Cyber Threat Intelligence Analyst - Remote
ExternalPrepare for this interview
EliteAI-generated questions, company research, and talking points tailored to this role
Benefits
Additional Information
External candidates: In order for your application to be correctly processed please sign-in before you apply Internal candidates: Please go to Workday and click "Find Jobs" link under Career Thank you for considering opportunities with us! Job Title Cyber Threat Intelligence Analyst - Remote Requisition Number R7811 Cyber Threat Intelligence Analyst - Remote (Open) Location Arizona - Home Teleworkers Additional Locations Alabama - Home Teleworkers, Alabama - Home Teleworkers, Arkansas - Home Teleworkers, California - Home Teleworkers, Colorado - Home Teleworkers, Connecticut - Home Teleworkers, Delaware - Home Teleworker, District of Columbia - Home Teleworkers, Florida - Home Teleworkers, Georgia - Home Teleworkers, Idaho - Home Teleworkers, Illinois - Home Teleworkers, Indiana - Home Teleworkers, Iowa - Home Teleworkers, Kansas - Home Teleworker, Kentucky - Home Teleworkers, Louisiana - Home Teleworkers, Maine Home Teleworkers, Maryland - Home Teleworkers, Massachusetts - Home Teleworkers, Michigan - Home Teleworkers, Minnesota - Home Teleworkers, Mississippi - Home Teleworker, Missouri - Home Teleworker, Montana - Home Teleworkers {+ 21 more} Job Information CSAA Insurance Group (CSAA IG), a AAA insurer, is one of the leading personal lines property and casualty insurance groups in the United States. Here, every employee shapes our mission. We build innovative, human-centered solutions that help AAA members prevent, prepare for, and recover from life's uncertainties. You will join a collaborative, inclusive culture where your strengths have room to grow and your ideas can drive real impact. Step into a role where you can contribute to our shared success through meaningful work. We are actively hiring for a Cyber Threat Intelligence Analyst - Remote Your Role: We are seeking an experienced Cyber Threat Intelligence (CTI) Analyst to help mature the CSAA CTI program. This hands‑on role focuses on operationalizing the Threat Intelligence Platform (TIP), tracking priority threats, and delivering actionable, detection‑driven intelligence to security teams and leadership. The ideal person is a well‑rounded security professional who is comfortable working across teams, proactively identifying risk, and translating intelligence into prevention, detection, and response actions. Your Work: The CSAA Cyber Threat Intelligence Team is responsible for identifying, analyzing, and tracking cyber threats that may impact the organization. We collect intelligence from a wide range of internal and external sources and use that information to understand threat actors, campaigns, vulnerabilities, and attacker tradecraft relevant to our environment. The successful candidate will be responsible for analyzing and contextualizing threat intelligence, identifying potential risks, and supporting security operations through actionable insights. They will help improve insight into emerging threats, support investigative efforts, and contribute to the continued development and maturity of the CTI program. Monitor and analyze intelligence from commercial, industry, and OSINT sources to track threat actors, campaigns, and vulnerabilities, and assess their relevance, impact, and risk to the organization Maintain and use Threat Intelligence Platforms (TIP) and related tools to support intelligence operations, including ingestion, enrichment, tagging, and data quality Integrate intelligence across security tools (SIEM, SOAR, case management) to support operations Collect, enrich, and manage actionable IOCs to drive detection, blocking, and mitigation efforts across security operations Provide real‑time intelligence context during investigations and incidents (e.g., adversary behavior, infrastructure, objectives) Analyze vulnerability intelligence, including KEV listings and active exploitation trends, to support risk‑based vulnerability prioritization Respond to ad hoc and time‑sensitive intelligence requests from stakeholders Support threat hunting by developing indicators, behaviors, and hypotheses Produce and deliver intelligence reports and briefings for technical and non‑technical audiences Improve intelligence workflows, intake processes, RFIs, and documentation Required Experience, Education and Skills 6+ years of experience in Cyber Threat Intelligence, SOC, Incident Response, Threat Hunting, or related cybersecurity roles Bachelor's degree in computer science, Information Technology, or a related field, or an equivalent combination of education and experience Deep experience operating and optimizing industry leading Threat Intelligence Platforms (TIPs) Proven experience leveraging commercial threat intelligence providers such as Flashpoint, Recorded Future, Intel 471, ZeroFox, or comparable services to support operational intelligence requirements Strong mastery of the intelligence lifecycle, with demonstrated ability to operationalize intelligence from collection through dissemination and action Advanced worki
Your Match
How well this role fits your profile.
Company Intel
What employees say
Worked at aaaie? Share your experience