Full-Time

Senior Intelligence Analyst 2

Updated on 9/4/2026

Flashpoint

Flashpoint

201-500 employees

Cybersecurity intelligence platform and services

No salary listed

No H1B Sponsorship

Remote in USA

Remote

Periodic travel is required for in-person client engagements and briefings.

US Top Secret Clearance Required

Category
Cybersecurity (1)
Required Skills
Penetration Testing
Linux/Unix

Get referred to Flashpoint

See people who can refer or advise you

Requirements
  • Have a proven track record of delivering actionable intelligence in support of high-impact national security missions and rapidly pivoting across dynamic global regions as intelligence requirements evolve.
  • Have advanced Open Source Intelligence and Deep & Dark Web research experience, including engaging threat actors in online communities while maintaining credible online personas under managed attribution.
  • Have experience working with novel and publicly exposed datasets and recognizing how adversaries can combine offensive cyber capabilities and exposed data to create real-world risk.
  • Bring an offensive-security perspective from hands-on red teaming, penetration testing, or equivalent work and use it to anticipate adversary operations.
  • Have a strong command of Linux and the command line, with intermediate- to advanced-level scripting and automation ability for manipulating and formatting large datasets.
  • Possess an advanced understanding of network and telecommunications technologies and topologies.
  • Have produced accurate investigations and key judgments for finished intelligence reports and presented complex findings to broad audiences, including community calls, executive-level briefings, and direct client engagements.
  • Have advanced Open Source Intelligence tradecraft and methodology, including Deep & Dark Web research and managed-attribution operations.
  • Have demonstrated offensive-security capability, such as OSCP or equivalent hands-on red teaming and penetration testing experience, and an adversarial mindset.
  • Have a track record as an intelligence analyst, ideally supporting public-sector or national-security missions.
  • Have strong writing skills and experience producing finished intelligence products, along with communication and presentation skills for technical and executive audiences.
  • Be willing to travel periodically for in-person client engagements and briefings.
Responsibilities
  • Lead high-impact analytical efforts across diverse global regions, use advanced tooling to execute rapid assessments, and directly support strategic clients in fulfilling critical security missions.
  • Conduct comprehensive analysis across Open Source Intelligence and Deep & Dark Web sources, focusing on novel, publicly exposed data to develop intelligence on threats to national security.
  • Run proactive, covert engagement with threat actors across underground environments and chat services, using managed-attribution tradecraft to elicit intelligence and identify emerging risks.
  • Apply an offensive-security lens to exposed-data investigations, assessing how adversaries could operationalize discovered information and where the real risk lies.
  • Monitor and collect high-signal data from illicit marketplaces, forums, and encrypted chat platforms using specialized keywords and patterns within Flashpoint tools.
  • Synthesize complex raw data into analytic judgments by assessing credibility, determining client relevance, and supporting client deliverables and intelligence requirements.
  • Safely navigate virtual environments, articulate the security safeguards required for each task, and comply with Flashpoint and Intel team policies, including Rules of Engagement.
  • Create finished intelligence products and peer-review others’ work for analytic accuracy and conformity with Flashpoint report-writing standards.
  • Brief clients and communities directly, including through in-person engagements, and propose relevant content for external publication.
  • Act as an internal subject-matter expert, document team processes, and mentor new and junior analysts.
Desired Qualifications
  • SANS/GIAC certification or equivalent experience.
  • TS/SCI clearance.

Flashpoint provides a suite of cyber threat intelligence products and services to help organizations detect, analyze, and mitigate threats. Its core is the Flashpoint Intelligence Platform, with modules like Flashpoint Automate, Compromised Credentials Monitoring, Payment Card Fraud Mitigation, Brand Exposure Protection, and VulnDB. It also offers Threat Response Readiness, Professional Services, Managed Intelligence, Tailored Reporting, and Curated Alerting to support incident preparation and response. The platform is sold on a subscription basis, differentiating by an integrated, modular threat intelligence approach that enables end-to-end protection across sectors such as finance, retail, healthcare, and technology.

