Interview track
Cyber Threat Intelligence Analyst
The core role. You own a collection area, produce finished intelligence against standing requirements, brief stakeholders, and drive detection and hunting priorities from what you find.
What is expected at this level
Expected to run the full cycle: translate a stakeholder question into requirements, collect and grade sources, apply structured analytic techniques, express calibrated confidence, and land the "so what" for a named audience.
Start a mock interview
35 questions
Questions from this track
Each one has a vetted expert answer you can read before or after you practise.
- What is cyber threat intelligence, and how is it different from a threat feed?
- Why do you want to work in threat intelligence rather than another security discipline?
- What threat intelligence do you read regularly, and how do you decide whether to believe a vendor report?
- Explain the difference between tactical, operational and strategic threat intelligence, with an example of each.
- A board member asks you what your team does and why it is worth the budget. You have two minutes. What do you say?
- What is the difference between an indicator of compromise and a TTP, and why does the distinction matter?