Cyber Intelligence Analyst
SECU · Région de Raleigh-Durham-Chapel Hill
Job description
About the role
Join a credit‑union focused team that turns external threat reports and internal telemetry into actionable intelligence. This hands‑on position balances writing Splunk SPL queries with deep threat‑intel analysis to reduce real exposure across the enterprise.
Key responsibilities
- Collect, analyze, and operationalize threat intelligence from commercial feeds, ISACs, open sources and vendor advisories.
- Map threat actors, campaigns, malware families and TTPs to MITRE ATT&CK and produce tactical, operational and strategic intelligence products.
- Assess exploitability of newly disclosed vulnerabilities (CISA KEV, EPSS, vendor advisories) and feed assessments into vulnerability prioritization.
- Design, build, test and tune detections in Splunk Enterprise Security, including correlation searches, risk‑based alerting rules and notable event logic.
- Write efficient SPL, maintain lookups, macros, data models and CIM‑compliant normalization for new data sources.
- Conduct hypothesis‑driven threat hunts across Splunk and endpoint, network, identity and cloud telemetry.
- Correlate vulnerability data (Tenable) with endpoint (SentinelOne), source control (GitHub), network/edge (F5, Check Point, Zscaler) and email (Proofpoint) telemetry to surface exposed assets.
- Build and maintain dashboards and reports for threat‑intel metrics, detection coverage and hunt outcomes.
Required profile
- Motivated professional who embraces the "People Helping People" credit‑union philosophy.
- Hands‑on experience with threat‑intelligence analysis and detection engineering.
- Ability to translate intelligence into detection coverage and close the loop between analysis and implementation.
Required skills
- Splunk Enterprise Security
- Splunk Search Processing Language (SPL)
- MITRE ATT&CK framework
- Threat‑intelligence feeds, ISACs and open‑source intel
- CISA KEV, EPSS, vendor advisory analysis
- Tenable vulnerability data
- SentinelOne endpoint telemetry
- GitHub source‑control data
- F5, Check Point, Zscaler network telemetry
- Proofpoint email security data
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in the United States.
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 5 hours ago
Expires 1 month from now
3 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
SECU
Région de Raleigh-Durham-Chapel Hill
Related job offers
-
Project Manager – LATAM Nearshore (English Required)
DaCodes. Uruguay -
Technology Support Specialist I
MANTECA UNIFIED SCHOOL DISTRICT School -
DevOps Engineer – Alpharetta, GA
Infosys Alpharetta -
Fullstack Developer – React & Node.js (US)
Infosys Richardson -
Data Engineer – Richardson, TX
Infosys Richardson