Interview track
CTI Team Lead / Manager
You run the function: intelligence requirements with the business, team capability and tooling, stakeholder relationships, and proving the team changed a decision rather than produced a volume of reports.
What is expected at this level
Expected to talk credibly about requirements management, measuring intelligence value, budget and vendor trade-offs, and building a team. Purely technical answers without an operating-model view score poorly.
Start a mock interview
12 questions
Questions from this track
Each one has a vetted expert answer you can read before or after you practise.
- Explain the difference between tactical, operational and strategic threat intelligence, with an example of each.
- A board member asks you what your team does and why it is worth the budget. You have two minutes. What do you say?
- You are the first intelligence hire at a company with a working SOC but no CTI function. What do you do in your first 90 days?
- Your CISO says "I want to know about ransomware." Turn that into something you can actually collect against.
- You have been producing reports for six months and you suspect nobody is reading them. How do you find out, and what do you change?
- On the same morning: a new critical vulnerability is being exploited in the wild, the CISO wants a board paper by Friday, and IR needs support on a live case. You cannot do all three. How do you decide?