CTI Analyst
Berkeley Heights, NJ - USA
Job Summary
Calling all innovators - find your future at Fiserv.
Were Fiserv a global leader in Fintech and payments and we move money and information in a way that moves the world. We connect financial institutions corporations merchants and consumers to one another millions of times a day - quickly reliably and securely. Any time you swipe your credit card pay through a mobile app or withdraw money from the bank were involved. If you want to make an impact on a global scale come make a difference at Fiserv.
Job Title
CTI AnalystCyber Threat Intelligence Analyst
Fully on-site Cybersecurity Operations Cyber Threat Intelligence
Calling all innovators find your future at Fiserv.
Were Fiserv a global leader in Fintech and payments and we move money and information in a way that moves the world. We connect financial institutions corporations merchants and consumers to one another millions of times a day quickly reliably and securely. Any time you swipe your credit card pay through a mobile app or withdraw money from the bank were involved. If you want to make an impact on a global scale come make a difference at Fiserv.
About your role:
Most threat intelligence roles end with a report. This one is built to change what happens next. As a Cyber Threat Intelligence (CTI) Analyst youll be a core member of our Cybersecurity Operations team reporting to our VP of Cyber Threat Intelligence. Your job is to identify track and translate emerging cyber threats into intelligence that protects Fiservs platforms clients data and infrastructure for a company that moves money and information millions of times a day.
This is a highly technical CTI seat at the intersection of threat intelligence incident response and engineering. Youll work side by side with the SOC Detection Engineering Threat Hunting Attack Surface Management and Red and Purple Team groups so your analysis never sits on a shelf it becomes the detections hunts and priorities that come next. If youre naturally curious love learning new things and want to explore novel approaches to CTI including building the tools models and platforms that mature a CTI program this is the seat.
What youll do:
- Operationalize the intelligence cycle by developing and maintaining intelligence requirements collection requirements collection plans and analytic frameworks then identifying gaps and refining the process to improve outcomes.
- Produce strategic operational and tactical intelligence threat assessments campaign analyses executive briefings and operational advisories that inform stakeholders and shape their decisions.
- Track the threat actors campaigns capabilities and attack patterns that matter most to Fiserv and use that awareness to set operational priorities.
- Partner with the SOC and Detection Engineering teams to turn adversary behavior into detection opportunities and prioritized monitoring.
- Work with the Threat Hunting team to build hunt hypotheses grounded in observed adversary behaviors and trends.
- Team up with Attack Surface Management to prioritize vulnerabilities using real intelligence on emerging threats exploitation trends and attacker adoption patterns.
- Support Red and Purple Team exercises by profiling relevant threat actors so testing stays realistic and impactful.
- Dig into adversary infrastructure domains IPs hosting providers certificates and operational patterns to uncover relationships that support investigations and intelligence production.
- Help build the CTI program of the future by developing and improving intelligence tools models processes and platforms.
- Responsibilities listed are not intended to be all-inclusive and may be modified as necessary.
Experience youll need to have:
- 5 years of experience in operational or technical cyber threat intelligence; OR 5 years of experience in threat hunting counter-adversary operations incident response digital forensics or related cybersecurity disciplines with demonstrated knowledge of CTI methodologies and practices.
- Bachelors degree in Cybersecurity Information Technology Computer Science or a related field and/or equivalent military or federal experience.
- Demonstrated ability to apply the intelligence lifecycle MITRE ATT&CK cyber kill chain concepts and adversary TTP analysis to real-world investigations detections threat hunts and intelligence production.
- Demonstrated ability to conduct threat intelligence analysis identify attack patterns develop intelligence assessments correlate technical indicators and communicate actionable intelligence to operational and executive stakeholders.
- Demonstrated ability to evaluate attacker capabilities assess organizational exposure and put threats in context for an enterprise environment.
- Experience using Threat Intelligence Platform (TIP) solutions (e.g. Anomali OpenCTI) to conduct analysis and support intelligence workflows.
