Threat IntelligenceInterviewsCareer

Threat Intelligence Interview Questions in 2026: The Analysis, Not the Feed

IJB

InfoSec Job Board

September 8, 2026 · 11 min read

Cyber threat intelligence interviews surprise people. Candidates arrive ready to recite the latest campaign write-ups and get asked to defend a confidence level instead. CTI is an analysis and writing job, not a feed-forwarding job - the work is turning messy, partial, often contradictory reporting into something a specific person can act on. This guide covers the questions that actually come up for CTI analyst seats, what the interviewer is listening for in each, and what you should ask back before you accept.

The analysis scenarios (the core of the interview)

  • "A vendor publishes a report claiming a new campaign targets your industry. What do you do with it?" The weak answer extracts the indicators and pushes them to the SIEM. The strong answer starts with relevance: does the described tradecraft work against our actual estate, and who asked for this? Then source evaluation - what is the vendor's visibility, is any of this corroborated independently, or is it recycling a third party's reporting? Then output split by audience: a paragraph for leadership on exposure, and behavioral detection ideas for the detection team. Saying "I would ask whether we can corroborate it before we repeat it" is the tradecraft signal.
  • "Two reports disagree about who is behind an intrusion. How do you handle that?" They are testing whether you can hold ambiguity. Good answers separate the observed facts (infrastructure, tooling, victimology, timing) from the interpretation layered on top, check whether both reports ultimately trace to the same original source - circular reporting is the most common failure in this field - and then present the competing hypotheses with the evidence for and against each rather than picking the more exciting one.
  • "Write me the executive summary for that campaign in three sentences." Some interviews run this live. What they want: the impact first, the exposure second, the recommendation third. No kill-chain vocabulary, no malware family names as if the reader knows them, no adjectives doing the work that evidence should. If the reader cannot decide something after reading it, it failed.
  • "We just onboarded a new business unit in a new region. Build me a threat model for it." This is the question that separates analysts from news readers. Start from the business: what does this unit do, what data and systems does it hold, who would want them and why, what is the realistic access path. Then map known adversary behaviors against those paths. A candidate who instead lists the three groups that were in the headlines last month has told the interviewer they cannot do the job.
  • "Your intel says an actor is exploiting a particular remote access product. Turn that into something the SOC can use." Indicators are the floor. The answer they want moves up the pyramid: what behaviors follow exploitation, which log sources would show them, what a detection would look like, and what the expected false positive profile is. Pairing with detection engineering → is most of the job in a mature team.

Knowledge questions

  • "Walk me through the intelligence cycle." Direction, collection, processing, analysis, dissemination, feedback. Anyone can list it. The answer that lands adds where teams actually fail: direction (producing intelligence nobody asked for) and feedback (never finding out whether anything you wrote changed a decision). Mentioning intelligence requirements as the thing that keeps the program honest is a strong signal.
  • "Strategic, operational, tactical - what is the difference and who reads each?" Strategic is risk and trend framing for executives and planners, on a horizon of quarters. Operational is campaign and actor behavior for IR and threat hunting, on a horizon of weeks. Tactical is the technical detail for detection and blocking, often perishable within days. The follow-up is usually "which do you write best?" - answer honestly.
  • "Explain the diamond model and the kill chain." Adversary, capability, infrastructure, victim - and the pivot logic that makes the diamond model useful, not the picture. The kill chain gives you phases to reason about where you can break the sequence. Both are thinking tools. Candidates who describe them as reporting decoration usually have not used them under pressure.
  • "Why are indicators of compromise the least valuable output?" Because they decay. Hashes change on rebuild, domains rotate, addresses get abandoned - often within days. Behaviors and tradecraft persist because they are tied to how the adversary works, not to what they happened to use last week. A candidate who can talk about IOC decay and aging policy in a feed has done the operational work.
  • "What are structured analytic techniques and why bother?" Techniques such as analysis of competing hypotheses, key assumptions checks and devil's advocacy exist to slow down the jump to a favored conclusion and force the evidence to be tested against every plausible explanation, not just the first one. You do not have to run a formal matrix on every task - but you should be able to say when you would.
  • "What does 'likely' mean in your reporting?" A trap for people who use confidence language decoratively. The correct answer is that probability terms only mean something against a defined scale that your consumers have seen, and that source confidence and analytic confidence are separate judgments - high-confidence analysis can rest on a single uncorroborated source, and you must say so.

The judgment questions

  • "An executive asks you to confirm that a nation state attacked us. The evidence is thin. What do you say?" The single most revealing question in a CTI interview. The answer is not to give them the headline they want. Describe what you can support - an activity cluster with observed overlaps in infrastructure and tooling - explain what would be needed to raise confidence, and then redirect to the decision they actually face, which is almost never the actor's nationality. Point out that attribution done publicly and wrongly carries legal, regulatory and reputational consequences the analyst does not get to unwind.
  • "How do you cluster activity without naming a group?" Internal designators tied to observed overlaps, with the criteria for the cluster written down, and merges treated as a deliberate analytic judgment rather than a convenience. Being able to explain that two vendors' group names are not interchangeable - because each is drawn from different visibility - is senior-level signal.
  • "You have access to a criminal forum. What are the limits?" They are checking that you will not create legal or safety exposure for the company. Collection is observation: no purchasing, no engaging or soliciting, no misrepresentation, no touching stolen data. Operate under policy and legal review, use isolated infrastructure, and know exactly when the conversation escalates to counsel and law enforcement. "I would check with legal first" is a good answer here, not a weak one.
  • "Tell me about a piece you wrote that nobody used." Have one. The point is whether you traced back why - wrong audience, no requirement behind it, no action available at the end - and what you changed. Every finished product should pass the "so what" test: what decision does this enable, and for whom.

Questions you should ask them

  • "What are your standing intelligence requirements, and who signed off on them?" (No requirements means the team writes into a void and gets measured on volume.)
  • "Who consumes what we produce, and how do you know whether it changed a decision?" (The feedback stage is the one almost nobody runs.)
  • "How close is CTI to detection and IR here - same team, same rituals, or a report thrown over a wall?"
  • "What is your collection posture: vendor feeds, internal telemetry from our own incidents, or both?" (Internal incident data is the most valuable source most teams underuse.)
  • "Do you have a published confidence and probability scale?" (An honest "no, and it is on the list" is fine. A blank look is the finding.)

Before you interview

Bring writing samples. A CTI hiring manager would rather read two pages you produced - a threat profile, a campaign assessment, even a public write-up you re-analyzed - than hear you list frameworks. If you are building toward the role, the research and proof-of-work ladder in how to become a security researcher → applies directly, and adjacent openings sit on our security researcher jobs board → and incident responder jobs board →. When you are ready to apply, the live CTI openings are on our threat intelligence jobs board → - updated hourly, every listing applying direct to the employer.

Live threat intelligence roles

Browse threat intelligence jobs

Get weekly alerts for Get weekly alerts for new threat intelligence jobs:
Share:LinkedInXWhatsApp

Related guides

Stay ahead of the curve. Get new infosec jobs in your inbox.