CTI Academy
Login Get Started

Entry-Level CTI Jobs: Where to Find Them and How to Land One

By CTI Academy

The seven employer categories that hire juniors, the titles that hide CTI work, and what gets you shortlisted.

Ninety percent of organizations surveyed for the 2026 SANS CTI Survey now have dedicated threat intelligence resources. Sixty percent of those teams run on four or fewer full-time analysts. That pair of numbers explains most of what is strange about entry-level threat intelligence jobs in 2026. The function has spread almost everywhere, while the doors into it stayed narrow and, in most cases, are not labeled the way you would expect.

It gets worse before it gets better. ISC2 surveyed 929 cybersecurity hiring managers and found that 38% of them require the CISA certification on entry-level postings, a credential that itself requires five years of professional auditing experience. Roughly a third expect the CISSP at the same level, which also demands five years. So a meaningful share of the postings you are reading were written for a candidate who does not exist.

Knowing that is the first real advantage you can have. The rest of this piece is about where the genuine openings live, what they are actually called, and what separates the applications that get read from the several hundred that do not.

What Counts as an Entry-Level CTI Job

An entry-level CTI job is a role where you collect, enrich, and write up threat information under the supervision of a more senior analyst, with no expectation that you already own an intelligence program. In practice that means monitoring sources and feeds, triaging what comes in, enriching indicators, tracking a small set of actors or campaigns, and drafting the first version of reporting that someone else reviews before it ships. You are doing the collection and processing stages of the intelligence lifecycle while you learn to do the analysis stage.

Three things follow from that definition, and they are worth internalizing before you open a job board.

The first is that these roles are usually funded inside a larger security function rather than as standalone headcount. When a CTI team is four people, the fifth chair rarely gets approved as "junior CTI analyst." It gets approved as a SOC role, a research role, or an intern position, and the CTI work accrues to whoever proves they can do it.

The second is that the work is heavily writing-shaped. If you have read our guide to what cyber threat intelligence actually is, you already know the product of the job is a judgment delivered to someone who has to make a decision. Hiring managers screen hard for whether you can produce that.

The third is that "entry-level" in this field usually means one to two years of adjacent experience rather than zero. The salary aggregators list entry-level CTI pay around $105,000 to $110,000 in the US, but that figure is scraped from postings that carry the words "entry level" while asking for prior SOC time. Treat aggregator numbers as a rough shape, not a promise. Our threat intelligence salary guide walks through why the published figures for this one job title disagree by more than $100,000.

Where Entry-Level Threat Intelligence Jobs Actually Live

One caveat before the map. Nobody publishes a clean count of open CTI roles specifically. What exists are whole-of-cybersecurity numbers, and they are healthy, with CyberSeek tracking over 514,000 US openings in the twelve months to March 2026 against a supply-demand ratio of 74%, and the US Bureau of Labor Statistics projecting 29% growth for information security analysts through 2034. Read those as weather rather than as a forecast for your specific job search, because CTI is a small, specialized slice inside them.

Seven employer categories hire at the junior end. They differ enormously in volume, in what they will teach you, and in how hard they are to get into.

Managed security providers. MSSPs and managed detection vendors hire in volume, hire year-round, and put you in front of dozens of client environments in your first year. That breadth is the reason this is the highest-yield category for someone starting out. The trade is that the work skews toward alert triage and repeatable enrichment, and you will have to actively push toward intelligence work rather than waiting for it to be assigned.

CTI vendors and platform companies. This is where the recognizable intelligence teams sit. CrowdStrike runs its intelligence internships through Counter Adversary Operations, splitting interns across a Global Threat Analysis Cell for adversary tracking, a Technical Analysis Cell for malware and encryption work, and a Persona Operations team. Google Threat Intelligence Group, Recorded Future, Intel 471, Flashpoint, KELA, and the regional vendors all run comparable programs. The technical bar is high and the application volume is punishing, so treat these as a long shot you prepare for properly rather than a default. What makes them worth the effort is conversion, because an intelligence internship at one of these firms turns into a full-time analyst seat more reliably than any other route in the industry.

