Cyber threat intelligence careers
Find out what you would actually say under questioning.
Reading about the Diamond Model and pivoting across it while an interviewer probes are different skills. Answer a real question now — graded against a vetted rubric, with the follow-up an interviewer would ask next. No account, no email.
- 36 vetted questions
- 6 career tracks
- 15 reference pages
Live question
Technical
Difficulty 3/5
In STIX, what is the difference between a cyber-observable object and an indicator? And what does TAXII do that STIX does not?
Graded on our own server. Your answer is not sent to a third-party AI provider, and it is only stored if you save your report.
Three things this site does
Each one is built to be genuinely useful on its own.
- Interview simulation, graded on our own server Pick a track and an interview type, answer real questions, and get scored across five dimensions — technical accuracy, framework fluency, analytical judgment, communication and practicality. Difficulty adapts as you go, and every answer gets the probing follow-up an interviewer would actually ask.
- CTI salary data, with the sample sizes shown An anonymous survey of what threat intelligence analysts are actually paid, broken down by role, region and seniority. Cells with too few responses are suppressed rather than padded out — 1 responses so far.
- How to become a CTI analyst The roadmap, the frameworks interviews test, and the tradecraft that separates intelligence from reporting — written to be used, including where each model breaks down.
Pick your track
Questions, difficulty and scoring expectations differ by seniority. Choose the one you are interviewing for.
- SOC Analyst moving into CTI You already triage alerts and understand detection. The gap is intelligence tradecraft: requirements, sourcing, structured analysis and writing for someone who is not in the SOC.
- Junior CTI Analyst First dedicated intelligence role. You run collection against defined requirements, enrich and triage indicators, map activity to ATT&CK, and draft reporting that a senior analyst edits.
- Cyber Threat Intelligence Analyst The core role. You own a collection area, produce finished intelligence against standing requirements, brief stakeholders, and drive detection and hunting priorities from what you find.
- DFIR-leaning Intelligence Analyst Intelligence work anchored in incident response. You turn forensic findings into durable intelligence, feed IR with adversary context mid-incident, and write the intrusion analysis afterwards.
- Senior CTI Analyst / Threat Hunter You set collection strategy, own contested analytic calls, run hypothesis-driven hunts from intelligence, and are the person who says "we do not know that" when the room wants a name.
- CTI Team Lead / Manager You run the function: intelligence requirements with the business, team capability and tooling, stakeholder relationships, and proving the team changed a decision rather than produced a volume of reports.