Threat Intelligence Analysts research and monitor cyber adversaries, malware campaigns, and emerging attack techniques to help organizations anticipate and defend against attacks before they happen. They collect data from open-source intelligence, dark web forums, malware samples, and threat feeds, then analyze patterns to produce actionable reports for security teams, executives, and incident responders. Their work bridges technical analysis with strategic communication, translating raw indicators of compromise into risk assessments that shape security investments and defensive priorities.
| Entry level | $68,000 |
| Median | $105,000 |
| Senior | $140,000 |
| Top 10% | $175,000 |
| Job growth | +32% |
| Professionals in the USA | 0.15 million |
| Typical hours/week | 42 hrs |
| Remote work share | 55% |
| Annual job openings | 17,000/yr |
| Demand | Very High |
AI and machine learning tools are increasingly used to automate data collection, correlation, and initial triage of threat indicators, speeding up analysis. However, interpreting attacker intent, contextualizing geopolitical or sector-specific risks, and making strategic recommendations still require human judgment. Analysts who leverage AI tools for enrichment and automation will remain valuable, while those who only perform manual data gathering are most at risk.
Automation exposure: Automated collection and aggregation of IOCs, malware signature matching, log correlation, phishing detection, and basic report generation can increasingly be handled by AI-driven SOAR/SIEM platforms and threat intel platforms.
The human edge: Humans excel at contextual reasoning about adversary motivation, geopolitical nuance, creative hypothesis-driven hunting, communicating risk to executives, and making judgment calls under uncertainty—areas where AI still falls short.
Figures are estimates for exploration — verify current data with BLS.gov.