Financial services. Banks, payment processors, and insurers built mature intelligence programs earlier than most sectors and have the budget to carry juniors while they learn. Fraud and brand protection teams inside these organizations are frequently the easiest way in, and they do genuine CTI work under a different name.

Government, defense, and cleared contract work. In the US market this is the largest single pool of openings that will genuinely take someone junior, because contractors like Booz Allen, CACI, and ManTech staff seats continuously and train into them. ClearanceJobs is the board that matters here. The clearance is both the barrier and the moat. Obtaining one takes months and sometimes more than a year, it usually requires citizenship, and once you hold it the compensation premium follows you for the rest of your career.

ISACs and sector sharing bodies. These are underrated to the point of being a genuine market inefficiency. FS-ISAC runs a formal CTI talent pipeline that moves people from a twelve-week paid internship into a one-year co-op and then into a full-time junior intelligence analyst seat in its Global Intelligence Office. Health-ISAC has historically staffed its Threat Operations Center with explicitly entry-level CTI analysts working alongside subject matter experts from member hospitals. Very few candidates think to check these organizations' career pages, which is exactly why you should.

In-house enterprise teams. Large technology firms, telcos, energy companies, and retailers increasingly run their own intelligence functions. They post junior roles less often than the categories above, and when they do, they tend to fill them internally. That is not a reason to skip them. It is a reason to read the section on internal transfers below.

National CERTs, law enforcement, and regional markets. Outside the US the map changes shape. European demand runs on NIS2 and DORA compliance pressure, with the UK holding the continent's largest CTI talent pool and anchoring much of it around NCSC-adjacent work. Gulf markets are expanding quickly on tax-free packages. India has turned into a major hub as global security operations centers scale there. Across most of these regions, national CERTs and sector sharing bodies will take a junior far more readily than a commercial vendor will, and in a lot of countries they are simply the best training ground available.

Nine differently shaped keys fanned toward one gold keyhole, showing varied job titles leading to the same CTI work

Different key shapes, same lock. The job title on the posting rarely matches the work behind it.

The Job Titles That Are Really CTI Jobs

If you type "threat intelligence analyst" into a job board and filter to entry-level, you will see a small fraction of the roles that would actually start your CTI career. The title is a poor index of the work.

Here is what to search for instead, and why each one counts:

Title you will see Why it is a CTI on-ramp
SOC Analyst Tier 1, Security Analyst I Alert triage teaches you what intelligence has to be useful for. The classic pivot, usually within twelve to eighteen months.
Threat Research Intern, Intelligence Intern Direct entry at vendors. Highest conversion rate of any path.
Brand Protection Analyst Phishing infrastructure, impersonation domains, takedowns. This is collection and pivoting under another name.
Fraud Analyst, Fraud Intelligence Analyst Underground marketplaces, stolen credentials, actor behavior. Heavy overlap with the Telegram and forum ecosystem a CTI analyst monitors.
Dark Web Analyst, OSINT Analyst Collection tradecraft with an intelligence output, frequently in the same team as CTI.
Vulnerability Intelligence Analyst Exploitation tracking and prioritization, which is the single most requested intelligence product from executives.
Detection Engineer (junior), Content Analyst The consumption side. You learn what makes intelligence operational by having to write the rule.
Cyber Intelligence Analyst, All-Source Analyst Government and contractor phrasing for the same discipline.
Associate Analyst, Junior Analyst, Analyst I Generic titles at vendors and ISACs that hide a specific CTI mandate in the description.

The practical instruction is to search the body of the posting rather than the title. Feed the board the vocabulary of the work itself, meaning terms like MITRE ATT&CK, threat actor, MISP, OpenCTI, TTP, indicators of compromise, and intelligence requirements. A posting titled "Security Analyst I" that asks for ATT&CK mapping and actor tracking in its responsibilities is a CTI job wearing a conservative HR title, and far fewer people will have found it.

