Senior Threat Intelligence Analyst

Expel · Remote · Data

Posted 2026-08-05

Apply for this role →

*]:pointer-events-auto R6Vx5W_threadScrollVars scroll-mb-[calc(var(--scroll-root-safe-area-inset-bottom,0px)+var(--thread-response-height))] scroll-mt-[calc(var(--header-height)+min(200px,max(70px,20svh)))]" data-turn-id="request-695dd903-083c-832d-b6bc-b9037604845c-13" data-turn-id-container="request-695dd903-083c-832d-b6bc-b9037604845c-13" data-testid="conversation-turn-734" data-turn="assistant">

You’re the kind of person who sees a new threat campaign and immediately wants to know how it works, who it’s targeting, and what defenders can do about it.

You know strong threat intelligence is more than collecting indicators or summarizing external reports. It means connecting intelligence from multiple sources, understanding how threat actors operate, and turning that information into something useful for analysts, detection engineers, customers, and business leaders.

You enjoy digging into real incidents, identifying root causes and attacker behavior, and helping others understand what matters. You’re equally comfortable working through IOCs and TTPs with security practitioners or translating the same findings into clear guidance for a less technical audience.

At Expel, you’ll serve as a senior contributor and subject matter expert helping mature our threat intelligence capabilities. You’ll analyze threats observed across our Security Operations Center alongside external intelligence sources, help prioritize the intelligence that creates the greatest operational value, and partner with teams across the business to strengthen how we protect our customers.

Does that sound like the kind of work you’d love to own? We’d like to hear from you.

What Expel can do for you

Give you direct exposure to real-world incidents and threat activity observed through our Managed Detection and Response service.

Provide the opportunity to shape and mature Expel’s threat intelligence practices, tooling, and methodologies.

Connect you with collaborative teams across the SOC, Threat Hunting, Detection Engineering, Product, Engineering, and Marketing.

Give you a platform to share meaningful threat intelligence with customers, practitioners, and the broader security community.

Surround you with curious security professionals who value thoughtful analysis, continuous learning, and practical outcomes.

Give you the opportunity to mentor developing analysts and help raise the technical bar across the organization.

What you can do for Expel

Monitor and curate intelligence from open-source reporting, dark web communities, proprietary feeds, internal incidents, and other relevant sources.

Evaluate threat intelligence for credibility, relevance, likelihood, and operational value before translating it into actionable guidance.

Review security incidents identified through Expel’s MDR service to uncover root causes, attacker TTPs, and exploited vulnerabilities.

Use internal incident data alongside external intelligence to identify emerging patterns and understand which threats are actively affecting customers.

Produce clear threat intelligence reports containing IOCs, TTPs, potential impact, and recommended mitigation strategies.

Communicate findings effectively to technical practitioners, customers, executive audiences, and cross-functional stakeholders.

Keep Expel’s curated intelligence current by regularly processing internal incidents and external feeds through a Threat Intelligence Platform.

Partner closely with SOC, Threat Hunting, and Detection Engineering teams to support the tactical application of intelligence.

Research new technologies, techniques, and data sources that could strengthen Expel’s threat intelligence capabilities.

Participate in intelligence-sharing communities and help build a positive reputation for Expel within the broader threat intelligence ecosystem.

Support strategic customer conversations and inquiries involving advanced threats and emerging attacker behavior.

Improve the processes, tools, and methodologies used to collect, assess, distribute, and operationalize threat intelligence.

Mentor junior and staff-level colleagues while serving as a trusted subject matter expert during complex incident reviews.

What you should bring with you

Approximately 5 to 8 years of professional experience across threat intelligence, security operations, incident response, detection engineering, or a closely related discipline.

A strong understanding of common cyberattack vectors and the tools, techniques, and procedures used by threat actors.

Experience performing detailed incident reviews to identify root causes, exploited vulnerabilities, and attacker behavior.

The ability to evaluate intelligence from multiple sources and determine what is credible, relevant, and actionable.

Familiarity with malware analysis reports generated by automated sandboxing tools, along with the ability to perform basic manual inspection.

Strong technical writing skills and the ability to adapt your communication for technical, executive, customer, and public audiences.

Strong capability in at least one technical area such as data analysis, network protocols, operating systems, security controls, or programming.

Experience mentoring colleagues and sharing technical expertise in a constructive, collaborative way.

Strong analytical, project-management, and time-management skills.

The ability to manage multiple priorities while maintaining sound judgment and attention to detail.

Confidence partnering across Marketing, Engineering, Product, SOC, Threat Hunting, and Detection Engineering teams.

Clear written and verbal communication skills, including the ability to navigate disagreement and technical ambiguity constructively.

Additional notes

While the full salary band reflects our long-term compensation framework, we're primarily targeting candidates between $135,000 and $170,000 based on experience, skills, internal equity, and market data. This role is also eligible for bonus and equity.

This is a fully remote position open to candidates residing in the United States.

Applicants must be authorized to work in the United States. The source job description does not specify whether immigration sponsorship is available, so that detail should be confirmed before posting.

Expel is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or disability.

We’ll ensure individuals with disabilities are provided reasonable accommodation throughout the application and interview process, while performing essential job functions, and when accessing employment benefits and privileges.

#LI-Remote

Salary Range

$126,500—$183,400 USD

Apply for this role →

← Back to all jobs