Cyber Threat Intelligence Analyst

State of Iowa
  • Des Moines, IA
  • Remote
  • $81,203.20–$124,883.20 Per Year
5 days ago

Job Description

Cyber Threat Intelligence Analyst

Salary

$81,203.20 - $124,883.20 Annually

Location

Des Moines - 50309 - Polk County, IA

Job Type

Full-time

Job Number

27-00559

Agency

532 Iowa Department of Management

Opening Date

08/25/2026

Closing Date

9/6/2026 11:59 PM Central

LinkedIn Tag

#LI-POST

Point of Contact

Kim Slattery (kim.slattery@dom.iowa.gov)

  • Description
  • Benefits
  • Questions

Job Description

Only applicants who meet the Minimum Qualification Requirements and meet all selective requirements (listed below) will be placed on the eligible list.

The Department of Management's Division of Information Technology (DoIT) is seeking a senior-level Information Technology Specialist 5 (ITS5) - Cyber Threat Intelligence Analyst to serve as the authoritative intelligence resource supporting the Security Operations Center (SOC). This role collects, reviews, and analyzes intelligence data to identify threats targeting state and local government environments and transforms that information into actionable outcomes for SOC analysts, threat hunters, engineering teams, GRC, and leadership. The analyst develops and maintains Priority Intelligence Requirements (PIRs), assesses cyber risks, identifies adversary tactics, and motives, and ensures intelligence is aligned to state security objectives. The role leverages CTI platforms, OSINT sources, and structured analytic methodologies to produce accurate and timely intelligence reports. It also coordinates intelligence exchanges with external partners including CISA and peer government entities. This ITS5 position requires deep technical understanding, high integrity, and the ability to communicate complex intelligence to diverse audiences.

What You Will Do

  • Collect, maintain, and enrich intelligence data from internal telemetry, OSINT, commercial intel feeds, third-party reporting, and government partners.
  • Correlate external threats with SOC alerting and state-specific vulnerabilities.
  • Analyze cyber threat data to assess likelihood, impact, and relevance to state and local government.
  • Identify threat actor TTPs, campaigns, emerging vulnerabilities, and exploitation trends.
  • Produce tactical, operational, and strategic reports for diverse stakeholder groups.
  • Develop, maintain, and refine PIRs aligned to evolving state risks.
  • Manage intelligence workflows including collection planning, source evaluation, assessment documentation, and dissemination tracking.
  • Translate CTI findings into actionable activities including detection recommendations, risk prioritization, threat hunting leads, vulnerability context, and architecture hardening actions.
  • Support incident response as an intelligence subject-matter expert.
  • Coordinate with CISA, law enforcement, and peer government agencies to exchange intelligence, validate trends, and support joint defensive efforts.
  • Maintain and optimize CTI platforms, automation pipelines, and enrichment tools.
  • Mentor SOC team members on intelligence concepts, frameworks, and analytic tradecraft.
  • Present intelligence briefings to technical and non-technical audiences in a clear, concise manner.
  • Document analytic methods, assumptions, and findings following best practices and structured analytic techniques.

What We Are Seeking

  • Cyber Threat Intelligence lifecycle management (PIR development, collection, analysis, dissemination)
  • Strong knowledge of threat actor motivations, targets, behaviors, and TTPs
  • Proficiency with CTI platforms, malware/trend research tools, enrichment feeds, and OSINT techniques
  • In-depth understanding of MITRE ATT&CK, attack surface concepts, incident response, and vulnerability prioritization
  • Ability to translate intelligence into operational actions, detections, and risk-driven recommendations
  • Excellent communication, presentation, and technical writing skills
  • Strong problem-solving, critical-thinking, and independent decision-making ability
  • Five or more years of experience in cyber threat intelligence, cyber defense analytics, or related field
  • Strong understanding of cybersecurity frameworks (MITRE ATT&CK, Kill Chain, Diamond Model)
  • Demonstrated knowledge of attack vectors, penetration methods, and defensive countermeasures
  • Experience with OSINT, intel feeds, CTI platforms, and log or alert correlation
  • Excellent problem-solving, writing, briefing, and documentation skills
  • Ability to work independently with minimal supervision and in a multidisciplinary team
  • Strong integrity, judgment, and professional conduct with sensitive information

Preferred Certifications

  • CISSP, CISA, GSEC, or related cyber/intelligence credentials

What We Offer

  • Flexible work environment
  • Iowa Public Employees Retirement System (IPERS)
  • Health, dental, and vision insurance
  • Generous vacation, sick leave, and paid holidays
  • Life and disability insurance
  • Retirement savings options (RIC)
  • Flexible Spending Accounts

Why Work with Us?

