IT Operations & Security

Threat Intelligence Analyst

SOC 15-1212.00 · ESCO 2519 · OSCA 271133

REA INV ART SOC ENT CON This role See your match →

Role snapshot

Overview

Researches and tracks cyber threat actors, their tools, and their tactics to help organisations prepare for attacks before they happen. Threat Intelligence Analysts collect, process, and analyse information about current and emerging cyber threats to produce actionable briefings and reports. These insights enable security teams to prioritise defences, detect indicators of compromise, and respond effectively to emerging risks and vulnerabilities.

Protects organisations from cyberattacks by proactively identifying, analysing, and communicating threats. This role enables informed decision-making for security investments and incident response, significantly reducing an organisation's attack surface and potential for financial and reputational damage.

On the job

  • Monitor open-source intelligence (OSINT) and commercial threat feeds for new threats and vulnerabilities
  • Analyse malware, phishing campaigns, and attack patterns to understand adversary tactics, techniques, and procedures (TTPs)
  • Produce detailed threat intelligence reports, briefings, and alerts for various audiences, from technical teams to executive leadership
  • Develop and refine indicators of compromise (IOCs) and rules for security tools to detect malicious activity
  • Collaborate with incident response, security operations, and engineering teams to integrate threat intelligence into defensive strategies
Threat Intelligence Analyst at work

Tools & technology

Threat Intelligence Platforms (TIPs)SIEM (Splunk, QRadar, Sentinel)Malware Analysis Tools (IDA Pro, Ghidra)OSINT Tools (Maltego, Shodan)Packet Analyzers (Wireshark)

Average salary

$110K
MEDIAN SALARY Annual · USD
$85K Bottom 10%
$145K Top 10%

Job outlook

Growing

Job growth is expected to be above average over the next five years.

Education & training

A bachelor's degree in cybersecurity, computer science, or a related field is typically required. Relevant certifications (e.g., CompTIA CySA+, GIAC GCTI) are highly valued.

AI impact outlook

While AI can process vast threat intelligence data and identify patterns, human analysts are essential for contextualizing threats, understanding adversary intent, and communicating strategic risks effectively.

Note — this is our current view. AI is moving fast, so we revisit these ratings.

Show how this was assessed Hide the detail

Why this role received this rating

Core task exposure

high

How much of the role’s important work could AI perform?

Monitoring vast threat feeds, initial data correlation, and generating basic indicators of compromise can be significantly automated by AI.

End-to-end automation

moderate

Can AI complete the work without substantial human involvement?

While AI can process and link threat data, the synthesis of insights into actionable strategic advice and communication to diverse audiences requires human judgment.

Adoption pressure

high

How likely are employers to introduce AI into this work?

The critical and fast-evolving nature of cybersecurity threats, coupled with a talent shortage, drives high adoption pressure for AI augmentation.

Human dependence

moderate

How much does success depend on human judgement, relationships and accountability?

Success requires critical thinking, understanding adversary psychology, assessing strategic risk, and effective communication of complex threats to leadership.

Protective — a higher rating lowers the overall score.

Role adaptability

low

How easily can the role evolve as AI takes on more tasks?

The role is inherently dynamic, requiring continuous learning and adaptation to new threat landscapes, tools, and analytical methods.

Shown for context — not part of the score.

What AI may take on

These are the parts of the role most likely to be automated or significantly accelerated.

  • Automated monitoring and aggregation of open-source and commercial threat feeds
  • Initial correlation of threat data to identify potential connections
  • Generating basic indicators of compromise (IOCs) from raw data
  • Drafting initial summaries of known threat actor tactics, techniques, and procedures (TTPs)
  • Vulnerability scanning and preliminary risk assessment

Where people remain essential

These parts continue to depend heavily on human judgement, relationships and accountability.

  • Synthesizing fragmented information into comprehensive, actionable intelligence
  • Understanding the motivations and strategic intent of cyber adversaries
  • Translating technical threat data into strategic implications for executive leadership
  • Collaborating with incident response and security operations teams on defensive strategies
  • Developing and refining advanced detection rules based on evolving threats
  • Assessing the geopolitical and economic context of cyber threats

How the role may evolve

Sifting data by AI. Synthesizing insights and strategy by human.

