This role has closed. Avav has taken the posting down.
hirly last saw it live on 29 September 2026. See similar open roles below, or browse all jobs in Melbourne.
Avav
Cyber Threat Intelligence III
Albuquerque, NM · Dayton, OH · Huntsville, AL · Simi Valley, CA · Sunrise, FL · Herndon, VA · Arlington, VA · Annapolis Junction, MD · Melbourne, FL · Germantown, MD · San Diego, CA
Similar open jobs
- Cyber Threat Intelligence Analyst - Mid-Level & Senior [U.S. Citizenship, Top Secret Clearance w/SCI Eligibility Required]Vialogic · Ashburn, VAFirst seen yesterday
- Sr. Software Engineer, Threat IntelligenceProofpoint · 12 LocationsFirst seen 3d ago
- Senior Technical Recruiter – Cybersecurity & Threat Intelligence TRM Labs · United StatesFirst seen 6d agoremote
- Senior Associate, Threat IntelligenceKroll · United StatesFirst seen 7d ago
- Senior Threat Intelligence Research Engineerfor interns · Sunnyvale, CA, United StatesFirst seen 7d ago
- Principal Cyber Threat Intelligence SpecialistUmiami · Miami, FLFirst seen today
- Cyber Threat Intelligence (Fusion) Analyst - TS/SCI with PolygraphGdit · 2 LocationsFirst seen today
- Junior Tactical All Source Threat Intelligence Analyst - Overnight Shift (Top Secret Clearance)Gdit · USA VA ViennaFirst seen today
- Cyber Threat Intelligence AnalystGeneralmotors · 2 LocationsFirst seen yesterday
- Threat Intelligence AnalystTlingit Haida Tribal Business Corporation · Washington, District of Columbia, United StatesFirst seen yesterday
- Program Manager, Safeguards Policy, Enforcement, and Threat IntelligenceAnthropic · San Francisco, CAFirst seen yesterday
- Cyber Threat Intelligence AnalystBah · Huntsville, ALFirst seen yesterday
- Principal Cyber Threat Intelligence AnalystJobgether · USFirst seen 2d agoremote
- Cyber Threat Intelligence Analyst, Scams (DC, MD, VA only)TRM Labs · Washington DCFirst seen 2d agoremote
- Manager, Threat IntelligencePditechnologies · Remote USFirst seen 2d agoremote
hirly's read of this role
- Seniority
- Senior
- Country
- US
- Work mode
- On-site / unstated
- First seen by hirly
- 12 Sept 2026
Derived automatically from the posting.
the posting
Worker Type
- Regular
- Job Description
Summary
The Cyber Threat Intelligence (CTI) Analyst is responsible for identifying, analyzing, and communicating cyber threats that may impact the organization, its employees, systems, data, and business operations. This role combines traditional threat intelligence analysis with strong technical cybersecurity aptitude to ensure intelligence is actionable and can be translated into detections, investigations, vulnerability prioritization, and defensive security improvements.
The ideal candidate understands threat actors and geopolitical or industry-specific threats while also possessing hands-on familiarity with security technologies, endpoint and network telemetry, SIEM/XDR platforms, vulnerability data, and common attacker techniques.
Position Responsibilities
Cyber Threat Intelligence
- Monitor and analyze cyber threat intelligence from commercial, government, open-source, and internal sources.
- Identify emerging threat actors, campaigns, malware, vulnerabilities, tactics, techniques, and procedures (TTPs) relevant to the organization.
- Develop intelligence assessments covering strategic, operational, and tactical cyber threats.
- Maintain threat actor profiles, indicators of compromise (IOCs), TTPs, and intelligence requirements.
- Analyze threats using frameworks such as MITRE ATT&CK and the Cyber Kill Chain.
- Produce executive-level intelligence reports, technical threat reports, alerts, and briefings.
- Evaluate the credibility, relevance, and confidence level of intelligence before dissemination.
- Track threats targeting the organization's industry, technology stack, supply chain, and critical business operations.
Technical Threat Analysis
- Analyze endpoint, network, identity, cloud, email, and security telemetry to validate threat intelligence.
- Use SIEM/XDR platforms to investigate IOCs, suspicious activity, and threat actor behaviors.
- Perform threat hunting based on intelligence-derived hypotheses and known adversary TTPs.
- Develop and execute searches using technologies such as KQL, XQL, SPL, or similar query languages.
- Analyze IP addresses, domains, URLs, file hashes, certificates, processes, command lines, and other technical indicators.
- Understand common Windows, Linux, network, Active Directory/Entra ID, cloud, and endpoint attack techniques.
- Work with SOC and security engineering teams to translate intelligence into actionable detections and security controls.
