Cyber Threat Intelligence Analyst
State of Iowa
Only applicants who meet the Minimum Qualification Requirements and meet all selective requirements (listed below) will be placed on the eligible list. The Department of Management’s Division of Information Technology (DoIT) is seeking a senior-level Information Technology Specialist 5 (ITS5) – Cyber Threat Intelligence Analyst to serve as the authoritative intelligence resource supporting the Security Operations Center (SOC). This role collects, reviews, and analyzes intelligence data to identify threats targeting state and local government environments and transforms that information into actionable outcomes for SOC analysts, threat hunters, engineering teams, GRC, and leadership. The analyst develops and maintains Priority Intelligence Requirements (PIRs), assesses cyber risks, identifies adversary tactics, and motives, and ensures intelligence is aligned to state security objectives. The role leverages CTI platforms, OSINT sources, and structured analytic methodologies to produce accurate and timely intelligence reports. It also coordinates intelligence exchanges with external partners including CISA and peer government entities. This ITS5 position requires deep technical understanding, high integrity, and the ability to communicate complex intelligence to diverse audiences. What You Will Do Collect, maintain, and enrich intelligence data from internal telemetry, OSINT, commercial intel feeds, third-party reporting, and government partners. Correlate external threats with SOC alerting and state-specific vulnerabilities. Analyze cyber threat data to assess likelihood, impact, and relevance to state and local government. Identify threat actor TTPs, campaigns, emerging vulnerabilities, and exploitation trends. Produce tactical, operational, and strategic reports for diverse stakeholder groups. Develop, maintain, and refine PIRs aligned to evolving state risks. Manage intelligence workflows including collection planning, source evaluation, assessment documentation, and dissemination tracking. Translate CTI findings into actionable activities including detection recommendations, risk prioritization, threat hunting leads, vulnerability context, and architecture hardening actions. Support incident response as an intelligence subject-matter expert. Coordinate with CISA, law enforcement, and peer government agencies to exchange intelligence, validate trends, and support joint defensive efforts. Maintain and optimize CTI platforms, automation pipelines, and enrichment tools. Mentor SOC team members on intelligence concepts, frameworks, and analytic tradecraft. Present intelligence briefings to technical and non-technical audiences in a clear, concise manner. Document analytic methods, assumptions, and findings following best practices and structured analytic techniques. What We Are Seeking Cyber Threat Intelligence lifecycle management (PIR development, collection, analysis, dissemination) Strong knowledge of threat actor motivations, targets, behaviors, and TTPs Proficiency with CTI platforms, malware/trend research tools, enrichment feeds, and OSINT techniques In-depth understanding of MITRE ATT&CK, attack surface concepts, incident response, and vulnerability prioritization Ability to translate intelligence into operational actions, detections, and risk-driven recommendations Excellent communication, presentation, and technical writing skills Strong problem-solving, critical-thinking, and independent decision-making ability Five or more years of experience in cyber threat intelligence, cyber defense analytics, or related field Strong understanding of cybersecurity frameworks (MITRE ATT&CK, Kill Chain, Diamond Model) Demonstrated knowledge of attack vectors, penetration methods, and defensive countermeasures Experience with OSINT, intel feeds, CTI platforms, and log or alert correlation Excellent problem-solving, writing, briefing, and documentation skills Ability to work independently with minimal supervision and in a multidisciplinary team Strong integrity, judgment, and professional conduct with sensitive information Preferred Certifications CISSP, CISA, GSEC, or related cyber/intelligence credentials What We Offer Flexible work environment Iowa Public Employees' Retirement System (IPERS) Health, dental, and vision insurance Generous vacation, sick leave, and paid holidays Life and disability insurance Retirement savings options (RIC) Flexible Spending Accounts Why Work with Us? At the Iowa Department of Management (DOM), we help government agencies across the state perform at their best by managing financial resources, technology, and information. Our mission is rooted in service—we provide efficient, innovative, and strategic solutions that empower agencies to fulfill their goals. We’re guided by four core values: Integrity– We act with honesty and accountability. Teamwork– We collaborate to achieve shared success. Service– We are committed to excellence in public service. Partnership – We build strong relationships to drive results. Working Arrangement This position occasionally requires onsite work in Des Moines, IA. Employees meeting all expectations of their work responsibilities may request fully remote work and develop a hybrid/remote schedule collaboratively with their manager. Please note, candidates for this position must reside in the state of Iowa at the time of starting the role. Background Check Requirements After a conditional offer