Jobs › Companies › SECU › Senior Cyber Intelligence Analyst

Über diese Senior Cyber Intelligence Analyst Stelle bei SECU

SECU · Vor Ort · Operations - Raleigh - Creedmoor Rd

If you are motivated and believe in the credit union philosophy of "People Helping People," join our team!

About the role

The Senior Cyber Intelligence Analyst is the technical lead for intelligence-driven detection and exposure management. You own the analytic tradecraft, the detection engineering standards, and the intelligence products that shape how the organization prioritizes vulnerabilities, builds detections, and briefs leadership. You set the bar for the team's Splunk work, mentor analysts, and represent threat intelligence to peer teams and executives.

This is a senior individual-contributor role with real ownership. You are expected to define how the work gets done, not just do it, and to make defensible analytic calls that leadership will act on.

What you will do

Lead threat intelligence and analysis

  • Own the intelligence requirements process: define priority intelligence requirements with stakeholders, maintain the collection plan, and evaluate feed and vendor value.
  • Lead analysis of threat actors, campaigns, malware families, and TTPs relevant to financial services, our technology stack, and our third-party ecosystem, mapped to MITRE ATT&CK.
  • Produce and quality-review decision-ready intelligence products at the tactical, operational, and strategic levels, including briefings for the CISO and contributions to governance and Board-level reporting.
  • Own the threat-informed assessment of newly disclosed vulnerabilities (CISA KEV, EPSS, exploit availability, vendor advisories) and drive that assessment into vulnerability prioritization and emergency remediation decisions.
  • Lead intelligence support to incident response: attribution, campaign context, indicator enrichment, and post-incident lessons that become detections and requirements.
  • Represent the organization in industry sharing communities (FS-ISAC and peer groups) and build relationships with vendor and government intelligence contacts.

Lead detection engineering

  • Own the detection engineering program in Splunk Enterprise Security: standards, lifecycle, coverage measurement, and the tuning process.
  • Design and build high-value detections, correlation searches, and risk-based alerting (RBA) logic; review and mentor others' detection work.
  • Maintain the MITRE ATT&CK coverage map, prioritize gaps against current threat intelligence and crown-jewel assets, and drive a roadmap to close them.
  • Establish detection-as-code practices: version control, peer review, testing against replayed or emulated attack data, and controlled deployment.
  • Lead purple-team and adversary emulation exercises to validate detections and measure real coverage rather than assumed coverage.
  • Set standards for SPL quality, data model use, CIM compliance, and search performance; partner with the Splunk platform team on data onboarding and platform direction.

Lead threat hunting and exposure management

  • Design and run the threat hunting program: hunt hypotheses tied to priority intelligence requirements, documented methodology, and outcomes that feed detections and remediation.
  • Lead cross-source analysis correlating vulnerability data (Tenable) with endpoint (SentinelOne), source control (GitHub), network and edge (F5, Check Point, Zscaler), and email (Proofpoint) telemetry to identify exposed, exploitable, and actively targeted assets.
  • Serve as the threat intelligence lead for the continuous threat exposure management (CTEM) program, ensuring exposure prioritization reflects real adversary behavior and business impact.
  • Provide threat research and detection strategy for emerging programs in AI security, software supply chain and third-party risk, and application security.

Mentor, influence, and report

  • Mentor and technically guide analysts on the team; review analytic products and detections for rigor and clarity.
  • Own the team's Splunk dashboards and scheduled reporting for intelligence metrics, detection coverage, hunt outcomes, and threat-informed vulnerability metrics that roll up to leadership reporting.
  • Influence remediation and control decisions across IT operations, application owners, and engineering by presenting evidence-based risk assessments.
  • Brief executives and governance audiences clearly and credibly, including confidence levels and dissenting assessments.

What you bring

Required

  • 7+ years in cybersecurity with at least 4 years in threat intelligence, detection engineering, or threat hunting, including experience leading work streams or projects.
  • Expert hands-on Splunk skills: advanced SPL, Splunk Enterprise Security, correlation searches, risk-based alerting, data models, CIM, and search optimization.
  • A track record of building detection programs or coverage strategies, not just individual detections, and measuring their effectiveness.
  • Deep working knowledge of MITRE ATT&CK, structured analytic techniques, and intelligence product standards (confidence language, sourcing, analytic rigor).
  • Strong understanding of attacker tradecraft across endpoint, network, identity, cloud, and email, with the ability to translate it into telemetry and search logic.
  • Experience integrating threat intelligence into vulnerability prioritization using CVSS, VPR, EPSS, CISA KEV, and exploit intelligence.
  • Excellent analytic writing and briefing skills; comfortable presenting to executives and defending assessments under scrutiny.
  • Demonstrated ability to mentor and raise the technical bar for a team.

Preferred

  • Experience in financial services or another regulated environment, with familiarity in FFIEC, NIST CSF, CIS Controls, and PCI DSS expectations for threat intelligence and monitoring.
  • Experience with Tenable, SentinelOne, GitHub Advanced Security, Zscaler, Proofpoint, or comparable platforms.
  • Python for enrichment, automation, and data analysis; experience with security APIs and STIX/TAXII; experience operating a threat intelligence platform (TIP).
  • Experience with detection-as-code tooling and CI/CD for detections.
  • Hands-on experience with CTEM or exposure management platforms.
  • Experience running purple-team or adversary emulation programs.
  • Certifications such as GCTI, GCDA, GCFA, GREM, Splunk Enterprise Security Certified Admin, or CISSP.
  • Research or practical experience in AI/ML security, software supply chain security, or application security.

SECU provides equal employment opportunity to all qualified persons regardless of race, color, religion, age, sex, sexual orientation, gender identity, national origin, genetic information, disability, veteran status, or other classification protected by law.

Disclaimer

State Employees' Credit Union reserves the right to fill this role at a higher/lower level based on business need.

Bereit, sich bei SECU zu bewerben?
Bei SECU bewerben

Über SECU

State Employees' Credit Union is a not-for-profit, member-owned financial cooperative with a "Do the Right Thing" mission and a goal of helping people in our community. SECU values the differences in our staff and in our North Carolina communities. We believe that embracing the uniqueness of individuals makes our cooperative stronger, more innovative and better able to serve SECU members.

Alle Jobs bei SECU ansehen →

Ähnliche Jobs

SECU
Sr Member Services Representative
SECU
⚡ Früh bewerben Brevard Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
SECU
Intern – Server Engineering and Operations Part-time Spring 2027
SECU
⚡ Früh bewerben North Carolina Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
SECU
Mortgage Loan Specialist
SECU
⚡ Früh bewerben Shallotte Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
SECU
Associate Member Services Representative
SECU
⚡ Früh bewerben Charlotte-Park Rd Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
SECU
Associate Member Services Representative
SECU
⚡ Früh bewerben Greenville-First St Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
SECU
Senior Member Services Representative
SECU
⚡ Früh bewerben Concord-Poplar Tent Rd Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
SECU
Senior Construction Lending Specialist
SECU
⚡ Früh bewerben Operations-Wake Forest Road Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
SECU
Intern – Branch Part-time Spring 2027
SECU
⚡ Früh bewerben North Carolina Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 2 Tg.
SECU
Mortgage Loan Specialist
SECU
⚡ Früh bewerben Durham - Lowe's Grove Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 2 Tg.

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei SECU

Alle Jobs bei SECU ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos