Cyber Intelligence Analyst

SECU - Raleigh-Durham-Chapel Hill Area

Hiring: Cyber Intelligence Analyst Company: SECU Location: Raleigh-Durham-Chapel Hill Area Job Posted Time: 2026-09-15 07:42:39 Target Skills & Keywords : CI/CD, GitHub, Python, SOC, Splunk About the job Experience: •4+ years in cybersecurity with at least 2 years focused on threat intelligence, detection engineering, threat hunting, or SOC analysis. •At least 2 years focused on threat intelligence, detection engineering, threat hunting, or SOC analysis. Required Skills: •Collect, analyze, and operationalize threat intelligence from commercial feeds, ISACs, open sources, and vendor advisories. •Track threat actors, campaigns, malware families, and TTPs relevant to our industry, technology stack, and third-party ecosystem, mapping findings to MITRE ATT&CK. •Produce clear, decision-ready intelligence products: tactical indicator packages, operational campaign analysis, and strategic briefings for leadership. •Assess the exploitability and real-world relevance of newly disclosed vulnerabilities (CISA KEV, EPSS, vendor advisories, exploit availability) and feed that assessment into vulnerability prioritization. •Support incident response with threat context, attribution analysis, and indicator enrichment. •Design, build, test, and tune detections in Splunk Enterprise Security, including correlation searches, risk-based alerting (RBA) rules, and notable event logic. •Translate intelligence on adversary TTPs into detection coverage; maintain a coverage map against MITRE ATT&CK and identify gaps. •Write efficient, maintainable SPL; build and maintain lookups, macros, data models, and CIM-compliant normalization for new data sources. Qualifications: •Strong hands-on Splunk experience: advanced SPL, Splunk Enterprise Security, correlation searches, risk-based alerting, data models, and CIM. •Demonstrated experience building and tuning detections from threat intelligence or adversary emulation. •Solid functional working knowledge of MITRE ATT&CK and the ability to apply it to both intelligence analysis and detection coverage. •Solid understanding of attacker tradecraft across endpoint, network, identity, cloud, and email. •Operational familiarity with vulnerability management data and prioritization frameworks (CVSS, VPR, EPSS, CISA KEV). •Strong analytical writing; able to produce concise intelligence products for audiences ranging from engineers to executives. •Scripting in Python for enrichment, automation, or data analysis; familiarity with APIs and STIX/TAXII. •Exposure to CTEM or exposure management platforms. •Relevant certifications such as GCTI, GCDA, GCFA, Splunk Core Certified Power User or Enterprise Security Certified Admin, or CySA+. •Background in AI/ML security, software supply chain security, or application security. Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!