Threat Intelligence Analyst
Collects, analyzes, and disseminates cyber threat intelligence from open-source, commercial, and classified feeds, producing actionable intelligence reports to inform defensive security strategies and incident response.
What does a Threat Intelligence Analyst do?
What the work is really like
You spend most of your time collecting signals from places most people never see: open-source intelligence feeds, dark web forums, malware repositories, industry sharing groups, classified briefings if you work in government or defence. You gather indicators of compromise, track threat actor campaigns, and piece together patterns that suggest what kind of attack might come next or which adversary group is behind the breach someone else just reported. The goal is to produce intelligence security teams can act on: a report that tells them which vulnerabilities matter this week, which phishing lures are targeting the industry, or which nation-state group just changed tactics.
Your deliverables are written reports. Some go to executives who need to understand risk in plain language. Others go to incident responders who need technical indicators they can feed into detection tools. You work in threat intelligence platforms like ThreatConnect or Anomali, tagging and scoring findings, managing indicators, and maintaining a library of actor profiles. You use frameworks like MITRE ATT&CK to map techniques and STIX/TAXII to share structured data with partner organisations. The work is research-heavy, and most of it happens alone at a screen.
Stress runs high because the threat picture changes faster than most teams can adapt. You might spend a morning tracking a new ransomware variant and an afternoon briefing leadership on geopolitical risks that could affect your sector. The job combines the investigative patience of a researcher with the urgency of someone who knows that what you miss could become a breach.
Skills and strengths that matter
You need fluency in the mechanics of cyberattacks. That means understanding how malware works at a basic level, how adversaries use infrastructure, and how exploits move through a network. You do not need to reverse-engineer binaries from scratch, but you need to read enough of an analysis to extract what matters. The technical depth required is real, though narrower than a penetration tester's or malware analyst's.
The intellectual core of the job is analytical thinking. Research skills matter more than certifications. You have to sort signal from noise in enormous volumes of data, recognise when two incidents share the same fingerprint, and make defensible judgments about attribution and intent. Written communication is the skill that turns your analysis into something useful. If you cannot write a clear, concise intelligence report, the research does not matter.
Attention to detail keeps you from publishing bad indicators or misattributing an attack. Critical thinking keeps you from overreacting to hype or underestimating a real risk. You work with incomplete information most of the time, so comfort with ambiguity is necessary. Certifications like GIAC Cyber Threat Intelligence or Certified Threat Intelligence Analyst help, though hiring managers care more about whether you can demonstrate investigative rigour and produce coherent analysis under pressure.
Who tends to thrive here
People who do well here like solving puzzles that do not have neat answers. You are comfortable with research that takes hours and sometimes leads nowhere. You enjoy the investigative process more than you mind the repetition, because a lot of threat intelligence work involves monitoring the same sources daily and writing similar reports on different threats. If you need immediate feedback or visible impact, this role will frustrate you. The work prevents incidents, which means much of your success is invisible.
This career suits people who prefer working solo or in small teams. You collaborate with SOC analysts, incident responders, and sometimes law enforcement, but most of your day is spent reading, analysing, and writing on your own. Remote work is common, and the role fits people who are disciplined enough to stay productive without much oversight. The schedule can be erratic when a new campaign breaks or a zero-day surfaces, so flexibility matters.
People who struggle here often find the work too abstract or too slow. If you want to be hands-on with systems, fixing problems in real time, threat intelligence will feel too far removed. The role also drains people who cannot tolerate the volume of bad news: you spend your days cataloguing the ways systems fail and adversaries win.
How people get into the role and grow
Most analysts enter the field with a bachelor's degree in cybersecurity, intelligence studies, computer science, or a related discipline. Some come from military or government intelligence backgrounds and move into the private sector with clearance and experience in classified threat reporting. Others start as SOC analysts, get exposure to threat intelligence through incident response work, and step into the role once they demonstrate research skills and an understanding of adversary behaviour.
Your first year is spent learning the tools, the taxonomy, and the rhythm of intelligence production. You contribute to reports rather than writing them solo, and you work under the supervision of a senior analyst who reviews your findings. By year four, you should be producing intelligence independently, managing your own collection sources, and briefing stakeholders without oversight. Certifications like GCTI or CTIA become more valuable as you move toward senior roles, where you are expected to mentor junior analysts and shape the direction of the intelligence programme.
Career progression typically moves through senior analyst to lead roles, where you manage a small team and coordinate intelligence sharing across the organisation. Some people move laterally into threat hunting, incident response, or security architecture. Others progress into director-level roles overseeing the entire intelligence function, or into advisory positions supporting executive risk decisions. Growth is steady in a field where demand continues to outpace the supply of people who can do the work well.
If any of this sounds like the shape of how you already think, CareerMatch can tell you whether the fit is as close as it reads.