of employment has been made, and as the final step in the hiring process, candidates for this position will be subject to a background investigation, which may include but may not be limited to a verification of a candidate’s education, previous employment/work history, contact of personal references, motor vehicle records, and a criminal history check (including through Federal, State, or Local criminal justice agencies). Information gathered as part of such background investigation will be treated as confidential to the extent permitted by Iowa Code section 22.7, 8B.4A, and other applicable laws, rules, and regulations; provided that, to the extent permitted by applicable law, such information shall be available to candidates upon request. E-Verify and Right to Work The State of Iowa participates in E-Verify, a federal program that helps employers confirm the employment eligibility of all newly hired employees. Within the required timeframe, new hires will be verified through the E-Verify system to ensure authorization to work in the United States. The State of Iowa also complies with the Federal Right to Work laws, which protect employees’ rights to work without being required to join a labor organization. For more information, please visit 990 Cyber Security Planning: A minimum of 18 months of full-time work experience in cyber security planning at a professional level that included the following major functions: participating in and leading a company-/agency-wide cyber security planning program including the identification of cyber security risks, development of prevention and response plans to minimize cyber-attack damages including mass care and consequences management, and the development of continuation of business operation plans; participating in national cyber security planning initiatives and exercises; responding to and participating in the recovery work from cyber security incidents; and working across governments, private sectors, and non-profit organizations collaboratively on cyber security planning activities and plans for response. AND 980 Strategic Planning: 6 months’ experience, 12 semester hours, or a combination of both. Generally, an administrative position (mid to upper level of the management team) is assigned this as one function of their overall job. However, there are some specialists who deal only in strategic planning. Some colleges and universities may now carry this as a major or area of emphasis as part of their business administration or public policy programs. For experience to count, the applicant must have had the responsibility either for coordinating or developing the organization's strategic plan. Sometimes an administrative assistanttype is responsible for a lower level of coordination, i.e., distributing information to managers, collecting what they develop, and putting it into one document; that is not what is sought here. This has to be experience to the point that the individual knows the following: What a good strategic plan looks like How to prepare a plan How to monitor progress and ancillary planning How to speak knowledgably for the organization about the plan AND 717 Security Administration: 6 months’ experience, 12 semester hours, or a combination of both in building and maintaining skillset and knowledge base for security issues that impact information technology systems. Applicants may refer to themselves as Security Administrator. System Administrator is not the same. AND 727 Risk Assessment: 6 months’ experience, 12 semester hours, or a combination of both in analyzing and identifying risks and the corresponding potential impact to information and information technology systems. Applicants must meet at least one of the following minimum requirements to qualify for positions in this job classification: 1) Graduation from an accredited four-year college or university with a degree in any field, and experience equal to three years of full-time work in application development and database management, business analysis, systems and network administration, technical training and reporting, IT vendor and purchasing management, IT project management, IT product management, system testing and quality assurance, mainframe and platform administration, and/or information technology security. 2) Graduation from an accredited four-year college or university with a degree in computer science, computer applications, software engineering, computer engineering, management information systems, business analytics, or cyber security, and experience equal to two years of full-time work in application development and database management, business analysis, systems and network administration, technical training and reporting, IT vendor and purchasing management, IT project management, IT product management, system testing and quality assurance, mainframe and platform administration, and/or information technology security. 3) All of the following (a and b): a. Three years of full-time work experience in application development and database management, business analysis, systems and network administration, technical training and reporting, IT vendor and purchasing management, IT project management, IT product management, system testing and quality assurance, mainframe and platform administration, and/or information technology security; and b. A total of four years of education and/or full-time experience (as described in part a), where thirty semester hours of accredited college or university coursework in any field equals one year of full-time experience. 