Become a part of our caring community and help us put health first
The Lead Cyber Threat Intelligence (CTI) Analyst operates with expanded scope, autonomy, and accountability to guide and mature the execution of the cyber threat intelligence lifecycle across the enterprise. The Lead is responsible for optimizing how CTI operates, ensuring intelligence activities are consistent, scalable, and aligned to enterprise objectives. Additionally, the Lead influences outcomes beyond individual execution, establishes standards and expectations for intelligence delivery, and enables effective, repeatable intelligence practices that support threat-informed decision making.
This role acts as the primary liaison between CTI and threat management operations, ensuring CTI delivers timely, relevant, and actionable intelligence that directly supports operational threat management functions. In support of this objective, the Lead advances CTI maturity by emphasizing adversary behavior, tactics, and techniques over indicator-only intelligence, enabling intelligence outputs that better inform detection priorities, security control posture, and operational prioritization, while contributing to the establishment and maintenance of intelligence requirements for CTI stakeholders.
Key Responsibilities
Operational Intelligence Enablement
- Drive the structuring and alignment of intelligence outputs to ensure they deliver intelligence driven operational outcomes, support threat-informed security operations, investigations, and remediation decision-making without requiring direct analyst rework.
- Direct the development and implementation of operational intelligence strategies to proactively address emerging threats and support enterprise objectives.
- Enable consistent production of timely intelligence products focused on relevant and active threats to support enterprise threat management operations.
Stakeholder Engagement & Intelligence Requirements
- Drive cross-functional collaboration, facilitating integration of threat intelligence with risk management, incident response, and security operations.
- Establish and maintain stakeholder engagement models, including onboarding, stakeholder profiling, intelligence requirement intake, and feedback mechanisms, to ensure intelligence outputs are aligned to evolving enterprise and business needs.
Collection Management & Threat Monitoring
- Direct intelligence collection planning and prioritization to ensure effective coverage of priority and emerging threats while minimizing duplicative or ad hoc collection efforts.
- Evaluate and recommend enhancements to intelligence tools, processes, and frameworks to optimize operational efficiency and effectiveness.
- Perform threat actor and infrastructure analysis, including research and data pivoting, to identify malicious campaigns and emerging threat activity.
- Leverage threat intelligence frameworks to assess threat coverage and identify gaps in visibility or control effectiveness.
Analysis and Production
- Lead the analysis of threats to the enterprise and the production of finished intelligence that integrates tactical and operational insights and provides direction on threat-driven prioritization.
- Enhance tactical and operational intelligence deliverables by applying adversary behavior and TTP-based analysis that informs detection priorities, security control posture, and response actions.
Governance, Metrics & Continuous Improvement
- Set clear goals and measure performance against established KPIs, using data-driven insights to inform decisions and program improvements.
- Incorporate stakeholder feedback and performance insights to drive continuous improvement of intelligence relevance, delivery efficiency, and measurable program outcomes.
- Apply data analysis and threat intelligence frameworks to assess adversary activity, intelligence coverage, and defensive alignment over time.
Communication & Influence
- Represent the CTI function in strategic forums, influencing enterprise security strategy and risk prioritization through actionable intelligence.
- Effectively communicate and report CTI program metrics and KPIs to technical leaders, senior leaders, and executives to demonstrate program effectiveness and value.
- Translate technical threat intelligence into risk-relevant context, when appropriate, to inform or influence enterprise risk understanding and prioritization.
- Influence security planning, prioritization, and response through actionable intelligence.
Required Qualifications
- Bachelor's degree or higher in a relevant field (e.g., Information Technology, Information Systems, Computer Science, Intelligence, Political Science, International Relations) or equivalent experience.
- Minimum of 5+ years' experience in cyber threat intelligence, or a related security discipline, within a large, highly regulated organization in the public or private sector.
- Demonstrated experience across the intelligence lifecycle (planning, collection, processing, analysis, dissemination).
- Experience in intelligence collection management, including aligning collection activities to defined intelligence requirements and evolving threat priorities.
- Demonstrated experience conducting tactical and operational cyber threat analysis, including threat actor tracking, adversary behavior analysis, and malicious infrastructure research.
- Strong understanding of advanced cyber threats, threat vectors, and adversary methodologies.
- Ability to apply threat intelligence frameworks and data analysis techniques to produce insights that inform detection strategy, control posture, and threat-driven prioritization.
Preferred Qualifications
- Professional cybersecurity or intelligence certifications (e.g., CISSP, GCTI, GOSI).
- Experience supporting enterprise investigations, fraud, or insider threat programs.
- Advanced knowledge of cyber threat frameworks and analytic techniques (e.g., ATT&CK, Diamond Model, Cyber Kill Chain).
- Experience leveraging automation tools to streamline and improve varies aspects of the intelligence lifecycle.
- Experience using analytical and investigative tools (e.g., Maltego, Analyst's Notebook) to support threat analysis, relationship mapping, and investigative research.
Use your skills to make an impact
Travel: While this is a remote position, occasional travel to Humana's offices for training or meetings may be required.
Scheduled Weekly Hours
40
Pay Range
The compensation range below reflects a good faith estimate of starting base pay for full time (40 hours per week) employment at the time of posting. The pay range may be higher or lower based on geographic location and individual pay will vary based on demonstrated job related skills, knowledge, experience, education, certifications, etc.
$129,300 - $177,800 per year
This job is eligible for a bonus incentive plan. This incentive opportunity is based upon company and/or individual performance.
Description of Benefits
Humana, Inc. and its affiliated subsidiaries (collectively, “Humana”) offers competitive benefits that support whole-person well-being. Associate benefits are designed to encourage personal wellness and smart healthcare decisions for you and your family while also knowing your life extends outside of work. Among our benefits, Humana provides medical, dental and vision benefits, 401(k) retirement savings plan, time off (including paid time off, company and personal holidays, volunteer time off, paid parental and caregiver leave), short-term and long-term disability, life insurance and many other opportunities.
Application Deadline: 03-04-2026
About us
Humana Inc. (NYSE: HUM) is committed to putting health first – for our teammates, our customers and our company. Through our Humana insurance services and CenterWell healthcare services, we make it easier for the millions of people we serve to achieve their best health – delivering the care and service they need, when they need it. These efforts are leading to a better quality of life for people with Medicare, Medicaid, families, individuals, military service personnel, and communities at large.
Equal Opportunity Employer
It is the policy of Humana not to discriminate against any employee or applicant for employment because of race, color, religion, sex, sexual orientation, gender identity, national origin, age, marital status, genetic information, disability or protected veteran status. It is also the policy of Humana to take affirmative action, in compliance with Section 503 of the Rehabilitation Act and VEVRAA, to employ and to advance in employment individuals with disability or protected veteran status, and to base all employment decisions only on valid job requirements. This policy shall apply to all employment actions, including but not limited to recruitment, hiring, upgrading, promotion, transfer, demotion, layoff, recall, termination, rates of pay or other forms of compensation and selection for training, including apprenticeship, at all levels of employment.