📢 New: get today's jobs on our WhatsApp Channel
Jobiglo

No results.

Cyber Intelligence Analyst

SECU · Région de Raleigh-Durham-Chapel Hill

New
🇬🇧 English
Splunk Enterprise Security MITRE ATT&CK ISACs CISA KEV EPSS Tenable SentinelOne GitHub F5 Check Point Zscaler Proofpoint

Job description

About the role

Join a credit‑union focused team that turns external threat reports and internal telemetry into actionable intelligence. This hands‑on position balances writing Splunk SPL queries with deep threat‑intel analysis to reduce real exposure across the enterprise.

Key responsibilities

  • Collect, analyze, and operationalize threat intelligence from commercial feeds, ISACs, open sources and vendor advisories.
  • Map threat actors, campaigns, malware families and TTPs to MITRE ATT&CK and produce tactical, operational and strategic intelligence products.
  • Assess exploitability of newly disclosed vulnerabilities (CISA KEV, EPSS, vendor advisories) and feed assessments into vulnerability prioritization.
  • Design, build, test and tune detections in Splunk Enterprise Security, including correlation searches, risk‑based alerting rules and notable event logic.
  • Write efficient SPL, maintain lookups, macros, data models and CIM‑compliant normalization for new data sources.
  • Conduct hypothesis‑driven threat hunts across Splunk and endpoint, network, identity and cloud telemetry.
  • Correlate vulnerability data (Tenable) with endpoint (SentinelOne), source control (GitHub), network/edge (F5, Check Point, Zscaler) and email (Proofpoint) telemetry to surface exposed assets.
  • Build and maintain dashboards and reports for threat‑intel metrics, detection coverage and hunt outcomes.

Required profile

  • Motivated professional who embraces the "People Helping People" credit‑union philosophy.
  • Hands‑on experience with threat‑intelligence analysis and detection engineering.
  • Ability to translate intelligence into detection coverage and close the loop between analysis and implementation.

Required skills

  • Splunk Enterprise Security
  • Splunk Search Processing Language (SPL)
  • MITRE ATT&CK framework
  • Threat‑intelligence feeds, ISACs and open‑source intel
  • CISA KEV, EPSS, vendor advisory analysis
  • Tenable vulnerability data
  • SentinelOne endpoint telemetry
  • GitHub source‑control data
  • F5, Check Point, Zscaler network telemetry
  • Proofpoint email security data

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec SECU.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

By continuing, you accept our terms of use.

Already have an account? Login

💬 Chat with us on Telegram Chat on WhatsApp

Published 5 hours ago

Expires 1 month from now

3 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

SECU

Région de Raleigh-Durham-Chapel Hill