At the Iowa Department of Management (DOM), we help government agencies across the state perform at their best by managing financial resources, technology, and information. Our mission is rooted in service-we provide efficient, innovative, and strategic solutions that empower agencies to fulfill their goals.

We're guided by four core values:

  • Integrity - We act with honesty and accountability.
  • Teamwork - We collaborate to achieve shared success.
  • Service - We are committed to excellence in public service.
  • Partnership - We build strong relationships to drive results.

Working Arrangement

This position occasionally requires onsite work in Des Moines, IA. Employees meeting all expectations of their work responsibilities may request fully remote work and develop a hybrid/remote schedule collaboratively with their manager.

Please note, candidates for this position must reside in the state of Iowa at the time of starting the role.

Background Check Requirements

  • After a conditional offer of employment has been made, and as the final step in the hiring process, candidates for this position will be subject to a background investigation, which may include but may not be limited to a verification of a candidate's education, previous employment/work history, contact of personal references, motor vehicle records, and a criminal history check (including through Federal, State, or Local criminal justice agencies).
  • Information gathered as part of such background investigation will be treated as confidential to the extent permitted by Iowa Code section 22.7, 8B.4A, and other applicable laws, rules, and regulations; provided that, to the extent permitted by applicable law, such information shall be available to candidates upon request.

E-Verify and Right to Work

The State of Iowa participates in E-Verify, a federal program that helps employers confirm the employment eligibility of all newly hired employees. Within the required timeframe, new hires will be verified through the E-Verify system to ensure authorization to work in the United States. The State of Iowa also complies with the Federal Right to Work laws, which protect employees' rights to work without being required to join a labor organization. For more information, please visit www.e-verify.gov.

Selectives

990 Cyber Security Planning:

A minimum of 18 months of full-time work experience in cyber security planning at a professional level that included the following major functions: participating in and leading a company-/agency-wide cyber security planning program including the identification of cyber security risks, development of prevention and response plans to minimize cyber-attack damages including mass care and consequences management, and the development of continuation of business operation plans; participating in national cyber security planning initiatives and exercises; responding to and participating in the recovery work from cyber security incidents; and working across governments, private sectors, and non-profit organizations collaboratively on cyber security planning activities and plans for response.

AND

980 Strategic Planning:

6 months' experience, 12 semester hours, or a combination of both. Generally, an administrative position (mid to upper level of the management team) is assigned this as one function of their overall job. However, there are some specialists who deal only in strategic planning. Some colleges and universities may now carry this as a major or area of emphasis as part of their business administration or public policy programs. For experience to count, the applicant must have had the responsibility either for coordinating or developing the organizations strategic plan. Sometimes an administrative assistanttype is responsible for a lower level of coordination, i.e., distributing information to managers, collecting what they develop, and putting it into one document; that is not what is sought here. This has to be experience to the point that the individual knows the following: • What a good strategic plan looks like • How to prepare a plan • How to monitor progress and ancillary planning • How to speak knowledgably for the organization about the plan

AND

717 Security Administration:

6 months' experience, 12 semester hours, or a combination of both in building and maintaining skillset and knowledge base for security issues that impact information technology systems. Applicants may refer to themselves as Security Administrator. System Administrator is not the same.

AND

727 Risk Assessment:

6 months' experience, 12 semester hours, or a combination of both in analyzing and identifying risks and the corresponding potential impact to information and information technology systems.

Minimum Qualification Requirements

Applicants must meet at least one of the following minimum requirements to qualify for positions in this job classification:

1) Graduation from an accredited four-year college or university with a degree in any field, and experience equal to three years of full-time work in application development and database management, business analysis, systems and network administration, technical training and reporting, IT vendor and purchasing management, IT project management, IT product management, system testing and quality assurance, mainframe and platform administration, and/or information technology security.

2) Graduation from an accredited four-year college or university with a degree in computer science, computer applications, software engineering, computer engineering, management information systems, business analytics, or cyber security, and experience equal to two years of full-time work in application development and database management, business analysis, systems and network administration, technical training and reporting, IT vendor and purchasing management, IT project management, IT product management, system testing and quality assurance, mainframe and platform administration, and/or information technology security.

3) All of the following (a and b):

a. Three years of full-time work experience in application development and database management, business analysis, systems and network administration, technical training and reporting, IT vendor and purchasing management, IT project management, IT product management, system testing and quality assurance, mainframe and platform administration, and/or information technology security; and

b. A total of four years of education and/or full-time experience (as described in part a), where thirty semester hours of accredited college or university coursework in any field equals one year of full-time experience.