If you are weighing the SOC route specifically, our comparison of SOC analyst and threat intelligence analyst roles covers what transfers and what does not.

Where to Search, Ranked by What Actually Works

The ISC2 hiring managers were asked directly where they source early-career candidates. Standard job postings and staffing firms tied at 57%, internships came in at 55%, apprenticeships at 46%, and colleges and universities fourth. Job boards matter, but they are barely ahead of channels most candidates never use at all.

Order your effort accordingly.

Company career pages come first, because postings appear there before they syndicate and because applying at the source skips a layer of aggregator noise. Build a list of thirty to fifty target employers across the seven categories above and check them on a schedule. This is tedious and it is the highest-conversion activity available to you.

Specialist boards come second. ClearanceJobs for cleared US work. The individual career pages of FS-ISAC, Health-ISAC, E-ISAC, MS-ISAC, and their regional equivalents. University career portals if you still have access to one, because vendor early-career programs post there with deadlines that are months earlier than the public listing.

Internships and apprenticeships come third and deserve more weight than most career-changers give them. If you are a student, or can structure your life around a twelve-week paid placement, this is statistically the strongest path in the data. It is also the only one where the employer has explicitly budgeted to train someone with no experience.

Communities come fourth. A large share of CTI roles are filled through referral before they are ever posted, because the teams are small and the hiring managers know each other. Being a recognizable, useful presence in intelligence-sharing communities, at conferences, and in the public conversation around actor tracking is not networking theater. It is how a four-person team finds its fifth person.

General aggregators come last. Use LinkedIn and Indeed for discovery, then apply through the company site.

The Path Almost Nobody Plans For

Twenty-two percent of the hiring managers ISC2 surveyed had sourced early-career cybersecurity talent from other departments inside their own organization. Of those, 85% pulled from IT and 68% from technical support and help desk, which is unsurprising. What is genuinely interesting is the rest of the distribution: 39% found candidates in finance, 38% in HR, 37% in communications, 35% in customer service, and 31% in marketing.

Read that as a strategy rather than a statistic. If you are already employed anywhere inside an organization that has a security team, you are competing in a pool of a handful of internal applicants rather than several hundred external ones. You have a referral channel, a track record someone can verify, and a manager who can vouch for you. The most reliable way to get an entry-level CTI job is often to already work at the company.

If that is your situation, the move is to make yourself visibly useful to the security team before a role opens. Ask for whatever intelligence reporting they publish internally and actually read it, then volunteer for the tedious collection task nobody on the team wants. The step that changes how they see you is writing something short and accurate about a threat affecting your own business unit and sending it to the person who would otherwise have had to write it.

How to Land One

The mechanics of getting hired have changed more in the last two years than the job itself has. The ISC2 hiring report's foreword describes recruiters facing more than a thousand applications in the first day of a posting, most of them polished by AI and delivered by automation. Volume is no longer a strategy that works for anyone, including the people using it.

What follows is what survives that filter.

A portfolio, because 84% of employers test you anyway. Most organizations in the ISC2 study use skills-based assessments for entry- and junior-level applicants. If you are going to be tested on whether you can do the work, arriving with proof that you already have is the shortest route through the process. Publish three to five short intelligence products that a stranger can read in ten minutes each. An actor profile built entirely from public reporting works well as a first one. So does a campaign write-up carrying your own ATT&CK mapping, an infrastructure pivot that takes a single indicator out to a cluster, or an assessment deliberately written for a reader who is not technical. Use real confidence language, and show your reasoning where you were uncertain rather than hiding it. The specific format matters less than the fact that a hiring manager can read three pieces and see how you think.