Company Size

201-500

Company Stage

Late Stage VC

Total Funding

$77M

Headquarters

New York City, New York

Founded

2010

Get referred to Flashpoint

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Flashpoint launched Custom Summary Builder at Black Hat USA 2026, deepening AI workflow stickiness.
  • The 2026 midyear report showed 1.7 billion credentials and 45% RaaS growth.
  • Flashpoint named a Gartner Challenger in 2026, strengthening enterprise sales credibility.

What critics are saying

  • Crowded CTI rivals like CrowdStrike, Mandiant, Palo Alto Networks, and Recorded Future compress pricing.
  • Flashpoint's free assessment commoditizes value and invites buyers to replace subscriptions with internal workflows.
  • Audax majority growth ownership, announced 2026, demands faster exits and disciplined expansion.

What makes Flashpoint unique

  • Flashpoint's PSC methodology sources threats directly from underground forums and illicit marketplaces.
  • Flashpoint Ignite won SC Award 2026 for transforming cyber, fraud, vulnerability, and physical intelligence.
  • Flashpoint's AI Workspace standardizes investigation summaries for executives, analysts, and MSSP clients.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Complete Health & Wellness Benefits

Competitive Salary & Compensation Plans

Wellness Perks & Programs

401k Plan with Company Match

Balanced Paid Time Off

Company Paid Holidays

Remote Worker Allowances

Learning & Development Opportunities

Recognition & Cultural Initiatives

Growth & Insights and Company News

Headcount

6 month growth

-1%

1 year growth

-1%

2 year growth

-1%
Associated Press
Aug 3rd, 2026
Flashpoint launches AI-driven Custom Summary Builder for threat intelligence investigations

Flashpoint has launched its Custom Summary Builder within the AI Workspace for Investigations Management at Black Hat USA 2026. The new feature, built into Flashpoint Ignite, enables security teams to tailor AI-generated investigation findings for different audiences whilst standardising intelligence delivery. Analysts can select from sections including Executive Summary, Key Observations, Actors and Entities, and Tactics, Techniques, and Procedures to create customised intelligence reports. Configurations can be saved as reusable templates for consistent reporting formats. The tool expands Flashpoint's AI Workspace capabilities, which help analysts collect evidence, synthesise findings, and communicate intelligence from a single platform. Features include multi-source data aggregation, AI-assisted investigation analysis, and fully sourced, auditable output. Custom summary templates are now available to Flashpoint Ignite customers with access to Investigations Management.

MSSP Alert
Feb 5th, 2026
Flashpoint's Free Threat Intelligence Assessment Gives MSSPs Tools and Insight