4) All of the following (a and b):

a. Five years of full-time work experience in application development and database management, business analysis, systems and network administration, technical training and reporting, IT vendor and purchasing management, IT project management, IT product management, system testing and quality assurance, mainframe and platform administration, and/or information technology security; and

b. Either of the following:

i. Certification from an authorized educational institution/major computer or software producer in one or more of the specialty areas listed in part a; or

ii. Eighteen semester hours from an accredited college or university in one or more of the specialty areas listed in part a.

5) Current, continuous experience in the state executive branch that includes six months of full-time work as an Information Technology Specialist 4.

For additional information, please click on this link to view the job description.

Why Choose the State of Iowa?

At the heart of our commitment to excellence is a dedication to our most valuable asset - our employees. Discover the outstanding benefits that set us apart as an employer of choice.

Our Robust Benefits Package Includes:

Competitive Compensation:

Enjoy a competitive salary that reflects directly on your skills and expertise.

Keep in mind, your wage is just one part of your total compensation. Unlock the complete value of your employment with the State of Iowa by using our user-friendly Total Compensation Calculator. Gain insights into your comprehensive annual compensation, including salary and State-provided benefits.

Health and Wellness:

Prioritize your well-being with our comprehensive health plans, including medical, dental, and vision coverage. Enjoy the peace of mind knowing that the State of Iowa covers 90% of the premiums, providing you and your loved ones with excellent coverage at a remarkably low cost.

Retirement Planning:

We are proud to offer the Iowa Public Employees Retirement System (IPERS). A defined benefit plan, IPERS benefits are guaranteed for life, meaning once you retire, you will receive the same monthly benefit for the remainder of your life (once vested). We invest in your long-term financial well-being, so you can retire with peace of mind. Click here to learn more about IPERS.

Paid Time Off:

Life is unpredictable, and at the State of Iowa, we understand the importance of work-life balance. Our leave policies, including paid holidays, vacation, and sick leave with unlimited accrual, ensure you have the flexibility you need for personal and family matters.

Professional Development:

Elevate your career with continuous learning opportunities. We support your growth through training programs, workshops, and tuition reimbursement.

Employee Assistance Program (EAP):

We care about your well-being beyond the workplace. Access confidential counseling, resources, and support through our Employee Assistance Program.

Diversity and Inclusion:

Be part of a diverse and inclusive workplace that embraces all backgrounds and perspectives. We believe diversity is a strength that drives innovation.

Join Us - Elevate Your Career:

Ready to elevate your career with the State of Iowa? Click here to explore more about our unparalleled benefits and discover what makes us unique. Your success is our priority!

01

Do you understand that the answers to all of the following questions must be truthful, honest, and accurate to the best of your ability? Please read all questions and answers thoroughly and make sure you understand them completely. Ensure the answers to your questions match the information filled out on your application and the attachments you have uploaded. If the answers to your questions are inconsistent with your application information or uploaded attachments, you will be given zero points for the question. Knowingly misrepresenting the facts when submitting any information related to an application, examination, certification, appeal, or any other facet of the selection process will result in your disqualification from this application and future employment with the state of Iowa.

  • Yes - I understand and agree.
  • No

02

PLEASE READ CAREFULLY

Have you filed a registration statement pursuant to the federal Foreign Agents Registration Act of 1938, as amended, 22 U.S.C. §611 et seq?

  • No - I have NOT filed a registration statement pursuant to the federal Foreign Agents Registration Act of 1938, as amended, 22 U.S.C. §611 et seq
  • Yes - I HAVE filed a registration statement pursuant to the federal Foreign Agents Registration Act of 1938, as amended, 22 U.S.C. §611 et seq

03

Have you graduated from an accredited four-year college or university with a degree in any field, and have experience equal to three years of full-time work in application development and database management, business analysis, systems and network administration, technical training and reporting, IT vendor and purchasing management, IT project management, IT product management, system testing and quality assurance, mainframe and platform administration, and/or information technology security?

