- Location
- Malvern, PA, United States of America
- Type
- Full-time
- Department
- Human Resources
- Experience
- 2+ years
- Education
- Bachelor
- Visa
- Not sponsored
- Source
- Workday
Description
Position Summary
The Cyber Threat Intelligence (CTI) Analyst is responsible for identifying, analyzing, and communicating cyber threats that may impact the organization. This role supports intelligence collection, threat monitoring, analytic assessments, and intelligence dissemination to enhance organizational awareness and defensive decision-making.
The successful candidate will transform technical threat data into actionable intelligence products for cybersecurity operations, incident response, risk management, and executive stakeholders.
Key Responsibilities
Intelligence Collection & Analysis
- Monitor open-source, commercial, government, and industry intelligence sources for emerging cyber threats.
- Research threat actors, malware campaigns, vulnerabilities, and geopolitical developments relevant to the organization's risk profile.
- Identify, assess, and contextualize indicators of compromise (IOCs), tactics, techniques, and procedures (TTPs).
- Produce timely assessments regarding threat activity, likelihood, and organizational impact.
Intelligence Production
- Develop intelligence reports, briefings, alerts, and situational awareness products.
- Produce tactical, operational, and strategic intelligence products for technical and non-technical audiences.
- Create executive summaries that clearly communicate risk, implications, and recommended actions.
- Maintain intelligence repositories and knowledge management resources.
Operational Support
- Support incident response and investigative activities through intelligence enrichment and adversary research.
- Collaborate with Security Operations Center (SOC), Threat Hunting, Detection Engineering, and Forensics teams.
- Provide intelligence-driven recommendations to improve detection and response capabilities.
- Assist with threat actor tracking and long-term campaign monitoring.
Stakeholder Engagement
- Brief cybersecurity teams, business leaders, and risk partners on relevant threats and trends.
- Participate in intelligence-sharing communities and industry partnerships.
- Develop strong working relationships with internal stakeholders to understand intelligence requirements.
Continuous Improvement
- Contribute to intelligence collection plans and analytic methodologies.
- Evaluate emerging intelligence tools, data sources, and automation opportunities.
- Leverage AI and automation technologies to improve collection, triage, and reporting efficiency.
- Maintain awareness of evolving cyber threats, industry trends, and intelligence tradecraft.
Required Qualifications
- 2-5 years of experience in cyber threat intelligence, security operations, incident response, digital forensics, threat hunting, vulnerability management, or a related cybersecurity discipline.
- Bachelor's degree in Cybersecurity, Information Technology, Intelligence Studies, Computer Science, or a related field (or equivalent experience).
- Understanding of cyber threat intelligence frameworks such as: MITRE ATT&CK Diamond Model Intelligence Lifecycle Kill Chain
- Familiarity with common threat actor TTPs and malware trends.
- Strong written and verbal communication skills.
- Demonstrated ability to analyze information from multiple sources and develop actionable assessments.
Preferred Qualifications
- Experience with intelligence platforms such as ThreatConnect, Recorded Future, Google Threat Intelligence, Intel471, Mandiant, or similar tools.
- Experience supporting financial services, critical infrastructure, or regulated industries.
- Knowledge of incident response processes and security operations workflows.
- Familiarity with scripting or automation technologies (Python, PowerShell, APIs).
- Intelligence or cybersecurity certifications such as: GIAC Cyber Threat Intelligence (GCTI) CISSP Security+ CySA+ Certified Threat Intelligence Analyst (CTIA)
Key Competencies
- Critical Thinking
- Analytical Reasoning
- Intellectual Curiosity
- Attention to Detail
- Executive Communication
- Collaboration and Teamwork
- Risk-Based Decision Making
- Written Intelligence Production
- Presentation and Briefing Skills
Success Measures
Within the first year, the analyst should demonstrate the ability to:
- Independently produce high-quality intelligence assessments.
- Deliver concise executive and operational threat briefings.
- Support incident investigations with timely intelligence analysis.
- Establish expertise in designated threat actors, campaigns, or threat domains.
- Improve intelligence processes through automation, research, or collection enhancements.
- Build trusted relationships with cybersecurity, risk, and business stakeholders.
Special Factors
Sponsorship
Vanguard is not offering visa sponsorship for this position.About Vanguard
At Vanguard, we don't just have a mission—we're on a mission.
To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.
How We Work
Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.