Flashpoint's free Threat Intelligence assessment gives MSSPs tools and insight. February 5, 2026 In world of increasingly complex cyber threats and sophisticated bad actors that wield them, threat intelligence programs are crucial tools organizations can use to protect themselves. They pull in data from multiple sources, analyze and correlate it to identity threats, see patterns, and understand their adversaries, then use that information to build their defenses. Enterprises know this. According to cloud security platform vendor Breachsense, 93% have threat intelligence programs. The question becomes how effective are those programs, and how well are they using that information. "Most organizations today have some form of threat intelligence, but far fewer have taken a step back to evaluate how well that intelligence actually supports critical decisions and operations that protect their people and assets," Steven Weinstein, senior vice president of Intelligence at threat intelligence firm Flashpoint, told MSSP Alert. For many companies, such programs grow organically, inside security operations centers (SOCs) and vulnerability and fraud teams, but without shared frameworks for prioritizing requirements or collecting feedback, Weinstein said. "Over time, teams accumulate tools, feeds, and reports, but struggle to answer basic questions like, are we collecting the right intelligence? Is it reaching the right people? Is it driving timely action?" he said. "Without defined intelligence requirements and feedback loops, it's difficult for teams to assess whether they're missing upstream threats, over-prioritizing noise, or relying on generic intelligence that isn't tailored to their environment." Assessing the intelligence. Flashpoint this week unveiled its new free Threat Intelligence Capability Assessment, which organizations can use to evaluate how the intelligence works across the spectrum, touching on requirements, tasking, feedback, and then re-tasking, according to the company. Beyond putting a score on the program, the assessment also is designed inform what the information means for operations, find what could be limiting the effect of the threat intelligence, steps for strengthening the intelligence workflows, and develop a 90-day planning framework. The differentiator. It's what separates Flashpoint's threat intelligence assessment from those of others, Weinstein said. "Many teams equate volume with quality, assuming that more feeds, more alerts, or more dashboards automatically translate into better intelligence," he said. "In practice, teams often don't have clear visibility into where their intelligence comes from, how well it aligns to their most important risks, or whether it's actually influencing decisions." Most other assessments focus on inputs, such as tools, headcount, or abstract maturity levels, he said. Flashpoint's assessment helps surface gaps in the intelligence operations by focusing on how it's scoped, collected, analyzed, and acted on, rather than just whether it exists. A big market. The importance of threat intelligence can be seen in the expected growth of the global market, which analysts with Fortune Business Insights expect to jump from $6.87 billion to $31.58 billion by 2034. Cybercrime isn't going anywhere, they wrote, noting that on average, a new company is victimized with ransomware every 10 seconds around the globe. It's also a crowded market with dozens of vendors that range from CrowdStrike, Mandiant, and IBM to Palo Alto Networks and Recorded Future. Intelligence for MSSPs. Threat intelligence systems are also important to MSSPs and other security services vendors, which are increasingly assuming the role of trusted security advisers. Flashpoint's new assessment "serves as a conversation and planning tool," Weinstein said. With it, MSSPs can baseline a client's entire intelligence capabilities rather than just focusing on tools, identify where intelligence is breaking down, use services to close gaps rather than address "assumed needs," and demonstrate value over take by proving progress when organization retake the assessment, he said. "Many service providers are being asked to deliver more proactive, intelligence-led outcomes," Weinstein said. "This assessment helps MSSPs and MSPs frame that work clearly, set realistic expectations, and guide clients toward more effective use of intelligence, whether the provider is delivering collection, analysis, operational support, or advisory services." Jeffrey Burt has been a journalist for almost 40 years, moving from general-circulation newspapers to IT news sites in 2000. He's an expert analyst and writer on cybersecurity, data center infrastructure, AI, and a host of other subjects for a range of organizations, including CyberRisk Alliance, eWEEK, Techstrong Group, The Next Platform, and The Register. Armed with the technology, fraudsters can automate, accelerate, and scale their campaigns, targeting more victims and stealing more money and information. RiskProfiler's strategic partnership with ACPL Systems expands its footprint across Australia, New Zealand, and India. The Darktrace / SECURE AI solution is designed to help organizations more safely integrate and manage AI in their environments. Related events. Related Terms

El Referente
Sep 15th, 2025
Vidext raises 6 million in a round led by Flashpoint to scale AI video automation.

Vidext, a 100% online production studio, has closed a Series A of 6 million euros led by Flashpoint, an international technology investment firm with about 500 million dollars in assets under management.

Business Wire
Aug 5th, 2025
Flashpoint Unveils AI Summarization for Search and Investigations at Black Hat USA 2025

Flashpoint unveils AI Summarization for Search and Investigations at Black Hat USA 2025.

SiliconANGLE Media
Aug 5th, 2025
Flashpoint debuts AI features to streamline search and reporting workflows

Business risk intelligence startup Flashpoint today announced the release of two new artificial intelligence-powered capabilities - AI Summarization for Search and AI Summarization for Investigations.