4) All of the following (a and b): a. Five years of full-time work experience in application development and database management, business analysis, systems and network administration, technical training and reporting, IT vendor and purchasing management, IT project management, IT product management, system testing and quality assurance, mainframe and platform administration, and/or information technology security; and b. Either of the following: i. Certification from an authorized educational institution/major computer or software producer in one or more of the specialty areas listed in part a; or ii. Eighteen semester hours from an accredited college or university in one or more of the specialty areas listed in part a. 5) Current, continuous experience in the state executive branch that includes six months of full-time work as an Information Technology Specialist 4. #J-18808-Ljbffr
- ...The Iowa Department of Management, Division of Information Technology, is seeking a senior ITS5 Cyber Threat Intelligence Analyst to serve as the authority on intelligence for the SOC. You will collect, analyze, and transform intelligence into actionable outcomes for SOC...Cyber
- ...tools. Respond to real-time security incidents and supports activities for response. Act as a liaison between the threat intelligence teams and the analyst teams to coordinate on emerging threats to the BHE networks.MidAmerican Energy Company, a Midwest utility, provides...CyberWork experience placementLocal areaImmediate start
$132.23k - $176.31k
...scale discovery of evolving malicious threats, provide mission-relevant intelligence, and support mitigations on large... ...detection. Work with cyber operators, when requested, to conduct... ...repeatable workflows that combine analyst expertise, automation, and AI-assisted...CyberFull timeTemporary workWork experience placementWork at officeRemote work- ...Senior Information Security AnalystAs a Senior Information Security Analyst, you will be a key member of our security team, responsible for safeguarding our organization's systems and data from cyber threats. Your primary focus will be assessing security risks, developing...CyberContract workWork experience placement
- ...Senior Information Security AnalystAs a Senior Information Security Analyst, you will play a vital role in safeguarding our systems, data, and business operations from evolving cyber threats. In this position, you will assess security risks, design and implement effective...CyberWork experience placement
- ...(FBI) seeks qualified individuals to become special agents. This position directly supports national security by investigating cyber threats, terrorism, fraud, and other crimes, using your technical and analytical background. Candidates must be a U.S. citizen, able to...CyberWork at office
- ...the Principal Advisor will drive thought leadership and inspired cyber security solutions powered by our ecosystem of people, products,... ...responsive communicationThorough understanding of the current threat landscape, vulnerabilities, and defensive controls as it pertains...CyberFull timeLocal areaRemote workWork from home
$98k - $122k
...security measures to protect LCS computer networks and systems from cyber-attacks.This position reports to the VP, Information Technology.... ...activity, and system-generated events to identify potential threats impacting LCS communities, corporate operations, or resident information...CyberFor contractors- ...technology solutions, aligning with national standards and the Iowa Cyber Strategy. The incumbent will lead scalable security controls,... ..., and drive RMF/NIST alignment across agencies, with a focus on threat modeling and secure design principles. #J-18808-Ljbffr...Cyber
- ...validating, remediating, and governing cyber exposures across Berkshire Hathaway Energy... ....The director advances Continuous Threat Exposure Management (CTEM), vulnerability... ...based vulnerability prioritization, threat intelligence, exploitability analysis, remediation governance...CyberWork experience placementLocal area
$151.4k - $311k
...security capabilities across Artificial Intelligence, Microsegmentation, Infrastructure & Cloud... ...in DT - US deliver services including: Cyber SecurityTechnology SupportTechnology &... ...program that adapts to a rapidly changing threat landscape, changes in business...CyberFor contractors$127.2k - $246.9k
...CI/CD pipelines (Detection-as-Code)Collaborate closely with Threat Intelligence, SOC, and Incident Response teams to map detections and automated... ...of logs, metrics, and tracesSupport and streamline Cyber Operations by actively automating repetitive tasks, threat intelligence...CyberH1bLocal area$118.7k - $243.7k
...in DT - US deliver services including: Cyber SecurityTechnology SupportTechnology & InfrastructureApplicationsRelationship... ...that adapts to a rapidly changing threat landscape, changes in business... .... Using situational awareness, threat intelligence, and building a security culture across...Cyber- ...Responsibilities include: Conducting complex criminal investigations into financial crimes, including counterfeiting, cyber fraud, and other threats to the financial infrastructure of the United States. Providing physical protection for the President, Vice...Cyber
