Intelligence Lead Analyst - OSINT Threat Hunting
Citigroup Inc
Intelligence Lead Analyst - OSINT Threat Hunting
Go beyond traditional analysis and become a proactive threat hunter at the heart of Citi's global security operations. The CSIS Advanced Analytics and Cyber OSINT program seeks a senior Intelligence Lead Analyst to design, lead, and mature our threat hunting capabilities. In this pivotal role, you will transform open-source information into actionable intelligence, safeguarding the assets, integrity, and reputation of Citi and its clients against emerging threats.
The Intelligence Lead Analyst (Open Source Intelligence - Threat Hunting) is a senior-level intelligence analyst position responsible for designing, leading, and maturing Citi's proactive threat hunting and cyber Open Source Intelligence (OSINT) capabilities. The role goes beyond reactive analysis: the incumbent will drive hypothesis-driven hunt operations across Citi's global enterprise environment, operationalize cyber threat intelligence into detection engineering, and serve as a subject matter expert on adversary tradecraft, tactics, techniques, and procedures (TTPs), and emerging threat actor campaigns targeting the financial sector. The role requires deep expertise in the cyber threat intelligence lifecycle, adversary emulation, and the ability to translate complex intelligence into actionable outcomes for Investigations, Security, and other stakeholders.
Responsibilities:
- Analyze regional threat data and determine a correlation if any, to existing intelligence requirements
- Monitor and research cyber threats with a direct or indirect impact to the Citi brand
- Research and identify malicious activity by performing post-mortem analysis on logs, traffic flows, and other activities
- Conduct intrusion analyses to ascertain the impact of an attack, and develop mitigation techniques for future attacks
- Evaluate networks and programs to assess potential weaknesses and points of entry
- Analyze and present to senior leadership discovered patterns to forecast future cyber-attacks and their potential impact
- Liaise with intelligence communities, law enforcement, industry partners, peer financial institutions, and information sharing communities
- Triage, process, analyze, and disseminate intelligence alerts, reports, and briefings
- Appropriately assess risk when business decisions are made, demonstrating particular consideration for the firm's reputation and safeguarding Citigroup, its clients and assets, by driving compliance with applicable laws, rules and regulations, adhering to Policy, applying sound ethical judgment regarding personal behavior, conduct and business practices, and escalating, managing and reporting control issues with transparency.
Qualifications:
- 6-10 years of relevant experience
- Should have a working knowledge in one or more of the following areas: Advanced Persistent Threat, Third Party Risks/Threats, Cybercrime, Extremist Groups and Cyber Terrorists, Hacktivism, Distributed Denial of Service attacks, Fraud, Malware, Mobile Threats
- Proven track record of operationalizing cyber threat intelligence — translating raw intelligence into detections, hunt packages, and risk-relevant reporting.
- Consistently demonstrates clear and concise written and verbal communication
- Proven influencing and relationship management skills
- Proven analytical skills
Education:
- Bachelor's degree/University degree or equivalent experience
- Master's degree preferred (Advanced degree preferred, ideally in Computer Science, Cybersecurity, Information Security, or a related STEM discipline)
- Additional valued certifications include: CREST CCTIM, Recorded Future Certified Analyst, CISSP, CEH, or OSCP.
Required Skills:
- Proficiency in the MITRE ATT&CK framework — mapping adversary TTPs, building hunt hypotheses, and driving detection coverage analysis.
- Hands-on experience with Threat Intelligence Platforms including Recorded Future, Mandiant Advantage, ThreatConnect, MISP, or OpenCTI.
- Experience with scripting and automation languages including Python, PowerShell, and Bash for intelligence collection, enrichment pipelines, and hunt tooling development.
- Advanced OSINT tradecraft including dark web monitoring, social media intelligence, infrastructure pivoting, and digital footprint analysis.
- Experience with link analysis platforms such as Palantir, Maltego, and i2 Analyst's Notebook, including building custom extractors, web scrapers, and automation workflows to support investigative and analytical tasks.
- Solid understanding of network forensics, log analysis, and reverse engineering in support of hunt operations.
- Working knowledge of malware analysis (static and dynamic) and adversary infrastructure analysis.
- Exceptional written and verbal communication skills with the ability to produce intelligence products for both technical and executive audiences, consistently demonstrating clarity, conciseness, and attention to detail.
- Proven influencing, relationship management, and analytical skills with a track record of driving outcomes across cross-functional teams.