Certifications that are actually reachable. ISC2 found that 89% of hiring managers would consider a candidate holding only an entry-level cybersecurity certification, and 90% would consider one with only prior IT experience. Both of those beat education alone. The certifications worth your money early are CompTIA Security+ for the foundation, CySA+ if you are heading toward the SOC route, and ISC2's Certified in Cybersecurity. For CTI specifically, arcX publishes a free CTI 101 course and a CREST-accredited practitioner track, and DFIR Diva maintains a list of free and low-cost CTI training that is the best-curated resource of its kind. The GIAC GCTI and SANS FOR578 are excellent and belong later in your career, once you have operational time behind you and, ideally, an employer paying for them.

A resume that names things. Screening for entry-level roles is a shared job between the hiring manager and HR in 53% of organizations, and handled by HR and software alone in another 13%. That means the document has to survive keyword matching and then impress a practitioner. Name the specific tools you have actually used rather than describing capabilities in the abstract. MISP, OpenCTI, MITRE ATT&CK Navigator, VirusTotal, urlscan.io, Shodan, Censys, Maltego, whatever SIEM you have touched. Link the portfolio in the header where it cannot be missed.

Interview preparation aimed at judgment, not trivia. Junior CTI interviews test whether you can reason under uncertainty and communicate the result. Expect to be handed a report or a set of indicators and asked what you would do next, who you would tell, and how confident you are. Expect a question about a time you were wrong. Practice explaining a technical finding to a hypothetical executive in ninety seconds without jargon, because that is the actual job and almost nobody rehearses it. The same handful of question patterns recur across CTI interviews, so keep a running list of the ones you get asked and rehearse your answers out loud before the next one.

A cleaned-up public presence. More than half of the hiring managers surveyed said they have passed on a candidate because of their social media activity. In a field built on trust and on handling sensitive information, this screening is more aggressive than in most professions. Audit what is public under your name before you start applying.

Applications that are few and specific. Twenty-one percent of entry-level cybersecurity roles are filled in under a month and another 40% within one to three months, so the window on any given posting is short. Apply early and to fewer roles, tailoring each one against the responsibilities the description actually lists. A short note explaining why that team's particular mission interests you will outperform fifty generic submissions, and it costs a great deal less of your life.

What to Skip

Some of the standard advice is actively counterproductive, so here is the honest version.

Do not stack certifications while you have no output. A candidate with four certificates and nothing written will lose to a candidate with Security+ and a public portfolio of five investigations, every time, at every employer I have seen hire at this level.

The GCTI and the CISSP are both worth having eventually and both wrong at the start, because they are built for practitioners with real operational time behind them. Taking either early signals that you optimized for the credential rather than the craft, and the CISSP will not issue as a full certification at all until you meet its experience requirement.

Degree requirements are softer than they look on the page. Around a quarter of hiring managers who recruit from universities have taken candidates out of programs unrelated to computing, and the ISC2 data consistently shows experience and certifications outweighing education on its own.

Be skeptical of any bootcamp promising job placement in this specific field. CTI hiring runs on demonstrated analysis and on trust networks, and a twelve-week program cannot manufacture either one for you.

Do not apply exclusively to roles with "threat intelligence" in the title. This is the single most common mistake, and it removes most of the on-ramps from your search before you begin.

Ladder with dissolving lower rungs and solid gold upper rungs, showing AI absorbing routine junior analyst tasks

The bottom rungs are dissolving. The climb into CTI now starts a step higher than it used to.

The AI Question, Answered Honestly

You have probably read that AI is closing the entry-level door. The evidence is genuinely mixed, and you deserve the real picture rather than the reassuring one.

ISC2 surveyed 856 practitioners who use AI in their work in May 2026. Fifty-three percent said AI is creating new types of entry-level roles. Respondents split almost evenly on whether AI has reduced hands-on learning opportunities in their workplace, with 37% saying it has against 36% saying it has not. That split is the honest headline, and it matters, because the tasks AI absorbs first are the enrichment and summarization work that used to be how juniors learned.

The countervailing finding is that 62% do not believe AI has reduced the need for foundational cybersecurity skills. Two-thirds of the same group reported spending more time deciding whether to trust AI output. The work that is growing is judgment about machine-generated analysis, which is the same skill that has always separated a CTI analyst from a feed.