- Experience working with common CTI providers (e.g. Google Threat Intelligence Recorded Future Flashpoint Silobreaker CrowdStrike).
- Experience using security telemetry from network endpoint cloud identity and/or email security platforms to support analysis investigations and threat validation.
- Strong written communication skills with the ability to produce clear concise relevant intelligence products for a diverse range of stakeholders.
- Strong verbal briefing skills and comfort presenting threat findings to stakeholders at all levels.
Experience that would be great to have:
- Relevant certifications such as GCTI GCIH GCFA or similar.
- Experience in financial services or other regulated environments.
- Experience conducting malware triage behavioral analysis and technical assessments of the malicious tooling adversaries use.
- Experience performing infrastructure investigations using passive DNS WHOIS certificate transparency internet scanning NetFlow and/or related enrichment sources.
- Experience using Python PowerShell KQL SPL or similar technologies to automate workflows.
- Experience running analytical investigations on large datasets including enrichment correlation visualization and trend analysis across multiple intelligence and security data sources.
- Experience using LLMs agentic workflows or other AI-enabled technologies to support intelligence collection processing analysis and/or production.
How youll work:
- Were better together! This role is fully on-site at either our Berkeley Heights NJ office OR our Alpharetta GA office.
- This is a full-time direct-hire position. No contract options or unsolicited agency submissions will be considered.
Sponsorship:
- You must currently possess valid and unrestricted U.S. work authorization to be considered for this role. Individuals with temporary visas including but not limited to F-1 (OPT CPT STEM) H-1B H-2 or TN or any candidate requiring sponsorship now or in the future will not be considered.
Fiserv is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race color religion national origin gender gender identity sexual orientation age disability protected veteran status or any other category protected by law.
If you have a disability and require a reasonable accommodation in completing a job application or otherwise participating in the overall hiring process please contact Please note our AskHR representatives do not have visibility to your application status. Current associates who require a workplace accommodation should refer to Fiservs Disability Accommodation Policy for additional information.
Note to agencies: Fiserv does not accept resume submissions from agencies outside of existing agreements. Please do not send resumes to Fiserv associates. Fiserv is not responsible for any fees associated with unsolicited resume submissions.
Warning about fake job posts: Please be aware of fraudulent job postings that are not affiliated with Fiserv. Fraudulent job postings may be used by cyber criminals to target your personally identifiable information and/or to steal money or financial information. Any communications from a Fiserv representative will come from a legitimate Fiserv email address.
Salary Range
$146000.00 - $244800.00These pay ranges apply to employees in New Jersey and New York. Pay ranges for employees in other states may differ.
It is unlawful to discriminate against a prospective employee due to the individuals status as a veteran.
For incentive eligible associates the successful candidate is eligible for an annual incentive opportunity which may be delivered as a mix of cash bonus and equity awards in the Companys sole discretion.Thank you for considering employment with Fiserv. Please:
- Apply using your legal name
- Complete the step-by-step profile and attach your resume (either is acceptable both are preferable).
Our commitment to Equal Opportunity:
Fiserv is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race color religion national origin gender gender identity sexual orientation age disability protected veteran status or any other category protected by law.
If you have a disability and require a reasonable accommodation in completing a job application or otherwise participating in the overall hiring process please contact. Please note our AskHR representatives do not have visibility to your application status. Current associates who require a workplace accommodation should refer to Fiservs Disability Accommodation Policy for additional information.
Note to agencies:
Fiserv does not accept resume submissions from agencies outside of existing do not send resumes to Fiserv associates. Fiserv is not responsible for any fees associated with unsolicited resume submissions.
Warning about fake job posts:
Please be aware of fraudulent job postings that are not affiliated with Fiserv. Fraudulent job postings may be used by cyber criminals to target your personally identifiable information and/or to steal money or financial information. Any communications from a Fiserv representative will come from a legitimate Fiserv email address.
Required Experience:
IC
About Company
Fiserv is a global fintech and payments company with solutions for banking, global commerce, merchant acquiring, billing and payments, and point-of-sale.