Cyber threat intelligence is an analysis and writing job. That sentence disappoints a lot of people who arrive expecting to track adversaries all day, and it is the single most useful thing to understand before you aim at the role. A CTI analyst turns partial, contradictory, often self-interested reporting into something a named person can act on. The technical grounding matters, but the output is prose with a judgment in it.
This guide covers what the work actually is, how it differs from detection engineering and a SOC seat, where the seats are, the skills employers weigh, the realistic paths in, the proof of work that gets you shortlisted, a 6-month plan, and an honest look at the parts of the job people find disappointing.
What threat intelligence actually is
The failure mode of the field is feed forwarding: receiving indicators, republishing them, and calling it intelligence. Intelligence is the analysis layer on top - what does this mean for us, how confident are we, and what should change as a result. If a product does not enable a decision for someone, it was activity, not intelligence.
How it sits next to the roles it is most often confused with:
- Versus detection engineering: a detection engineer builds and tunes the logic that fires. CTI supplies the behavioral picture that logic should encode, and evaluates whether the assumption behind a detection still holds. Adjacent, constantly paired, different deliverables.
- Versus a SOC seat: a SOC analyst works a queue against events that already happened. CTI works ahead of and around the queue: what should we be watching for, what is the exposure, is this campaign relevant to our estate at all.
- Versus security research: a researcher goes deep on a technical artifact. CTI is broader and more synthetic, and is measured on whether a non-technical reader made a better decision. The two overlap heavily - see how to become a security researcher.
The three consumer tiers, and how the job changes across them
- Strategic: written for executives, risk committees and planners on a horizon of quarters. Trend and exposure framing, budget and investment implications, almost no technical vocabulary. This is the hardest tier to write well and the one that gets people promoted.
- Operational: written for incident response and threat hunting on a horizon of weeks. Campaign and actor behavior, victimology, the access paths that matter for your estate specifically.
- Tactical: written for detection and blocking, and frequently perishable within days. Behaviors, tooling, infrastructure patterns. The tier everyone starts in and the one where the least durable value lives.
Most job descriptions do not say which tier the seat sits in. Ask. A role that is 90% tactical enrichment and a role that briefs the board are the same title and a completely different career.
Where the seats are
- Security vendors: research and publication-facing work. Your output is partly marketing surface, which is a real constraint worth naming in the interview.
- Large enterprises with an in-house function: a small team serving internal consumers, with intelligence requirements tied to the business. Often the best environment for learning to write for a specific reader.
- MSSPs: intelligence produced once and delivered across many clients. High volume, and a genuine tension between generic and specific.
- Financial services: one of the densest concentrations of mature CTI teams, driven by regulation, fraud adjacency and sector information sharing.
- Government and its contractors: the deepest tradecraft training available, usually with clearance requirements and a slower hiring path.
Core skills employers actually weigh
- Structured analytic techniques: analysis of competing hypotheses, key assumptions checks, devil's advocacy. The point is to stop you jumping to the first plausible explanation. You should be able to say when you would run one, not just name them.
- Writing that survives an executive audience: impact first, exposure second, recommendation third. If the reader cannot make a decision after three sentences, it failed. This is the most commonly underrated skill in the field.
- Source evaluation: what visibility does this source actually have, is anything corroborated independently, and does the reporting ultimately trace back to one original source. Circular reporting is the field's most common quiet failure.
- A defined confidence scale: words such as likely only mean something against a published scale your consumers have seen. Source confidence and analytic confidence are separate judgments, and you have to say which is thin.
- OSINT tradecraft: collection as observation, with isolated infrastructure, documented method and a clear line where the work escalates to legal counsel. No purchasing, no soliciting, no misrepresentation.
- Enough technical grounding: you need to read malware and infrastructure reporting without being led by it, understand logging and telemetry, and be able to translate a behavior into something a detection team can use.
- A language beyond English: a genuine differentiator, not a nice-to-have. Much of the primary source material is not in English, and teams that can read it directly stop depending on someone else's summary.
Certifications
CTI is a portfolio field first. A hiring manager would rather read two pages you wrote than see a credential list. Certifications mainly help pass HR filters and matter more in government-adjacent and large enterprise hiring.
Certifications employers ask for in Threat Intelligence Analyst roles
Salaries
We deliberately do not publish a single threat intelligence salary band, because the title covers seats that are not priced alike. Vendor-side research, an in-house corporate intelligence function and government-adjacent work pay on different curves, and seniority in CTI is measured by the audience you can write for rather than by years. Rather than quote a number we cannot defend, use the live disclosed data:
- Cybersecurity salary report - medians and percentiles computed from postings that actually disclose pay, with the sample size shown.
