highly technical and requires continuous self-education to stay ahead of evolving threats. While collaborative, much of the core analysis is independent, which may not suit those who prefer constant team interaction. Occasional weekend work may be required during critical incident response or urgent threat analysis.
What is the work environment like for a Threat Intelligence Analyst?
Work as a Threat Intelligence Analyst is mostly office-based with hybrid arrangements common, semi-structured — a mix of set processes and self-directed work, a moderate pace and high exposure to clients or stakeholders. Around 58% of the week is focused deep work.
What skills do you need to be a Threat Intelligence Analyst?
Core skills for a Threat Intelligence Analyst include Threat analysis and research, Cybersecurity principles, Data analysis and correlation, Report writing and communication and Malware analysis.
How do you become a Threat Intelligence Analyst?
Common entry routes into Threat Intelligence Analyst roles include Security Operations Center Analyst, Junior Cybersecurity Analyst and Network Security Specialist.
What career progression is there for a Threat Intelligence Analyst?
From a Threat Intelligence Analyst role, common next steps include Senior Threat Intelligence Analyst and Threat Intelligence Lead; lateral moves include Cybersecurity Architect and Incident Response Analyst.
What is the job outlook for Threat Intelligence Analyst roles?
The outlook for Threat Intelligence Analyst roles is currently rated growing. Job growth is expected to be above average over the next five years.
Will AI replace Threat Intelligence Analyst roles?
Traitstack rates automation risk for Threat Intelligence Analyst roles at 66 out of 100, which is strong. While AI can process vast threat intelligence data and identify patterns, human analysts are essential for contextualizing threats, understanding adversary intent, and communicating strategic risks effectively. AI is most likely to take on automated monitoring and aggregation of open-source and commercial threat feeds, initial correlation of threat data to identify potential connections and generating basic indicators of compromise (iocs) from raw data. Synthesizing fragmented information into comprehensive, actionable intelligence, understanding the motivations and strategic intent of cyber adversaries and translating technical threat data into strategic implications for executive leadership stay with people. Sifting data by AI. Synthesizing insights and strategy by human. That score measures how much of the work could change, not the likelihood the job disappears. It is Traitstack's current view, revisited as AI capability moves.