Interview track
Senior CTI Analyst / Threat Hunter
You set collection strategy, own contested analytic calls, run hypothesis-driven hunts from intelligence, and are the person who says "we do not know that" when the room wants a name.
What is expected at this level
Expected to design hunt hypotheses from TTPs, critique weak sourcing, handle attribution with explicit confidence and alternative hypotheses, and mentor. Vague or unhedged answers score badly at this level regardless of technical detail.
Start a mock interview
24 questions
Questions from this track
Each one has a vetted expert answer you can read before or after you practise.
- What threat intelligence do you read regularly, and how do you decide whether to believe a vendor report?
- You are the first intelligence hire at a company with a working SOC but no CTI function. What do you do in your first 90 days?
- You have one piece of evidence: a single IP address that a compromised host was beaconing to. Walk me through how you would develop this.
- Your CISO says "I want to know about ransomware." Turn that into something you can actually collect against.
- What is F3EAD, and why do some CTI teams prefer it to the traditional intelligence cycle?
- What is the difference between saying something is "likely" and saying you have "high confidence" in an assessment? Can you have high confidence in an unlikely outcome?