Threat Intelligence Analyst
United StatesJob Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
The Role
You'll use ZeroFox's patented technology to pull relevant signal out of noisy, high-volume data — from mainstream social platforms to deep and dark web forums — and turn it into intelligence that actually changes what a client does next. The work spans physical security threats, cyber risk, geopolitical developments, reputational exposure, and compliance concerns, often in the same week, sometimes in the same report.
This isn't queue-clearing. You'll research a threat, decide what's credible and what's noise, and write it up in a BLUF-first format a client's security team can act on without a follow-up call. You'll work daily security and incident alerts, support recurring intelligence deliverables, brief clients directly, and partner with Collection Management to keep the intelligence pipeline getting sharper — not just bigger.
In your first 90 days, you'd be expected to run point on at least one recurring client deliverable, complete ZTAC's onboarding certifications, and independently produce a BLUF-format report your manager signs off on without edits.
You'll thrive here if...
- You've done real OSINT and social media investigation work — 2–3 years of it — and know the difference between a lead and a rabbit hole
- You can hold four threat categories (physical, cyber, geopolitical, reputational) in your head at once without losing the thread on any of them
- You've written a BLUF-format report under deadline and had a client act on it the same day
- You're comfortable being the one who decides something is credible enough to escalate — nobody's rubber-stamping your judgment
- You're comfortable working the deep and dark web as part of the job
- You're comfortable briefing a customer directly, live
This probably isn't for you if...
- You want a fully scoped ticket queue where someone else has already decided what's relevant — this role requires deciding that yourself
- You've never had to defend why you called something credible, or not, to someone who disagreed
- You're looking for a single-domain specialty — this role moves across physical, cyber, and geopolitical risk, and narrow focus isn't the job
Requirements
2–3 years of OSINT and social media research experience, including executive threat assessments or investigations
Ability to judge the credibility, value, and relevance of information across sources — and say so clearly in writing
Strong written and oral communication skills; comfortable producing BLUF-style reports and briefing customers directly
Experience with at least one online investigative tool (Whois, Ping, Traceroute, or similar), plus proficiency in Google Suite
Working familiarity with surface web platforms, blogs, IRC, message boards, and deep/dark web environments
Benefits
- Comprehensive health, dental, and vision (Cigna)
- 401(k) with 3% match, 100% immediately vested — no cliff
- HSA with quarterly company contributions
- Company-paid disability and life insurance
- Generous time off
How would you rate this job post?
See what other professionals think about this role.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.