From people doing the work
As a Threat Intelligence Analyst, you're constantly sifting through noise to find the signal. It's like being a digital detective, piecing together clues from various sources to understand who the adversaries are, what they want, and how they operate. The work is challenging, requiring a combination of technical know-how and critical thinking, but very worthwhile when your insights help protect an organization.
Drawn from SANS Internet Storm Center, FIRST (Forum of Incident Response and Security Teams), r/cybersecurity, Threat Intelligence Slack
Attribution: Composite
Composite · Synthesised from SANS Internet Storm Center, FIRST (Forum of Incident Response and Security Teams), r/cybersecurity, Threat Intelligence Slack
A day in the life of a Threat Intelligence Analyst
- People interaction
- Moderate
- Team vs solo
- 40% Team / 60% Solo
- Client facing
- Rarely
- Impact visibility
- High
- Travel
- Low
- Schedule flexibility
- Moderate
- Remote work
- Mostly Remote
- Typical work hours
- 42-50
- Stress level
- High
Threat Intelligence Analyst salary, education and outlook at a glance
- Median salary
- $98,000
- Entry-level
- $65,000
- Senior
- $142,000
- Growth by 2033
- 12%
- Demand
- Growing Fast
- Freelance potential
- Moderate
- Salary growth potential
- 118%
- Typical student debt
- Moderate
Skills you need as a Threat Intelligence Analyst
Hard skills
- MITRE ATT&CK/STIX/TAXII
- OSINT Collection
- Malware Analysis (basic)
- Threat Intelligence Platforms (ThreatConnect/Anomali)
- Dark Web Monitoring
- IOC Management
- Intelligence Report Writing
Soft skills
- Analytical Thinking
- Research Skills
- Written Communication
- Critical Thinking
- Attention to Detail
Technical complexity: High
Tools of the trade
Core tools
- MITRE ATT&CK (Standard): A globally accessible knowledge base of adversary tactics and techniques based on real-world observations, used for developing specific threat models and methodologies.
- STIX/TAXII (Standard): Standards for automated sharing of cyber threat intelligence, enabling organizations to exchange threat information efficiently and securely.
- ThreatConnect (Platform): A threat intelligence platform that aggregates, analyzes, and acts on threat intelligence to inform security operations and risk management.
Commonly used
- Anomali ThreatStream (Platform): Provides a unified platform for threat intelligence management, enabling analysts to operationalize intelligence and detect threats faster.
- Maltego (Software): An open-source intelligence (OSINT) and graphical link analysis tool used for gathering and connecting information for investigative tasks.
- Splunk (Platform): A security information and event management (SIEM) solution used for collecting, monitoring, and analyzing security data from various sources.
- VirusTotal (Service): A free online service that analyzes suspicious files and URLs to detect types of malware and automatically shares them with the security community.
How to become a Threat Intelligence Analyst
- Minimum education
- Bachelor's in Cybersecurity, Intelligence Studies, or IT; GIAC GCTI, CTIA certifications
- Licensing
- No
- Years to mid-career
- 4-4
- Years to senior
- 9-9
- Career switching
- Moderate
Where this career leads
How people arrive here
- SOC Analyst: Often, the foundational experience in monitoring and responding to security incidents provides a strong basis for understanding threat landscapes.
- Network Security Engineer: Deep understanding of network infrastructure and traffic patterns is crucial for identifying and analyzing network-based threats.
- Malware Analyst: Specialized skills in dissecting malicious software directly contribute to understanding adversary capabilities and developing intelligence.
Where you can go from here
- Senior Threat Intelligence Analyst: Advancing to a senior role involves leading intelligence projects, mentoring junior analysts, and developing strategic intelligence reports.
- Cyber Threat Hunter: Utilizing threat intelligence to proactively search for undetected threats within an organization's network and systems.
- Security Architect: Applying threat intelligence insights to design and implement robust security architectures that defend against known and emerging threats.
Typical progression
- SOC Analyst
- Threat Intel Analyst
- Senior Threat Intel Analyst
- Threat Intel Lead
- Director of Threat Intelligence / CISO
Threat Intelligence Analyst job outlook and future demand
- Automation probability
- Low
- AI disruption risk
- Moderate
- Demand trend
- Growing Fast
Job satisfaction as a Threat Intelligence Analyst
- Overall satisfaction
- 7.5/10
- Meaning
- 8/10
- Work-life balance
- 6/10
- Prestige
- 7/10
- Social perception
- High
Where practitioners gather
Professional organisations
- FIRST (Forum of Incident Response and Security Teams): A global forum for incident response and security teams to share information, tools, and best practices.
Podcasts and media
- SANS Internet Storm Center: Provides daily summaries of internet threats and vulnerabilities, offering valuable insights for threat intelligence professionals.
Reddit communities
- r/cybersecurity: A community for discussions, news, and resources related to all aspects of cybersecurity, including threat intelligence.
Online communities
- Threat Intelligence Slack: A collaborative space for threat intelligence professionals to share real-time updates, ask questions, and network.