Senior CIRT / Threat Intel Analyst

S&P Global - Boulder, CO

Hiring: Senior CIRT / Threat Intel Analyst Company: S&P Global Location: Boulder, CO Job Posted Time: 2026-09-17 12:32:56 Target Skills & Keywords : AWS, Azure, GCP, Linux, Root Cause Analysis, SIEM, SOC, SaaS, Splunk, TCP/IP About the job Experience: •3+ years of information security experience with a focus on incident response, threat hunting, or threat intelligence. Required Skills: •Coordinate and triage response to cybersecurity events and conduct forensic analysis across endpoints, networks, cloud, and SaaS. •Integrate threat intelligence into investigations (e.g., enrich IOCs, map activity to MITRE ATT&CK, identify likely threat actors/TTPs, and assess potential impact). •Understand the threat landscape through collaboration with industry peers, FS-ISAC, trust groups, and commercial/open-source intelligence, translating insights into actionable recommendations. •Develop, maintain, and operationalize Incident Response playbooks and SOPs; include PIRs (Priority Intelligence Requirements), collection plans, and feedback loops to refine detections. •Work closely with the SOC to investigate incidents and deliver containment, remediation, and root cause analysis; produce high-quality intel-informed incident reports. •Create and tune detections (e.g., SIEM/SOAR, EDR) using intelligence signals (TTPs, behaviors, YARA/Sigma where applicable). •Produce and present consumable intelligence outputs (e.g., flash alerts, threat overviews, executive briefs) tailored to technical and non-technical stakeholders. •Contribute to vulnerability/threat surfacing (e.g., emerging CVEs, exploit trends) and advise on risk-based prioritization. Qualifications: •Solid functional working knowledge of common cyber attacks, tools, and attacker tradecraft; ability to map activity to MITRE ATT&CK and articulate likely TTPs. •Demonstrated experience handling security events in critical environments and applying intelligence to accelerate triage and response. •Applied hands-on capability in a SIEM (Splunk preferred) for investigations, alert creation, reporting, and threat hunting. •Demonstrated capacity to produce clear, actionable intel and incident reports, including executive-ready summaries and visuals. •Operational familiarity with threat intel workflows: collection planning, source evaluation, indicator lifecycle, PIRs, TLP, and feedback loops to detections. •Excellent communication skills for varied business and technical audiences; strong presentation skills. •Comfortable working in a fast-paced environment; passion for cyber security. •Advanced knowledge of network protocols (TCP/IP, HTTP) and operating systems. •Operational familiarity with threat hunting techniques (hypothesis-driven, ATT&CK-aligned, behavior-based). •Windows and Linux administration tools and concepts. Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!