Intelligence Lead Analyst, Advanced Analytics and Cyber OSINT

Citi

Confirmed live yesterday High trust
Remote

Quick summary

Work type
Remote
Location
Charlotte, NC
Salary
$117,440–$176,160 / yr
Posted
16 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $158k
This role $147k
$108k most similar roles pay here $204k

This role pays less than 64% of similar roles. Most pay $131,000–$185,000 — the shaded band above. At the midpoint, this role pays about $147k versus about $158k for comparable roles.

Based on 239 similar postings.

Employer

About Citi

Citi is one of the world’s most trusted financial institutions, proudly serving millions of customers across the United States.

Citi currently has 256 open roles on FindRole.

Listed pay typically runs $140,080–$210,120 across 238 roles with salary data.

Most-posted roles

View all roles at Citi

At a glance

TL;DR · Intelligence Lead Analyst, Advanced Analytics and Cyber OSINT

The CSIS Intelligence Lead Analyst - Advanced Analytics and Cyber OSINT is a senior-level role within the CSIS Advanced Analytics and Cyber OSINT program. You will be responsible for collecting and analyzing indicators of compromise and tactics, techniques, and procedures while maintaining link analysis frameworks. The core mission involves leveraging advanced OSINT tradecraft to identify and neutralize threats related to financial crime, cyber-enabled fraud, and high-risk security events. Day-to-day tasks include developing in-house tools to automate intelligence collection and processing using Python, PowerShell, or Bash. You will utilize the MITRE ATT&CK framework and platforms like Recorded Future, Mandiant Advantage, ThreatConnect, MISP, or OpenCTI. Additionally, you will perform infrastructure pivoting, dark web monitoring, and network forensics while utilizing link analysis tools such as Palantir, Maltego, and i2 Analyst's Notebook to support complex investigations.

What you'll do

  • Fulfill cyber OSINT requests by applying advanced analysis techniques to surface actionable intelligence.
  • Design, implement, and maintain in-house solutions for collecting and processing open source data.
  • Automate intelligence collection capabilities using existing link analysis frameworks and custom scripts.
  • Triage, process, and analyze intelligence alerts, reports, and briefings using disciplinary knowledge.
  • Identify and evaluate alternative solution providers to address gaps in the intelligence posture.
  • Engage in liaison activities with law enforcement, industry partners, and information sharing communities.
  • Mentor and coach new team members on intelligence analysis and technical capabilities.

What we're looking for

  • 6-10 years of relevant experience.
  • Bachelor's degree or equivalent experience; Master's degree in a STEM field preferred.
  • Advanced OSINT tradecraft including dark web monitoring, social media intelligence, and infrastructure pivoting.
  • Proficiency in the MITRE ATT&CK framework for mapping adversary TTPs and building hunt hypotheses.
  • Experience with scripting and automation languages including Python, PowerShell, and Bash.
  • Hands-on experience with Threat Intelligence Platforms such as Recorded Future, Mandiant Advantage, ThreatConnect, MISP, or OpenCTI.
  • Experience with link analysis platforms like Palantir, Maltego, or i2 Analyst's Notebook to build custom extractors and automation workflows.
  • Relevant certifications such as CREST CCTIM, Recorded Future Certified Analyst, CISSP, CEH, or OSCP (preferred).

More like this

Similar roles

Cyber Threat Intelligence Analyst III

Leidos

Washington, DC +2 2 days ago
Cyber Threat Intelligence Cyber Kill Chain Diamond Model Splunk Analyst1 Python Bash PowerShell C++ CrowdStrike Falcon Tanium Proofpoint TAP Zscaler Malware Analysis Incident Response Threat Hunting Forensics XML HTML
8+ yrs exp

Cyber Threat Intelligence Analyst

Leidos

Washington, DC 59 days ago $107,900$195,050
Cyber Threat Intelligence MITRE ATT&CK Threat Intelligence Platforms (TIP Python PowerShell SIEM SOAR Firewalls IDS/IPS AWS Azure O365 KQL Elastic DSL SPL Cyber Kill Chain Diamond Model Data Correlation
8+ yrs exp Hybrid

Counterintelligence Analyst Lead

Anduril Industries

Costa Mesa, CA 88 days ago $129,000$171,000
Counterintelligence Intelligence Analysis Risk Management Insider Threat Threat Intelligence Security Clearance Case Studies Research Briefing analytic s
8+ yrs exp

Cyber Intelligence Fusion Analyst

Leidos

Alexandria, VA 8 days ago $107,900$195,050
SIEM EDR MITRE ATT&CK Cyber Kill Chain Splunk Microsoft Sentinel Microsoft Defender for Endpoint Wireshark Python PowerShell SQL KQL SPL Lucene Linux Unix PCAP NetFlow OSINT Cyber Threat Intelligence Incident Response Threat Hunting
8+ yrs exp