- ...than the basics to create an inclusive and dynamic work environment at our various locations.Purpose:The Senior Competitive Intelligence Analyst plays a key role within Athene’s Retail Product Development team, leading the Competitive Intelligence function supporting our...Full timeWork at officeLocal area
- ...Description As a Senior Information Security Analyst, you will play a vital role in... ...and business operations from evolving cyber threats. In this position, you will assess security... ...speed. While we use artificial intelligence tools to enhance our initial screening...CyberWork experience placementLocal area
$81.48k - $96.76k
...succeed. The Information Security Analyst II is responsible for... ...Information Security team, perform threat detection, incident... ...attack (IOAs). Monitor threat intelligence sources and recommend defensive... ...events. Understanding of the Cyber Kill Chain, MITRE ATT&CK Framework...CyberLocal area$55.8k - $100.8k
...Participant Experience Consulting team as a Senior Education Analyst ! This is an opportunity to drive positive participant outcomes... ...Most Recently Posted Date 8/11/2026 Principal uses artificial intelligence tools to assist in reviewing and evaluating job applications,...Hourly payPermanent employmentTemporary workWork experience placementH1bWork at officeRemote workFlexible hours$102.8k - $176k
...Account Manager is responsible for developing cyber and risk consulting accounts through the... ...effectiveness, regulatory pressure, threat exposure, control gaps, audit findings,... ...revenue. Cyber, Risk & Regulatory Intelligence Develop deep industry, cyber, and risk expertise...CyberFull timeContract workWork experience placementInternshipWork at officeLocal area- ...member firm security representatives to plan and execute regional cyber adoption campaignsAid the Regional Security Hub & RISO and... ...regular basis and reflects the latest security standards, trends and threats; structure and maintain this program to be long term.Act with...CyberH1bLocal area
- ...Fortigate Firewall experience3+ years of experience in network security infrastructure (includes firewall, intrusion detection, and cyber threat)Desired Qualifications: Splunk experienceFamiliarity with AI and automation toolsKnowledge and understanding of network...CyberFull timeWork experience placementAfternoon shift
- ...broad, current experience across Cisco enterprise networking and network security and helps clients translate business requirements, cyber risk, and infrastructure priorities into practical architecture strategies.The Principal Advisor leads technical discovery and...CyberFull timeLocal areaRemote workWork from home
$130k - $160k
...sector organizations design, build and scale intelligent AI, digital, cybersecurity, cloud and... ..., security governance, networks, protocols, threat management, change management, vulnerability management and overall cyber security best practices. Develop enablement...CyberFull timeTemporary workFlexible hoursShift work- ...Industry Financial Services Type Privately Held Founded 1892 Employees 501-1000 Categories Crowdfunding Cyber Security Financial Services Information Technology Insurance Funds Worker's Compensation Finance Funds Fund Families...Cyber
- ...Iowa’s enterprise security architecture. This position is critical to safeguarding state systems and data by embedding security into technology solutions, aligning with national standards, and advancing the Iowa Cyber Strategy and CyberGUARD framework. #J-18808-Ljbffr...Cyber
$153k - $297k
...join our team.KPMG is currently seeking an Associate Director, Cyber Architecture & Engineering to join our Enterprise Security Services... ...'s goals and objectives, and effectively addresses the evolving threats to the firm's environment and dataServe as an internal senior...CyberH1bLocal area- ...strategic and technical advice, and we have expertise in areas covering Artificial Intelligence, Cloud Migration, Custom Software Development, Data Analytics Infrastructure & Cloud Solutions, Cyber Security Services, etc. We make reasonable accommodations for clients and...Cyber
- ...Industry Financial Services Type Privately Held Founded 1892 Employees 501-1000 Categories Crowdfunding Cyber Security Financial Services Information Technology Insurance Funds Worker's Compensation Finance Funds Fund Families...Cyber
- ...cybersecurity risk management, security operations, threat detection, vulnerability management, and... ...Ensure proactive defense against cyber threats and continuously improve the... ...defense capabilities through threat intelligence, automation, and operational maturity initiatives...CyberTemporary workRemote work
- ...cyberattacks, detecting and responding to the unknown, or running an entire security operations center, we will help companies build cyber resilience to grow with confidence. Our team of the security sector's brightest people uses the coolest tech to out-hack the hackers...CyberWork experience placementLive inWork at officeLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Threat Intelligence Analyst. Be the first to apply!
- cyber Des Moines, IA
- private intelligence Des Moines, IA
- manager competitive intelligence Des Moines, IA
- intelligence Des Moines, IA
- military intelligence Des Moines, IA
- signals intelligence Des Moines, IA
- artificial intelligence - machine learning intern Des Moines, IA
- cyber security analyst no experience
- cyber soc analyst
- junior cyber security analyst