AI will handle the heavy lifting of data collection and initial pattern recognition, allowing analysts to focus on deeper strategic analysis and human-centric intelligence communication.

Strengthen your future fit

  • Advanced analytical and critical thinking for complex threat assessment
  • Proficiency in using AI-powered threat intelligence platforms
  • Strong communication and presentation skills for diverse audiences
  • Understanding of geopolitical and cyber-economic contexts
  • Expertise in adversary TTPs and counter-intelligence strategies
Assessment horizon
3–7 years
Confidence
High
Last reviewed
August 2026
Methodology
v1.0

This assessment reflects current AI capabilities and expected adoption patterns. Actual impacts will vary by industry, employer and the way each role is performed.

Career pathways

WHERE YOU COULD GO

Senior Threat Intelligence Analyst
Threat Intelligence Lead

CURRENT ROLE

Threat Intelligence Analyst

IT Operations & Security

ADJACENT MOVES

Cybersecurity Architect
Incident Response Analyst
Security Operations Center Analyst
Junior Cybersecurity Analyst
Network Security Specialist

STARTING POINTS

Who thrives here

Interest profile

C

conventional · CIR

Individuals who thrive on systematic analysis, meticulous research, and the practical application of technical knowledge to solve complex problems are well-suited for this role.

Personality characteristics

Analytical

Possesses a strong desire to explore complex data, uncover patterns, and understand the root causes of cyber threats.

Meticulous

Exhibits a high degree of conscientiousness, ensuring accuracy and thoroughness in threat research and report generation.

Independent

Comfortable working autonomously on detailed research and analysis, often preferring focused individual work.

Objective

Approaches information with a critical and unbiased perspective, prioritising facts and evidence in threat assessments.

Calm under pressure

Maintains composure and clear thinking when dealing with critical and rapidly evolving cyber threats.

Best for

  • Individuals who enjoy detective work, piecing together clues to understand and predict adversary actions.
  • Professionals who are detail-oriented, systematic, and committed to producing high-quality, actionable intelligence.
  • Those who are passionate about cybersecurity and eager to protect organisations from sophisticated digital threats.

Watch out for

  • The work can be highly technical and requires continuous self-education to stay ahead of evolving threats.
  • While collaborative, much of the core analysis is independent, which may not suit those who prefer constant team interaction.
  • Occasional weekend work may be required during critical incident response or urgent threat analysis.

A week in the life

A representative working week for a Threat Intelligence Analyst — where the deep work, meetings, and admin actually land.

8am9am10am11am12pm1pm2pm3pm4pm5pm6pm
Mon
Daily Threat Briefing Standup
OSINT Monitoring & Initial Triage
Deep Dive - Analysing a New Threat Campaign
Tue
Vulnerability Intelligence Review
Collaboration with SOC Team on IOCs
Drafting Threat Report - Executive Summary
Wed
Threat Intelligence Platform (TIP) Management
Researching Emerging Attack Vectors
Peer Review of Threat Report
Refining Report Based on Feedback
Thu
Attending Industry Threat Briefing (Webinar)
Malware Sample Analysis
Developing Custom Detection Rules
Fri
Weekly Planning and Prioritisation
Knowledge Sharing Session with Security Engineering
Ad-hoc Research / Self-paced Learning
Deep work Meeting External Social Admin

Real people. Real results.

Thousands of people
can't be wrong.

4.88
★★★★★
Rating
Image-based assessment that doesn't drain your energy
Science-backed — Big Five + RIASEC research models
A report that tells you why — not just which box you fit in
Start free assessment

Frequently asked questions about Threat Intelligence Analyst roles

What does a Threat Intelligence Analyst do?