- Assist with developing detection logic, watchlists, blocklists, threat-hunting queries, and alerting rules.
Vulnerability & Exposure Intelligence
- Monitor emerging vulnerabilities, zero-day vulnerabilities, exploitation activity, and threat actor targeting.
- Correlate vulnerability intelligence with the organization's technology and asset inventory.
- Assist vulnerability management teams with risk-based vulnerability prioritization based on active exploitation, threat intelligence, asset criticality, and business impact.
- Monitor sources such as CISA KEV, vendor advisories, security researchers, and commercial intelligence providers.
- Evaluate whether newly disclosed vulnerabilities represent an immediate threat to the organization.
Incident Response Support
- Provide threat intelligence support during cybersecurity incidents.
- Research suspected threat actors, malware, infrastructure, and attack techniques during active investigations.
- Enrich security alerts and incidents with relevant threat intelligence.
- Identify related infrastructure, IOCs, TTPs, and historical activity.
- Support incident scoping and attribution where appropriate.
- Document intelligence findings and provide recommendations to incident commanders and security leadership.
Threat Intelligence Platform & Data Management
- Maintain and improve threat intelligence platforms, feeds, integrations, and intelligence repositories.
- Evaluate intelligence feeds for accuracy, duplication, relevance, and operational value.
- Integrate threat intelligence with SIEM, XDR, SOAR, EDR, vulnerability management, and other security platforms.
- Support automation of IOC ingestion, enrichment, correlation, and response workflows.
- Continuously improve the organization's intelligence collection requirements and processes.
Basic Qualifications (Required Skills & Experience)
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Intelligence Studies, or a related discipline, or equivalent professional experience.
- 3+ years of cybersecurity, threat intelligence, SOC, incident response, threat hunting, or related experience.
- Strong understanding of cyber threat intelligence principles and intelligence lifecycle processes.
- Strong technical aptitude and ability to investigate security data rather than relying solely on intelligence reports.
- Working knowledge of SIEM/XDR platforms, EDR technologies, network security, Windows and Linux operating systems, identity and authentication, vulnerability management, and cloud/SaaS security.
- Understanding of MITRE ATT&CK, adversary TTPs, and common attack methodologies.
- Ability to analyze technical indicators including domains, IP addresses, hashes, URLs, processes, and network activity.
- Ability to communicate complex technical threats to both technical teams and executive leadership.
- Strong analytical, research, documentation, and critical-thinking skills.
Other Qualifications & Desired Competencies
Experience with one or more of the following technologies is preferred:
- Microsoft Sentinel / Defender XDR
- Palo Alto Networks
- Tanium
- VirusTotal
- CISA and government intelligence sources
- Threat intelligence platforms (TIPs)
- SOAR technologies
- Vulnerability management platforms
Experience with KQL, XQL, SPL, Python, PowerShell, APIs, JSON, or other scripting/query technologies is highly desirable.
Experience supporting aerospace, defense, manufacturing, government, or other regulated environments is also desirable.
Certifications
Relevant certifications are preferred but not required and may include:
- GIAC Cyber Threat Intelligence (GCTI)
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Forensic Analyst (GCFA)
- CompTIA CySA+
- CompTIA Security+
- CISSP or equivalent cybersecurity certifications
Key Competencies
- Cyber Threat Intelligence
- Technical Threat Analysis
- Threat Hunting
- Threat Actor & Campaign Analysis
- MITRE ATT&CK
- SIEM/XDR Investigation
- Vulnerability Intelligence
- IOC/TTP Analysis
- Incident Response
- Security Data Analysis
- Intelligence Reporting
- Executive Communication
- Cross-Functional Collaboration
What Success Looks Like
The successful Cyber Threat Intelligence Analyst does more than distribute threat reports. This individual can determine which threats actually matter to the organization, validate those threats against internal security data, and work with security teams to turn intelligence into measurable defensive action.
The role serves as the bridge between external threat intelligence and internal security operations, helping the organization move from simply knowing about threats to actively detecting, prioritizing, and defending against them.
Physical Demands
- Ability to work in an office environment (Constant)
- Required to sit and stand for long periods; talk, hear, and use hands and fingers to operate a computer and telephone keyboard (Frequent)
Clearance Level
No Clearance
The salary range for this role is:
$74,500 - $113,500
AeroVironment considers several factors when extending an offer, including but not limited to, the location, the role and associated responsibilities, a candidate’s work experience, education/training, and key skills.
ITAR Requirement:
This position requires access to information that is subject to compliance with the International Traffic Arms Regulations (“ITAR”) and/or the Export Administration Regulations (“EAR”). In order to comply with the requirem
Listed on hirly, a job board. hirly is not the employer: Avav is hiring for this role.