What this means for you practically: automation is compressing the part of the junior role that was mechanical, and expanding the part that requires you to be right about something. Build the second thing.

Where CTI Academy Fits

Everything above assumes you can do the work when you get in the room. Reading about collection, pivoting, and actor tracking teaches you the vocabulary. It does not give you the reps, and reps are what the skills-based assessment in your interview is measuring.

That gap is the reason our platform is built the way it is. NullBase puts you inside a simulated underground forum so you can practice persona tracking, listing analysis, and channel monitoring without operating against live criminal infrastructure. LeakLens gives you real-shaped credential and breach data to work through as an analyst would, which is where a great deal of entry-level CTI work genuinely happens. The SOC Simulator puts you on the receiving end of intelligence, so you learn what a finished product feels like to the person who has to act on it. And because the landscape moves weekly, we run todayincyber.io to keep the day's signal in one place.

If you want the structured version of the path this article describes, from fundamentals through the tradecraft that shows up in interviews, start with the Hunter track.

Frequently Asked Questions

Are there really entry-level threat intelligence jobs, or is it a mid-career field?

Both are true, which is why the question is confusing. Genuine entry-level CTI seats exist at MSSPs, vendors, ISACs, and government contractors, and internships convert into them reliably. Standalone in-house CTI teams rarely hire externally at the junior level because they average four people. Aim at the categories that hire volume rather than the small internal teams.

Do I need a SOC job first to get into threat intelligence?

It is the most common route, not a requirement. Twelve to eighteen months in a SOC gives you the detection context that makes intelligence useful, and internal pivots from SOC to CTI happen constantly. Intern-to-analyst pipelines at intelligence vendors and ISACs skip that step entirely, and fraud, brand protection, and OSINT roles are equally valid on-ramps.

What certification should I get first for a CTI career?

CompTIA Security+ or ISC2's Certified in Cybersecurity for the foundation, since 89% of hiring managers said they would consider a candidate holding only an entry-level certification. Add arcX's free CTI 101 for the discipline-specific vocabulary. Leave the GIAC GCTI until you have operational experience and preferably an employer funding it.

How long does it take to get an entry-level CTI job?

Plan on six to eighteen months of deliberate preparation if you are starting from adjacent IT or from a non-technical background, and treat that time as portfolio-building rather than waiting. Once you are applying, the roles themselves move quickly, with 21% of entry-level cybersecurity positions filled in under a month and another 40% within three.

Can I get a threat intelligence job with no degree?

Yes, and the data supports it more strongly than most candidates believe. ISC2 found 90% of hiring managers would consider a candidate with only prior IT work experience, and 89% would consider one with only an entry-level certification, both of which outranked education alone. Demonstrated analysis matters more than the credential that got you into the room.

Is AI eliminating junior threat intelligence roles?

Not eliminating, but reshaping. In ISC2's 2026 research, 53% of practitioners said AI is creating new types of entry-level roles, while opinion split evenly on whether it has reduced hands-on learning opportunities. The routine enrichment work is shrinking and the judgment work is growing, so build toward the analysis rather than the collection mechanics.

Where are entry-level CTI jobs outside the United States?

The UK holds Europe's largest CTI talent pool, with demand concentrated in financial services and NCSC-adjacent work. NIS2 and DORA compliance are driving hiring across Germany, the Netherlands, and France. Gulf markets are expanding quickly, India is scaling as global security operations centers grow there, and national CERTs across most regions hire juniors more readily than commercial vendors do.

What does an entry-level threat intelligence analyst actually do all day?

Monitoring sources and feeds, triaging what comes in, enriching indicators, tracking a small assigned set of actors or campaigns, and drafting reporting that a senior analyst reviews. You are running the collection and processing stages of the intelligence lifecycle while learning the analysis stage from someone who has done it longer.

Sources

Read more at CTI Academy Blog