  • Yes - I have an accredited four-year college or university with a degree in any field, and have experience equal to three years of full-time work in application development and database management, business analysis, systems and network administration, technical training and reporting, IT vendor and purchasing management, IT project management, IT product management, system testing and quality assurance, mainframe and platform administration, and/or information technology security
  • I do not have an accredited four-year college or university with a degree in any field
  • I have an accredited four-year college or university with a degree in any field, BUT DO NOT have experience equal to three years of full-time work in application development and database management, business analysis, systems and network administration, technical training and reporting, IT vendor and purchasing management, IT project management, IT product management, system testing and quality assurance, mainframe and platform administration, and/or information technology security

04

Have you graduated from an accredited four-year college or university with a degree in computer science, computer applications, software engineering, computer engineering, management information systems, business analytics, or cyber security, and have experience equal to two years of full-time work in application development and database management, business analysis, systems and network administration, technical training and reporting, IT vendor and purchasing management, IT project management, IT product management, system testing and quality assurance, mainframe and platform administration, and/or information technology security?

  • Yes - I have graduated from an accredited four-year college or university with a degree in computer science, computer applications, software engineering, computer engineering, management information systems, business analytics, or cyber security, and have experience equal to two years of full-time work in application development and database management, business analysis, systems and network administration, technical training and reporting, IT vendor and purchasing management, IT project management, IT product management, system testing and quality assurance, mainframe and platform administration, and/or information technology security
  • I have not graduated from an accredited four-year college or university with a degree in computer science, computer applications, software engineering, computer engineering, management information systems, business analytics, or cyber security,
  • I have graduated from an accredited four-year college or university with a degree in computer science, computer applications, software engineering, computer engineering, management information systems, business analytics, or cyber security, but do not have experience equal to two years of full-time work in application development and database management, business analysis, systems and network administration, technical training and reporting, IT vendor and purchasing management, IT project management, IT product management, system testing and quality assurance, mainframe and platform administration, and/or information technology security

05

Do you meet a and b: a. Three years of full-time work experience in application development and database management, business analysis, systems and network administration, technical training and reporting, IT vendor and purchasing management, IT project management, product management, system testing and quality assurance, mainframe and platform administration, and/or information technology security; and b. A total of four years of education and/or full-time experience (as described in part a), where thirty semester hours of accredited college or university coursework in any field equals one year of full-time experience.

  • Yes - I meet a and b
  • I do not meet a and b

06

Do you meet a and b: a. Five years of full-time work experience in application development and database management, business analysis, systems and network administration, technical training and reporting, IT vendor and purchasing management, IT project management, IT product management, system testing and quality assurance, mainframe and platform administration, and/or information technology security; and b. Either of the following: i. Certification from an authorized educational institution/major computer or software producer in one or more of the specialty areas listed in part a; or ii. Eighteen semester hours from an accredited college or university in one or more of the specialty areas listed in part a.

  • Yes - I meet a and b
  • I do not meet a and b

07

Are you a current permanent State of Iowa employee? If yes - Do you have current, continuous experience in the state executive branch that includes six months of full-time work as an Information Technology Specialist 4?

  • I am a current permanent State of Iowa employee and have current, continuous experience in the state executive branch that includes six months of full-time work as an Information Technology Specialist 4
  • I am a current permanent State of Iowa employee but do not have current, continuous experience in the state executive branch that includes six months of full-time work as an Information Technology Specialist 4
  • I am not a current permanent State of Iowa employee

08

Does your application demonstrate that you have A minimum of 18 months of full-time work experience in cyber security planning at a professional level that included the following major functions: participating in and leading a company-/agency-wide cyber security planning program including the identification of cyber security risks, development of prevention and response plans to minimize cyber-attack damages including mass care and consequences management, and the development of continuation of business operation plans; participating in national cyber security planning initiatives and exercises; responding to and participating in the recovery work from cyber security incidents; and working across governments, private sectors, and non-profit organizations collaboratively on cyber security planning activities and plans for response? (990)

  • Yes
  • No

09

If you answered "Yes" to the question above - please list exactly HOW you meet it: list exact classes and credit hours, employer, dates and hours per week and exact duties. Please do not paste or state - See application or resume. If you answered no to the question above please type in "No" in the box below.

10

Does your application demonstrate that you have 6 months experience, 12 semester hours, or a combination of both? Generally, an administrative position (mid to upper level of the management team) is assigned this as one function of their overall job. However, there are some specialists who deal only in strategic planning. Some colleges and universities may now carry this as a major or area of emphasis as part of their business administration or public policy programs. For experience to count, the applicant must have had the responsibility either for coordinating or developing the organizations strategic plan. Sometimes an administrative assistant type is responsible for a lower level of coordination, i.e., distributing information to managers, collecting what they develop, and putting it into one document; that is not what is sought here. This has to be experience to the point that the individual knows the following:

  • What a good strategic plan looks like
  • How to prepare a plan
  • How to monitor progress and ancillary planning
  • How to speak knowledgeably for the organization about the plan
  • Yes - My current application and/or attached documentation clearly addresses this requirement
  • No - I do not currently meet this requirement

11

If you answered "Yes" to the question above - please list exactly HOW you meet it: list exact classes and credit hours, employer, dates and hours per week and exact duties. Please do not paste or state - See application or resume. If you answered no to the question above please type in "No" in the box below.