This job description provides a high-level review of the types of work performed. Other job-related duties may be assigned as required.
- The Depository Trust & Clearing Corporation (DTCC) is hiring an Insider Threat Manager in Tampa, Florida, responsible for leading a team to proactively detect and prevent insider threats. You will provide technical direction and manage daily operations while aligning efforts...Suggested
- ...Threat And Risk Intelligence Analyst This position is contingent upon contract award. Position Summary: Upon award, the Threat and Risk Intelligence... ...Operations Expertise in open-source intelligence (OSINT) collection, analysis, and reporting methodologies Proficiency...SuggestedContract work
- CACI in Tampa, FL is seeking a Counter Threat Finance Analyst to identify and disrupt threat financing networks using FININT, OSINT, and multi-source intelligence. You will map networks, produce intelligence products, and inform operational planning through rigorous analytic...Suggested
$105.79k - $141.05k
...has an opening for a Lead Information Security Engineer... ...who will support threat hunting, investigation, and... ...relationships with internal intelligence teams, law enforcement... ...that combine analyst expertise, automation,... .... Experience using OSINT methods for investigation...SuggestedFull timeTemporary workWork experience placementRemote workWork from home- ...division of HII, is seeking an experienced All-Source Analyst in Tampa, Florida. This role supports intelligence operations focused on dismantling transnational... ...candidate will need a TS/SCI clearance, experience in threat network analysis, and proficiency in intelligence...Suggested
- ...Protective Intelligence & Threat Assessment Analyst This position is contingent upon contract award. Position Summary: Upon award, the Protective Intelligence & Threat Assessment Analyst will provide specialized protective intelligence and threat assessment support...Contract work
- ...risk-based mitigation strategies. The candidate will maintain knowledge of current and future SOF mission requirements and contribute to threat analysis and resource planning in a dynamic, mission-focused environment. #J-18808-Ljbffr QinetiQ US (formerly Avantus Federal)
- Booz Allen Hamilton is seeking a senior intelligence analyst to apply OSINT methods, open-source research, and social media analysis to deliver actionable... ...to aid planners, analysts, and decision-makers in threat and mission planning. #J-18808-Ljbffr Phase2 Technology
- ...CACI International Inc. in the United States is seeking a Counter Threat Finance Analyst to identify, analyze, and disrupt adversary financial networks, using FININT and multi-source intelligence to support OIE and IW mission objectives. You will produce intelligence products...
$105k - $111k
Amentum is seeking a professional for Threat Finance Intelligence analysis to support U.S. government efforts in identifying and disrupting financial networks associated with terrorism and crime. Responsibilities include providing intelligence analysis, facilitating cooperation...- A trusted government contracting partner in Tampa is seeking a Senior All-Source Intelligence Analyst to lead analytic teams and manage intelligence projects. This role involves producing strategic-level assessments and mentoring junior analysts while collaborating with...
$90.8k - $199.7k
...activities. Responsibilities Lead a team of all-source analysts to meet customer requirements for worldwide UxS threat technologies. Research,... ...author, and present technical intelligence products focused on UxS,... ...TAC, CIAWIRE, NSA PULSE, OSINT Analytical Framework....Worldwide$129.3k - $177.8k
...caring community(remote in location) The Lead Intelligence Data Architect serves as the subject... ...functional owner for how Humana's cyber threat intelligence is collected, organized, kept... ...it can be reliably referenced by both analysts and the AI-driven and automated systems...Full timeTemporary workWork at officeRemote workHome office- Vantor is looking for an experienced OSINT Collection Analyst based in Florida to support military operations and intelligence gathering. The successful candidate will leverage open-source intelligence methodologies to analyze diverse information sources and produce actionable...
$78k - $163.8k
Job Title: Operational Intelligence Analyst LeadJob Category: IntelligenceTime... ...of rapidly evolving global threats. Working across geographic and... ...team. Responsibilities: Lead the production and... ...of all-source intelligence, OSINT, socio-cultural analysis, behavioral...Full timeContract workWork experience placementLocal areaFlexible hours- Job TitleSr. Counter-Intelligence AnalystLocationTampa, FL 33621 US (Primary... ...a Sr. Counter-Intelligence Analyst to support a Federal... ...software tools to assess risks and threats to SOF and HUMINT activities,... ...correlating data, identifying leads, and producing analytical...Contract workFor contractors
- Booz Allen Hamilton is seeking an Open-Source Analyst, Lead in the United States. The role focuses on advanced OSINT, all-source intelligence methods, and social media analysis to produce insights shaping targeting support and operational understanding. The candidate will...