A Threat Intelligence Analyst researches and tracks cyber threat actors, their tools, and their tactics to help organisations prepare for attacks before they happen. Threat Intelligence Analysts collect, process, and analyse information about current and emerging cyber threats to produce actionable briefings and reports. These insights enable security teams to prioritise defences, detect indicators of compromise, and respond effectively to emerging risks and vulnerabilities. Protects organisations from cyberattacks by proactively identifying, analysing, and communicating threats. This role enables informed decision-making for security investments and incident response, significantly reducing an organisation's attack surface and potential for financial and reputational damage.

How much does a Threat Intelligence Analyst earn?

A Threat Intelligence Analyst earns a median of $110,000 per year in the US, typically ranging from $85,000 to $145,000.

What qualifications do you need to become a Threat Intelligence Analyst?

To become a Threat Intelligence Analyst, a bachelor's degree in cybersecurity, computer science, or a related field is typically required. Relevant certifications (e.g., CompTIA CySA+, GIAC GCTI) are highly valued.

What personality suits a Threat Intelligence Analyst?

Threat Intelligence Analyst roles tend to suit people who are highly conscientious — precise, organised and strong on follow-through (Conscientiousness 82/100) and open and curious — drawn to variety, ideas and new approaches (Openness 70/100). The traits that matter most in the role are Analytical, Meticulous, Independent and Objective. Possesses a strong desire to explore complex data, uncover patterns, and understand the root causes of cyber threats. On interests, Threat Intelligence Analyst maps to a CIR Holland Code profile — individuals who thrive on systematic analysis, meticulous research, and the practical application of technical knowledge to solve complex problems are well-suited for this role.

Who does a Threat Intelligence Analyst role suit?

A Threat Intelligence Analyst role is usually a strong fit for these reasons. A strong Investigative affinity means you'll enjoy deep research into threat actors and their methods. The role's Conventional nature rewards systematic processes, detailed analysis, and structured reporting. A significant portion of the week involves focused deep work, ideal for those who thrive on complex problem-solving.

What are the downsides of being a Threat Intelligence Analyst?

Threat Intelligence Analyst roles come with trade-offs worth weighing up. The work can be highly technical and requires continuous self-education to stay ahead of evolving threats. While collaborative, much of the core analysis is independent, which may not suit those who prefer constant team interaction. Occasional weekend work may be required during critical incident response or urgent threat analysis.

What is the work environment like for a Threat Intelligence Analyst?

Work as a Threat Intelligence Analyst is mostly office-based with hybrid arrangements common, semi-structured — a mix of set processes and self-directed work, a moderate pace and high exposure to clients or stakeholders. Around 58% of the week is focused deep work.

What skills do you need to be a Threat Intelligence Analyst?

Core skills for a Threat Intelligence Analyst include Threat analysis and research, Cybersecurity principles, Data analysis and correlation, Report writing and communication and Malware analysis.

How do you become a Threat Intelligence Analyst?

Common entry routes into Threat Intelligence Analyst roles include Security Operations Center Analyst, Junior Cybersecurity Analyst and Network Security Specialist.

What career progression is there for a Threat Intelligence Analyst?

From a Threat Intelligence Analyst role, common next steps include Senior Threat Intelligence Analyst and Threat Intelligence Lead; lateral moves include Cybersecurity Architect and Incident Response Analyst.

What is the job outlook for Threat Intelligence Analyst roles?

The outlook for Threat Intelligence Analyst roles is currently rated growing. Job growth is expected to be above average over the next five years.

Will AI replace Threat Intelligence Analyst roles?

Traitstack rates automation risk for Threat Intelligence Analyst roles at 66 out of 100, which is strong. While AI can process vast threat intelligence data and identify patterns, human analysts are essential for contextualizing threats, understanding adversary intent, and communicating strategic risks effectively. AI is most likely to take on automated monitoring and aggregation of open-source and commercial threat feeds, initial correlation of threat data to identify potential connections and generating basic indicators of compromise (iocs) from raw data. Synthesizing fragmented information into comprehensive, actionable intelligence, understanding the motivations and strategic intent of cyber adversaries and translating technical threat data into strategic implications for executive leadership stay with people. Sifting data by AI. Synthesizing insights and strategy by human. That score measures how much of the work could change, not the likelihood the job disappears. It is Traitstack's current view, revisited as AI capability moves.