Threat Intelligence Analyst job description.
A Threat Intelligence Analyst researches and synthesizes information about emerging cyber threats, threat actors, and attack campaigns to inform an organization's security posture. They gather intelligence from open-source, commercial, and internal feeds, then translate findings into actionable guidance for security and executive teams. The role requires strong analytical writing and cross-functional collaboration.
The Threat Intelligence Analyst job description · $29
The full editable .docx — role summary, 8 worked responsibilities, qualifications, and skills, formatted for your letterhead. Delivered to your inbox within 24 hours — usually instantly.
Role: Threat Intelligence Analyst Reports to: Security Operations Manager or CISO
A Threat Intelligence Analyst researches and synthesizes information about emerging cyber threats, threat actors, and attack campaigns to inform an organization's security posture. They gather intelligence from open-source, commercial, and internal feeds, then translate findings into actionable guidance for security and executive teams. The role requires strong analytical writing and cross-functional collaboration.
- Collect and analyze threat data from open-source and commercial feeds
- Track and profile threat actor groups and campaigns relevant to the organization
- Produce strategic, tactical, and operational intelligence reports
What's inside the document.
One-paragraph plain-English explanation of the role's outcome and scope.
8 responsibilities phrased the way the work is actually done.
4 qualifications a candidate must have to perform on day 30.
3 qualifications that would make a candidate excellent in year two.
5 skill chips you can copy directly into your ATS.
Security Operations Manager or CISO
A complete document set.
- Word document (.docx) — fully editable
- PDF — signature-ready
- Google Docs — one-click copy to your Drive
- 12 months of updates to this document
- Commercial-use licence for internal and client work
The work, not the title.
- Collect and analyze threat data from open-source and commercial feeds
- Track and profile threat actor groups and campaigns relevant to the organization
- Produce strategic, tactical, and operational intelligence reports
- Brief security and executive stakeholders on emerging threats
- Recommend detection and mitigation strategies based on intelligence findings
- Maintain threat intelligence platforms and data feeds
- Collaborate with SOC and incident response teams during active investigations
- Evaluate the relevance and reliability of intelligence sources
Required — and what would make a candidate excellent.
- Bachelor's degree in cybersecurity, intelligence studies, or related field
- 3+ years of experience in threat intelligence or security analysis
- Strong analytical writing and briefing skills
- Familiarity with threat intelligence platforms and frameworks
- Certification such as GCTI or CTIA
- Experience with dark web or OSINT research tools
- Background in geopolitical or industry-specific risk analysis
Eight steps from download to publish.
- 01Open the Threat Intelligence Analyst job description in Word or your one-click Google Docs copy.
- 02Replace placeholders for company name, reporting line, and location with your specifics.
- 03Tighten the summary to one paragraph that names the team's outcome, not just the role.
- 04Edit the responsibilities to match the actual scope of the seat — aim for 6 to 8 items, not 12.
- 05Separate required qualifications from preferred. Required is what a candidate must have to do the work on day 30; preferred is what would make them excellent in year two.
- 06Add salary range guidance using BLS, Payscale, or your own band data — do not copy generic figures.
- 07Have the hiring manager and one peer read it. Cut anything that wouldn't survive a candidate question.
- 08Publish to your ATS, intranet, and external careers page.
The right document at the right moment.
Use this Threat Intelligence Analyst job description any time you are opening or reopening a seat at this level. The mid band sets the calibration — copy the document, tighten it to your specific scope, and circulate to the hiring panel before the first interview.
The reporting line (Security Operations Manager or CISO) and skills list are starting points. Override either if your org structure or stack differs from the norm — the template is a draft, not a contract.
Honest answers before you download.
- Does this role involve hands-on incident response?
- It can support incident response with context and analysis, but the primary focus is research and intelligence production rather than direct remediation.
- What makes a strong Threat Intelligence Analyst candidate?
- Look for demonstrated analytical writing, familiarity with intelligence frameworks, and the ability to translate technical findings into business-relevant guidance.
Other documents in this neighbourhood.
Threat Analyst
A Threat Analyst monitors, investigates, and assesses cybersecurity threats to protect an organization's systems and data.
SOC Analyst
A SOC Analyst monitors an organization's security infrastructure to detect, investigate, and respond to cybersecurity threats.
Chief Information Security Officer
A Chief Information Security Officer leads an organization's information and cyber security strategy, protecting systems, data, and infrastructure from threats.
This Threat Intelligence Analyst job description is a professionally drafted starting point for your hiring process and is not legal advice. Hiring practice varies by jurisdiction (e.g. pay-transparency laws differ across US states and AU jurisdictions). Adapt this document for your specific location and have employment counsel review any clauses you add before publishing. Salary varies by region, employer type, and experience. Reference BLS or current industry surveys for ranges. Full disclaimer.