Cyber Threat Intelligence Analyst (Cybersecurity)
ΠΡΡΡ & Π‘ΠΎΠΏΡΠΎΠ²ΠΎΠ΄
ΠΠ»Ρ ΠΌΡΡΡΠ° Ρ ΡΡΠΎΠΉ Π²Π°ΠΊΠ°Π½ΡΠΈΠ΅ΠΉ Π½ΡΠΆΠ΅Π½ Plus
ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅ Π²Π°ΠΊΠ°Π½ΡΠΈΠΈ
TL;DR
Cyber Threat Intelligence Analyst (Cybersecurity): Turning threat and vulnerability data into actionable intelligence for 's IT, OT, and connected-vehicle environments with an accent on threat analysis, intelligence operations, and detection enablement. Focus on operationalizing indicators, supporting active incidents, mapping adversary TTPs to MITRE ATT&CK, and improving intelligence-driven defenses.
Location: Hybrid role based in Austin, Texas or Warren, Michigan, with in-person attendance at least three times per week. does not provide immigration-related sponsorship, and candidates must already have U.S. work authorization without requiring current or future immigration support. The role may be eligible for relocation benefits.
Company
General Motors develops automotive products and technologies guided by a vision of zero crashes, zero emissions, and zero congestion.
What you will do
- Monitor, triage, and analyze threats and vulnerabilities affecting IT, OT, manufacturing, and connected-vehicle environments.
- Produce actionable intelligence bulletins, vulnerability advisories, threat-actor profiles, campaign summaries, and executive assessments.
- Maintain indicators of compromise and operationalize curated intelligence across sensors, SIEM, detection workflows, and other security tools.
- Ingest and normalize intelligence from ISACs, government and law-enforcement partners, commercial providers, and open sources using platforms such as MISP.
- Support active incident response and cross-functional requests for information with confidence-rated assessments.
- Partner with cybersecurity teams and improve CTI processes, automation, playbooks, metrics, and detection coverage.
Requirements
- At least 2 years of experience in cyber threat intelligence, security operations, incident response, threat hunting, or a related cybersecurity field.
- Working knowledge of the threat-intelligence lifecycle, indicators of compromise, adversary TTPs, MITRE ATT&CK, and the Diamond Model.
- Experience analyzing and correlating security data across multiple sources and communicating findings to technical and non-technical audiences.
- Hands-on experience with threat-intelligence and detection tools such as MISP, SIEM, EDR, or NDR, along with open-source research techniques.
- Understanding of attacker techniques, malware, phishing, credential theft, vulnerabilities, CVE, and CVSS concepts.
- Bachelor's degree in information security, computer science, information systems, or equivalent practical experience.
Nice to have
- Experience with OT, ICS, PLCs, manufacturing, connected vehicles, or embedded environments.
- Experience with ISACs, law-enforcement or government intelligence-sharing communities, or the automotive industry.
- Scripting experience with Python, PowerShell, KQL, or similar tools.
- Experience monitoring the clear web and dark web, investigating impersonation or employment fraud, or attributing online personas.
- Cloud security exposure or certifications such as GCTI, GCIH, GCFA, or Security+.
Culture & Benefits
- Work within a cross-functional Cyber Threat Intelligence and Security Operations organization.
- Collaborate with Cyber Defense, Product Cybersecurity, Manufacturing/OT Cybersecurity, Third-Party Cybersecurity, and external security partners.
- Hybrid work arrangement with regular onsite collaboration.
- Potential eligibility for relocation benefits.
- Employee total rewards and benefits supporting well-being at work and at home.
Hiring process
- Applicants may be required to complete role-related assessments and pre-employment screening where applicable.
ΠΡΠ΄ΡΡΠ΅ ΠΎΡΡΠΎΡΠΎΠΆΠ½Ρ: Π΅ΡΠ»ΠΈ ΡΠ°Π±ΠΎΡΠΎΠ΄Π°ΡΠ΅Π»Ρ ΠΏΡΠΎΡΠΈΡ Π²ΠΎΠΉΡΠΈ Π² ΠΈΡ ΡΠΈΡΡΠ΅ΠΌΡ, ΠΈΡΠΏΠΎΠ»ΡΠ·ΡΡ iCloud/Google, ΠΏΡΠΈΡΠ»Π°ΡΡ ΠΊΠΎΠ΄/ΠΏΠ°ΡΠΎΠ»Ρ, Π·Π°ΠΏΡΡΡΠΈΡΡ ΠΊΠΎΠ΄/ΠΠ, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡΠ΅ ΡΡΠΎΠ³ΠΎ - ΡΡΠΎ ΠΌΠΎΡΠ΅Π½Π½ΠΈΠΊΠΈ. ΠΠ±ΡΠ·Π°ΡΠ΅Π»ΡΠ½ΠΎ ΠΆΠΌΠΈΡΠ΅ "ΠΠΎΠΆΠ°Π»ΠΎΠ²Π°ΡΡΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡΠΈΡΠ΅ Π² ΠΏΠΎΠ΄Π΄Π΅ΡΠΆΠΊΡ. ΠΠΎΠ΄ΡΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β