ForgeApply · Job listing
Senior Threat Intelligence Analyst
Expel
Apply in about a minute — without sacrificing quality.
ForgeApply autofills this application and tailors your resume to this exact posting. You review everything before it's sent. Free trial, no card required.
About this role
*]:pointer-events-auto R6Vx5W_threadScrollVars scroll-mb-[calc(var(--scroll-root-safe-area-inset-bottom,0px)+var(--thread-response-height))] scroll-mt-[calc(var(--header-height)+min(200px,max(70px,20svh)))]" data-turn-id="request-695dd903-083c-832d-b6bc-b9037604845c-13" data-turn-id-container="request-695dd903-083c-832d-b6bc-b9037604845c-13" data-testid="conversation-turn-734" data-turn="assistant">
You’re the kind of person who sees a new threat campaign and immediately wants to know how it works, who it’s targeting, and what defenders can do about it.
You know strong threat intelligence is more than collecting indicators or summarizing external reports. It means connecting intelligence from multiple sources, understanding how threat actors operate, and turning that information into something useful for analysts, detection engineers, customers, and business leaders.
You enjoy digging into real incidents, identifying root causes and attacker behavior, and helping others understand what matters. You’re equally comfortable working through IOCs and TTPs with security practitioners or translating the same findings into clear guidance for a less technical audience.
At Expel, you’ll serve as a senior contributor and subject matter expert helping mature our threat intelligence capabilities. You’ll analyze threats observed across our Security Operations Center alongside external intelligence sources, help prioritize the intelligence that creates the greatest operational value, and partner with teams across the business to strengthen how we protect our customers.
Does that sound like the kind of work you’d love to own? We’d like to hear from you.
What Expel can do for you
• Give you direct exposure to real-world incidents and threat activity observed through our Managed Detection and Response service.
• Provide the opportunity to shape and mature Expel’s threat intelligence practices, tooling, and methodologies.
• Connect you with collaborative teams across the SOC, Threat Hunting, Detection Engineering, Product, Engineering, and Marketing.
• Give you a platform to share meaningful threat intelligence with customers, practitioners, and the broader security community.
• Surround you with curious security professionals who value thoughtful analysis, continuous learning, and practical outcomes.
• Give you the opportunity to mentor developing analysts and help raise the technical bar across the organization.
What you can do for Expel
• Monitor and curate intelligence from open-source reporting, dark web communities, proprietary feeds, internal incidents, and other relevant sources.
• Evaluate threat intelligence for credibility, relevance, likelihood, and operational value before translating it into actionable guidance.
• Review security incidents identified through Expel’s MDR service to uncover root causes, attacker TTPs, and exploited vulnerabilities.
• Use internal incident data alongside external intelligence to identify emerging patterns and understand which threats are actively affecting customers.
• Produce clear threat intelligence reports containing IOCs, TTPs, potential impact, and recommended mitigation strategies.
• Communicate findings effectively to technical practitioners, customers, executive audiences, and cross-functional stakeholders.
• Keep Expel’s curated intelligence current by regularly processing internal incidents and external feeds through a Threat Intelligence Platform.
• Partner closely with SOC, Threat Hunting, and Detection Engineering teams to support the tactical application of intelligence.
• Research new technologies, techniques, and data sources that could strengthen Expel’s threat intelligence capabilities.
• Participate in intelligence-sharing communities and help build a positive reputation for Expel within the broader threat intelligence ecosystem.
• Support strategic customer conversations and inquiries involving advanced threats and emerging attacker behavior.
• Improve the processes, tools, and methodologies used to collect, assess, distribute, and operationalize threat intelligence.
• Mentor junior and staff-level colleagues while serving as a trusted subject matter expert during complex incident reviews.
What you should bring with you
• Approximately 5 to 8 years of professional experience across threat intelligence, security operations, incident response, detection engineering, or a closely related discipline.
• A strong understanding of common cyberattack vectors and the tools, techniques, and procedures used by threat actors.
• Experience performing detailed incident reviews to identify root causes, exploited vulnerabilities, and attacker behavior.
• The ability to evaluate intelligence from multiple sources and determine what is credible, relevant, and actionable.
• Familiarity with malware analysis reports generated by automated sandboxing tools, along with the ability to perform basic manual inspection.
• Strong technical writing skills and the ability to adapt your communication for technical, executive, customer, and public audiences.
• Strong capability in at least one technical area such as data analysis, network protocols, operating systems, security controls, or programming.
• Experience mentoring colleagues and sharing technical expertise in a constructive, collaborative way.
• Strong analytical, project-management, and time-management skills.
• The ability to manage multiple priorities while maintaining sound judgment and attention to detail.
• Confidence partnering across Marketing, Engineering, Product, SOC, Threat Hunting, and Detection Engineering teams.
• Clear written and verbal communication skills, including the ability to navigate disagreement and technical ambiguity constructively.
Additional notes
While the full salary band reflects our long-term compensation framework, we're primarily targeting candidates between $135,000 and $170,000 based on experience, skills, internal equity, and market
Ready to apply to Expel?
Apply in about a minuteSimilar jobs
- Senior Threat Detection Engineer - Intelligence — Miro · Austin
- Senior Threat Detection Engineer - Intelligence — Realtimeboardglobal · Austin, US
- Senior Insider Threat Analyst — Coinbase · Remote
- Senior Threat Intelligence Specialist I, Protective and Geopolitical Intel — Coreweave · Remote
- Senior Threat Engineer — Coalition · Any location, United States
- Senior Threat Hunter — M9solutions · Remote
- Associate Principal Threat Intelligence Analyst — Rockstargames · Carlsbad, California, United States
- Associate Principal Threat Intelligence Analyst — Rockstargames · Andover, Massachusetts, United States
More like this: More jobs at Expel · Browse all jobs