- ...Type Full-time Description Mission Intelligence Analyst The Ascendancy Group's Mission To be the unequaled provider... ...Environment (OIE) planning and operations by delivering threat assessments, target system analyses, and predictive...Full timeContract work
- ...Job Title: Law Enforcement Analyst Job Category: Consulting Time Type: Full time Minimum... ...partners stay ahead of rapidly evolving global threats. Working across geographic and... ...environments. Integrate law enforcement reporting, intelligence products, and open-source information...Full timeContract workWork experience placementLocal areaFlexible hours
$99k - $225k
Open-Source Analyst, LeadThe Opportunity: With all the... ..., it takes a skilled intelligence analyst to know how to... ...will use innovative OSINT collection techniques... ...ideological, and counter‑threat materials to identify... ...Experience developing or leading intelligence fusion...Full timeContract workPart timeWork at officeLocal areaRemote work- ...of special operations forces (SOF) and Intelligence Community focused technical, service, and... ...a full-time position integrating cyber threat intelligence into irregular and information... ...with operational planners, intelligence analysts, and cross-functional directorates...Full timeContract work
- ...Ingalls Industries is seeking an experienced All-Source Analyst in Tampa, Florida. This role focuses on supporting intelligence operations aligned with USSOUTHCOM's mission, requiring strong knowledge of threat networks and regional dynamics. The candidate will leverage...
- ...components, payloads, and associated media to support all-source intelligence production and target development. Apply advanced analytical... ...intelligence reports, assessments, and briefings on UAS/sUAS threats, including payload configurations, communication systems,...Contract work
$87.28k - $212.16k
...ProfessionalCompany: CitiWhy CitiCiti, the leading global bank, has... ....The AI Offensive Security Analyst is an operational role on a team... ...that can behave like insider threats. Frontier models can harvest... ...Testing, Artificial Intelligence (AI), Cybersecurity, Large Language...Full timeWork at officeFlexible hoursShift workWeekend work- Job TitleSenior Identity Intelligence Exploitation Cell (I2EC) Analyst SupportLocationTampa, FL 33621 US (Primary)CategoryIntelligenceJob TypeFull-TimeCareer LevelStaffEducationHigh School / GEDTravel-Security Clearance RequiredTS/SCIJob DescriptionPrescient Edge is seeking...Contract workTemporary workFor contractorsWorldwide
- ...Job Description Job Description Description: Acquisition Intelligence Analyst At Celestar, a B&A Company, we foster and embrace a... ...acquisition production process, to include validated online Lifecycle Threat Reports (VOLT), and create Critical Intelligence Parameters....Full timeWork at officeLocal area
$85k - $127.5k
...responsible for conducting all aspects of the intelligence analysis and project review functions... ...intelligence reports, bulletins, threat assessments, training decks, and programmatic... ...data in a clear and actionable manner. Lead and mentor intelligence officers, providing...Work at officeLocal areaWork from homeFlexible hours- ...Intelligence Lead Analyst Vice PresidentThe Intelligence Lead Analyst is a senior level professional responsible for driving efforts to prevent... ...intelligence requirements, strategic priorities, and emerging threat trends.Monitor and research fraud and scam threats with a...Contract work
- ...Draft, edit, review, and publish formal intelligence reports and assessments, including United... .... Coordinate with intelligence analysts, collection managers, and operational elements... ...of all-source intelligence assessments, threat reports, and operational summaries in support...Contract work
- ...SOS International LLC (SOSi) is seeking an All-Source Analyst to support our customer in McDill AFB, Florida. The role requires an... ...related experience. The analyst will produce current all-source intelligence analysis, assess geopolitical and security developments, and apply...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Intelligence Lead Analyst - OSINT Threat Hunting. Be the first to apply!
- intelligence analyst Tampa, FL
- all-source intelligence analyst Tampa, FL
- criminal intelligence analyst Tampa, FL
- senior intelligence analyst Tampa, FL
- competitive intelligence analyst Tampa, FL
- military intelligence officer Tampa, FL
- open source intelligence analyst Tampa, FL
- military intelligence analyst Tampa, FL
- military intelligence Tampa, FL
- intelligence Tampa, FL



