Cyber Threat Intelligence Analyst
On-siteWarren, Michigan, United States
Job Summary
Monitor, triage, and analyze threat activity and emerging vulnerabilities relevant to GM's IT, OT, and connected-vehicle environments, then produce actionable intelligence products like bulletins and advisories tailored to technical defenders and executives. Maintain and enrich indicators of compromise and threat-actor profiles while ingesting, normalizing, and curating data from ISACs, government partners, and commercial feeds using MISP and SIEM platforms. Provide time-sensitive intelligence support during active incidents and complete executive requests for information with confidence-rated assessments. Collaborate with Cyber Defense, Product Cybersecurity, and Manufacturing teams to align intelligence to priority risks and map adversary tactics to MITRE ATT&CK frameworks.
Required Qualifications
- 2+ years of experience in cyber threat intelligence, security operations, incident response, threat hunting, or a related cybersecurity discipline
- Working knowledge of the threat-intelligence lifecycle, indicators of compromise, and adversary TTPs, with familiarity with frameworks such as MITRE ATT&CK and the Diamond Model
- Ability to analyze security and threat data, correlate across sources, and communicate findings clearly to both technical and non-technical audiences
- Hands-on experience with threat-intelligence and detection tooling (e.g., threat-intelligence platforms such as MISP, SIEM, EDR/NDR) and open-source research techniques
- Understanding of common attacker techniques, malware behavior, phishing and credential-theft campaigns, and vulnerability and CVE/CVSS concepts
- Strong written and verbal communication skills, including the ability to produce concise intelligence products and time-sensitive assessments under deadline
- Bachelor's degree in Information Security, Computer Science, Information Systems, or equivalent practical experience
Desired Qualifications
- Experience supporting intelligence for OT/manufacturing (ICS, PLCs, plant-floor systems) or connected-vehicle and embedded environments
- Familiarity with ISAC participation (e.g., Auto-ISAC), law enforcement, or government intelligence-sharing communities
- Hands-on scripting experience (Python, PowerShell, KQL, or similar) to enrich indicators and automate investigative and reporting workflows
- Experience with clear- and dark-web monitoring, brand/impersonation abuse, employment-fraud investigations, or attribution of online personas
- Exposure to cloud environments (Azure, AWS, GCP) and integrating intelligence into cloud-native detection tooling
- Relevant certifications (e.g., GCTI, GCIH, GCFA, Security+, or equivalent)
- Prior experience in the automotive industry or a similarly complex, deadline-driven, and regulated field
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.