Cyber Threat Intelligence Analyst — Full Time

May 28, 2026 1 Competitive Atlanta, GA (Hybrid) or Remote - US

About the Role

Trurion empowers organizations with cybersecurity, AI risk management, cyber threat intelligence, and continuous monitoring — helping them identify, assess, and confidently mitigate evolving digital risks.

As a Cyber Threat Intelligence Analyst, you sit at the point where collection becomes conviction. You will track threat actors and campaigns relevant to our clients, enrich and validate what our collection platform surfaces, and produce finished intelligence that a CISO can act on without a translation layer. This is an analytical role with real writing in it: the output of your work is judgment, not a feed.

You will work across client sectors — financial services, healthcare, technology, and critical infrastructure — with exposure to both strategic reporting and time-critical tactical support during active incidents.


Responsibilities

Intelligence production: Research, analyze, and author finished intelligence products — threat actor profiles, campaign assessments, sector threat landscapes, and executive briefings — with clearly stated confidence levels and analytic reasoning that holds up to scrutiny.

Collection and monitoring: Monitor open-source, commercial, dark-web, and first-party collection sources for threats to client environments, industries, and third-party ecosystems. Identify what matters and discard what does not.

Adversary tracking: Track threat actor tactics, techniques, and procedures over time, mapping observed activity to MITRE ATT&CK and maintaining the internal knowledge base of actors, tooling, and infrastructure relevant to our client base.

Indicator analysis: Validate, enrich, and contextualize indicators of compromise. Pivot across infrastructure, malware artifacts, and telemetry to establish attribution confidence and assess relevance rather than simply passing indicators downstream.

Detection and response support: Partner with detection engineering and client security teams to translate intelligence into actionable detection logic and hunt hypotheses, and to prioritize mitigation guidance. Support incident response with rapid tactical intelligence during active events.

Vulnerability and exposure intelligence: Assess emerging vulnerabilities and exploitation activity, and communicate real-world risk to client environments — separating what is being exploited from what is merely severe.

Stakeholder communication: Brief technical and executive audiences, present findings to clients, and communicate complex threat activity in clear language that simplifies complexity without losing accuracy.

Tradecraft and process: Contribute to intelligence requirements, collection planning, and the continuous improvement of analytic standards, reporting templates, and platform workflows.


Requirements

  • 3+ years of professional experience in cyber threat intelligence, security operations, incident response, or a closely related analytical role
  • Working command of core intelligence frameworks — the intelligence lifecycle, MITRE ATT&CK, the Cyber Kill Chain, and the Diamond Model — and the ability to apply them rather than recite them
  • Demonstrated ability to write clear, concise, well-structured intelligence products for both technical and executive audiences
  • Practical experience with indicator analysis and enrichment across infrastructure, domains, and malware artifacts
  • Familiarity with SIEM platforms and threat intelligence platforms such as MISP, OpenCTI, or a commercial equivalent
  • Solid understanding of networking, operating system internals, cloud services, and common attack techniques
  • Structured analytic thinking, including the discipline to express and defend confidence levels and to flag intelligence gaps rather than fill them with assumptions
  • Ability to manage competing priorities and deliver under incident-driven time pressure
  • Minimum of a Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or equivalent major
  • Must be legally authorized to work in the United States without sponsorship

Preferred Qualifications

  • Relevant certification such as GCTI, GCIA, GCFA, CySA+, or CISSP
  • Experience with dark web and closed-forum collection, and with the operational security practices it requires
  • Working knowledge of STIX/TAXII, YARA, and Sigma
  • Scripting ability in Python for enrichment, automation, and data analysis
  • Malware triage or reverse engineering fundamentals
  • Experience supporting third-party or supply chain risk assessments with intelligence
  • Prior consulting, MSSP, or client-facing intelligence experience
  • Foreign language proficiency relevant to threat actor research

What's on Offer

  • Competitive base salary with an annual performance bonus
  • Comprehensive medical, dental, and vision coverage
  • 401(k) with company contribution
  • Paid time off, paid holidays, and paid parental leave
  • Annual budget for training, certifications, and conference attendance
  • Access to commercial intelligence sources and internal collection tooling that most analysts never get their hands on
  • Hybrid schedule from our Atlanta office, or fully remote within the United States

Trurion, LLC is an Equal Opportunity Employer. We evaluate all qualified applicants without regard to any characteristic protected by applicable federal, state, or local law.