- Am I underpaid? - compare a specific offer against the market for your role and country.
Realistic paths in
- From a SOC seat: the most common route. You already know telemetry, triage and what a real alert looks like. The gap is writing and analytic method, so start producing short assessments off your own incidents and get them read by someone senior.
- From journalism or academic research: genuinely competitive, because sourcing, verification and writing for a reader are already there. The gap is technical grounding, and it closes faster than most people expect.
- From an intelligence-community background: the tradecraft transfers almost intact. The gap is the technical and commercial context, and translating military or government reporting conventions into something a business audience reads.
- From incident response: you have seen adversary behavior end to end, which is the material CTI reasons about. The gap is moving from one case to patterns across many, and from a timeline to an assessment.
Proof of work that gets you shortlisted
- Published analysis with your reasoning shown. Not a summary of someone else's report. Take a public write-up, re-analyze it, state what you would and would not conclude from the evidence, and say what would change your mind.
- A tracked infrastructure write-up. Pick a publicly documented cluster, work the open infrastructure, document the pivots and where they stopped. Showing the dead ends is the point.
- OSINT and CTF-adjacent work. Useful for demonstrating method and discipline, especially if you write up how you collected rather than just what you found.
- A blog that demonstrates judgment. Aggregation blogs are invisible. A blog with three genuinely reasoned pieces on it beats one with thirty link roundups.
A 6-month plan
- Months 1-2: learn the method. The intelligence cycle, the diamond model and kill chain as thinking tools, structured analytic techniques, and probability and confidence language. Write your first one-page assessment on a public incident and get it critiqued.
- Months 3-4: build collection and technical grounding. Set up isolated infrastructure, practice open-source collection with documented method, and get comfortable reading malware and infrastructure reporting critically. Publish two pieces.
- Months 5-6: write for real audiences. Produce a strategic one-pager and an operational assessment on the same event, so you can show a hiring manager you can change register. Prepare with our threat intelligence interview questions and start applying.
The honest part: what people find disappointing
- It is a lot of writing. If you want to spend your day in a terminal, this is the wrong seat. The analysis is real, but the deliverable is prose, and you will spend more time on the third draft than on the collection.
- Stakeholders who never read it. The feedback stage of the intelligence cycle is the one almost nobody runs, so it is entirely possible to produce for a year without learning whether anything you wrote changed a decision. The fix is standing intelligence requirements with a named owner, and it is worth asking about before you accept an offer.
- The constant pull toward indicator lists. Indicator counts are easy to measure, so teams under pressure drift toward publishing lists nobody uses. Indicators decay within days; behaviors persist. Resisting that drift is a large part of the job, and it is a political job as much as an analytic one.
Live threat intelligence roles
Browse every open listing on our threat intelligence jobs board or the adjacent security researcher jobs board - updated hourly, every listing applying direct to the employer.
Frequently asked questions
- How many Threat Intelligence Analyst jobs are available right now?
- We currently list 108 active Threat Intelligence Analyst roles, refreshed continuously across 150+ security employers.
- What does a Threat Intelligence Analyst earn?
- Threat intelligence pay varies more than most security roles because the seats are not the same job. Vendor-side research, in-house corporate intelligence and government-adjacent work are priced differently, and country matters as much as level. We do not publish a single CTI band we cannot defend - check our cybersecurity salary report for what live listings actually disclose, and the Am I Underpaid tool to compare a specific offer.
- Which certifications help for Threat Intelligence Analyst roles?
- CTI is judged on published analysis and writing far more than on credentials. Where certifications help, GIAC intelligence-track certificates carry the most weight, and CySA+ is a reasonable baseline if you are coming from a SOC seat. A portfolio of finished analysis outranks any of them.
- Are Threat Intelligence Analyst jobs remote?
- Many threat intelligence analyst roles offer remote or hybrid work. Browse our remote cybersecurity jobs to filter for fully-remote positions.
Related guides
How to Become a Detection Engineer in 2026: From Triaging Alerts to Building Them
The realistic path into detection engineering - how the role differs from a SOC analyst seat, the query langua…
11 min read
How to Become an IAM Engineer in 2026: Identity Is the Control Plane
The realistic path into identity and access management - why identity became the control plane, OAuth, OIDC an…
11 min read
How to Become a Product Security Engineer in 2026: Own the Shipped Product
The realistic path into product security - the line between AppSec and product security, threat modelling and …
11 min read