12

Does your application demonstrate that you have 6 months experience, 12 semester hours, or a combination of both in analyzing and identifying risks and the corresponding potential impact to information and information technology systems?

  • Yes
  • No

13

If you answered "Yes" to the question above - please list exactly HOW you meet it: list exact classes and credit hours, employer, dates and hours per week and exact duties. Please do not paste or state - See application or resume. If you answered no to the question above please type in "No" in the box below.

14

Does your application demonstrate that you have 6 months experience, 12 semester hours, or a combination of both in building and maintaining skillset and knowledge base for security issues that impact information technology systems?

  • Yes
  • No

15

If you answered "Yes" to the question above - please list exactly HOW you meet it: list exact classes and credit hours, employer, dates and hours per week and exact duties. Please do not paste or state - See application or resume. If you answered no to the question above please type in "No" in the box below.

Required Question

Employer State of Iowa

Agency 532 Iowa Department of Management Address State Capitol Building, Room 13

1007 E Grand Ave

Des Moines, Iowa, 50319

Website https://dom.iowa.gov/

Numbers & Facts

LocationDes Moines, IA (
Remote
)
Salary$81,203.20–$124,883.20 Per Year

Skills

  • Address Managementunmatched
  • Administrative Skillsunmatched
  • Analysis Skillsunmatched
  • Automationunmatched
  • Business Administrationunmatched
  • Business Analysisunmatched
  • Business Developmentunmatched
  • Business Operationsunmatched
  • Business Planunmatched
  • CISA - Certified Information Systems Auditorunmatched
  • Campaignsunmatched
  • Communication Skillsunmatched
  • Compensation and Benefitsunmatched
  • Computer Engineeringunmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • Computer Softwareunmatched
  • Computer Telephony Integration (CTI)unmatched
  • Criminal Justiceunmatched
  • Cross-Functionalunmatched
  • DOM (Document Object Model)unmatched
  • Data Analysisunmatched
  • Database Administrationunmatched
  • Database Programmingunmatched
  • Defense Intelligenceunmatched
  • Dental Insuranceunmatched
  • Disability Accommodationsunmatched
  • Diversityunmatched
  • Documentationunmatched
  • Employee Assistance Planunmatched
  • Establish Prioritiesunmatched
  • Financial Managementunmatched
  • Financial Trend Analysisunmatched
  • Flexible Spending Accountsunmatched
  • Governmentunmatched
  • Government Reportingunmatched
  • Health Planunmatched
  • Huntingunmatched
  • Incident Responseunmatched
  • Information Technology & Information Systemsunmatched
  • Intel Product Familyunmatched
  • Intelligence Agenciesunmatched
  • Intelligence Analysisunmatched
  • Intelligence Collection Managementunmatched
  • Internet Securityunmatched
  • Law Enforcementunmatched
  • Leadershipunmatched
  • Local Governmentunmatched
  • Mainframe Computerunmatched
  • Malwareunmatched
  • Management of Information Systems/Technology (MIS)unmatched
  • Mentoringunmatched
  • Network Administration/Managementunmatched
  • Nonprofitunmatched
  • OSINT (Open Source Intelligence)unmatched
  • Operational Strategyunmatched
  • Operational Supportunmatched
  • Operations Planningunmatched
  • Organizational Development/Managementunmatched
  • Presentation/Verbal Skillsunmatched
  • Problem Solving Skillsunmatched
  • Procurement Managementunmatched
  • Product Managementunmatched
  • Project Trackingunmatched
  • Project/Program Managementunmatched
  • Public Policyunmatched
  • Quality Assuranceunmatched
  • Resource Managementunmatched
  • Retirement Planningunmatched
  • Riskunmatched
  • Risk Analysisunmatched
  • Security Attacksunmatched
  • Software Developmentunmatched
  • Software Engineeringunmatched
  • State Governmentunmatched
  • Strategic Planningunmatched
  • System Testunmatched
  • Systems Administration/Managementunmatched
  • Tactical Operationsunmatched
  • Team Playerunmatched
  • Technical Presentationunmatched
  • Technical Writingunmatched
  • Telemetryunmatched
  • Trend Analysisunmatched
  • Vision Planunmatched
  • Web Analyticsunmatched
  • Writing Skillsunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder