IT Operations & Security

Threat Intelligence Analyst

SOC 15-1212.00 · ESCO 2519 · OSCA 271133

REA INV ART SOC ENT CON This role See your match →

Role snapshot

Overview

Researches and tracks cyber threat actors, their tools, and their tactics to help organisations prepare for attacks before they happen. Threat Intelligence Analysts collect, process, and analyse information about current and emerging cyber threats to produce actionable briefings and reports. These insights enable security teams to prioritise defences, detect indicators of compromise, and respond effectively to emerging risks and vulnerabilities.

Protects organisations from cyberattacks by proactively identifying, analysing, and communicating threats. This role enables informed decision-making for security investments and incident response, significantly reducing an organisation's attack surface and potential for financial and reputational damage.

On the job

  • Monitor open-source intelligence (OSINT) and commercial threat feeds for new threats and vulnerabilities
  • Analyse malware, phishing campaigns, and attack patterns to understand adversary tactics, techniques, and procedures (TTPs)
  • Produce detailed threat intelligence reports, briefings, and alerts for various audiences, from technical teams to executive leadership
  • Develop and refine indicators of compromise (IOCs) and rules for security tools to detect malicious activity
  • Collaborate with incident response, security operations, and engineering teams to integrate threat intelligence into defensive strategies
Threat Intelligence Analyst at work

Tools & technology

Threat Intelligence Platforms (TIPs)SIEM (Splunk, QRadar, Sentinel)Malware Analysis Tools (IDA Pro, Ghidra)OSINT Tools (Maltego, Shodan)Packet Analyzers (Wireshark)

Average salary

$110K
MEDIAN SALARY Annual · USD
$85K Bottom 10%
$145K Top 10%

Job outlook

Growing

Job growth is expected to be above average over the next five years.

Education & training

A bachelor's degree in cybersecurity, computer science, or a related field is typically required. Relevant certifications (e.g., CompTIA CySA+, GIAC GCTI) are highly valued.

Career pathways

WHERE YOU COULD GO

Senior Threat Intelligence Analyst
Threat Intelligence Lead

CURRENT ROLE

Threat Intelligence Analyst

IT Operations & Security

ADJACENT MOVES

Cybersecurity Architect
Incident Response Analyst
Security Operations Center Analyst
Junior Cybersecurity Analyst
Network Security Specialist

STARTING POINTS

Who thrives here

Interest profile

C

conventional · CIR

Individuals who thrive on systematic analysis, meticulous research, and the practical application of technical knowledge to solve complex problems are well-suited for this role.

Personality characteristics

Analytical

Possesses a strong desire to explore complex data, uncover patterns, and understand the root causes of cyber threats.

Meticulous

Exhibits a high degree of conscientiousness, ensuring accuracy and thoroughness in threat research and report generation.

Independent

Comfortable working autonomously on detailed research and analysis, often preferring focused individual work.

Objective

Approaches information with a critical and unbiased perspective, prioritising facts and evidence in threat assessments.

Calm under pressure

Maintains composure and clear thinking when dealing with critical and rapidly evolving cyber threats.

Best for

  • Individuals who enjoy detective work, piecing together clues to understand and predict adversary actions.
  • Professionals who are detail-oriented, systematic, and committed to producing high-quality, actionable intelligence.
  • Those who are passionate about cybersecurity and eager to protect organisations from sophisticated digital threats.

Watch out for

  • The work can be highly technical and requires continuous self-education to stay ahead of evolving threats.
  • While collaborative, much of the core analysis is independent, which may not suit those who prefer constant team interaction.
  • Occasional weekend work may be required during critical incident response or urgent threat analysis.

A week in the life

A representative working week for a Threat Intelligence Analyst — where the deep work, meetings, and admin actually land.

8am9am10am11am12pm1pm2pm3pm4pm5pm6pm
Mon
Daily Threat Briefing Standup
OSINT Monitoring & Initial Triage
Deep Dive - Analysing a New Threat Campaign
Tue
Vulnerability Intelligence Review
Collaboration with SOC Team on IOCs
Drafting Threat Report - Executive Summary
Wed
Threat Intelligence Platform (TIP) Management
Researching Emerging Attack Vectors
Peer Review of Threat Report
Refining Report Based on Feedback
Thu
Attending Industry Threat Briefing (Webinar)
Malware Sample Analysis
Developing Custom Detection Rules
Fri
Weekly Planning and Prioritisation
Knowledge Sharing Session with Security Engineering
Ad-hoc Research / Self-paced Learning
Deep work Meeting External Social Admin

FREE ASSESSMENT

Does Threat Intelligence Analyst fit you?

Measure your personality and interests, then see how this career ranks against 1,300+ others — for you personally.

Take the free assessment →