Senior Cyber Intelligence Analyst
If you are motivated and believe in the credit union philosophy of "People Helping People," join our team!
About The Role
The Senior Cyber Intelligence Analyst is the technical lead for intelligence-driven detection and exposure management. You own the analytic tradecraft, the detection engineering standards, and the intelligence products that shape how the organization prioritizes vulnerabilities, builds detections, and briefs leadership. You set the bar for the team's Splunk work, mentor analysts, and represent threat intelligence to peer teams and executives.
This is a senior individual-contributor role with real ownership. You are expected to define how the work gets done, not just do it, and to make defensible analytic calls that leadership will act on.
What you will do
Lead threat intelligence and analysis
Required
Disclaimer
State Employees' Credit Union reserves the right to fill this role at a higher/lower level based on business need.
About The Role
The Senior Cyber Intelligence Analyst is the technical lead for intelligence-driven detection and exposure management. You own the analytic tradecraft, the detection engineering standards, and the intelligence products that shape how the organization prioritizes vulnerabilities, builds detections, and briefs leadership. You set the bar for the team's Splunk work, mentor analysts, and represent threat intelligence to peer teams and executives.
This is a senior individual-contributor role with real ownership. You are expected to define how the work gets done, not just do it, and to make defensible analytic calls that leadership will act on.
What you will do
Lead threat intelligence and analysis
- Own the intelligence requirements process: define priority intelligence requirements with stakeholders, maintain the collection plan, and evaluate feed and vendor value.
- Lead analysis of threat actors, campaigns, malware families, and TTPs relevant to financial services, our technology stack, and our third-party ecosystem, mapped to MITRE ATT&CK.
- Produce and quality-review decision-ready intelligence products at the tactical, operational, and strategic levels, including briefings for the CISO and contributions to governance and Board-level reporting.
- Own the threat-informed assessment of newly disclosed vulnerabilities (CISA KEV, EPSS, exploit availability, vendor advisories) and drive that assessment into vulnerability prioritization and emergency remediation decisions.
- Lead intelligence support to incident response: attribution, campaign context, indicator enrichment, and post-incident lessons that become detections and requirements.
- Represent the organization in industry sharing communities (FS-ISAC and peer groups) and build relationships with vendor and government intelligence contacts.
- Own the detection engineering program in Splunk Enterprise Security: standards, lifecycle, coverage measurement, and the tuning process.
- Design and build high-value detections, correlation searches, and risk-based alerting (RBA) logic; review and mentor others' detection work.
- Maintain the MITRE ATT&CK coverage map, prioritize gaps against current threat intelligence and crown-jewel assets, and drive a roadmap to close them.
- Establish detection-as-code practices: version control, peer review, testing against replayed or emulated attack data, and controlled deployment.
- Lead purple-team and adversary emulation exercises to validate detections and measure real coverage rather than assumed coverage.
- Set standards for SPL quality, data model use, CIM compliance, and search performance; partner with the Splunk platform team on data onboarding and platform direction.
- Design and run the threat hunting program: hunt hypotheses tied to priority intelligence requirements, documented methodology, and outcomes that feed detections and remediation.
- Lead cross-source analysis correlating vulnerability data (Tenable) with endpoint (SentinelOne), source control (GitHub), network and edge (F5, Check Point, Zscaler), and email (Proofpoint) telemetry to identify exposed, exploitable, and actively targeted assets.
- Serve as the threat intelligence lead for the continuous threat exposure management (CTEM) program, ensuring exposure prioritization reflects real adversary behavior and business impact.
- Provide threat research and detection strategy for emerging programs in AI security, software supply chain and third-party risk, and application security.
- Mentor and technically guide analysts on the team; review analytic products and detections for rigor and clarity.
- Own the team's Splunk dashboards and scheduled reporting for intelligence metrics, detection coverage, hunt outcomes, and threat-informed vulnerability metrics that roll up to leadership reporting.
- Influence remediation and control decisions across IT operations, application owners, and engineering by presenting evidence-based risk assessments.
- Brief executives and governance audiences clearly and credibly, including confidence levels and dissenting assessments.
Required
- 7+ years in cybersecurity with at least 4 years in threat intelligence, detection engineering, or threat hunting, including experience leading work streams or projects.
- Expert hands-on Splunk skills: advanced SPL, Splunk Enterprise Security, correlation searches, risk-based alerting, data models, CIM, and search optimization.
- A track record of building detection programs or coverage strategies, not just individual detections, and measuring their effectiveness.
- Deep working knowledge of MITRE ATT&CK, structured analytic techniques, and intelligence product standards (confidence language, sourcing, analytic rigor).
- Strong understanding of attacker tradecraft across endpoint, network, identity, cloud, and email, with the ability to translate it into telemetry and search logic.
- Experience integrating threat intelligence into vulnerability prioritization using CVSS, VPR, EPSS, CISA KEV, and exploit intelligence.
- Excellent analytic writing and briefing skills; comfortable presenting to executives and defending assessments under scrutiny.
- Demonstrated ability to mentor and raise the technical bar for a team.
- Experience in financial services or another regulated environment, with familiarity in FFIEC, NIST CSF, CIS Controls, and PCI DSS expectations for threat intelligence and monitoring.
- Experience with Tenable, SentinelOne, GitHub Advanced Security, Zscaler, Proofpoint, or comparable platforms.
- Python for enrichment, automation, and data analysis; experience with security APIs and STIX/TAXII; experience operating a threat intelligence platform (TIP).
- Experience with detection-as-code tooling and CI/CD for detections.
- Hands-on experience with CTEM or exposure management platforms.
- Experience running purple-team or adversary emulation programs.
- Certifications such as GCTI, GCDA, GCFA, GREM, Splunk Enterprise Security Certified Admin, or CISSP.
- Research or practical experience in AI/ML security, software supply chain security, or application security.
Disclaimer
State Employees' Credit Union reserves the right to fill this role at a higher/lower level based on business need.
Recommended Jobs
Senior Network Security Engineer
Posted 41 minutes ago
Senior Cyber Threat Operations Engineer
Posted 1 hour ago
Threat Hunter
Posted 1 hour ago
Director, Cyber Security Detection Engineering
Posted 1 hour ago
Cyber - ServiceNow Security Operations (SecOps) - Manager - Consulting
Posted 1 hour ago

