Full-Time

Senior Cyber Incident Response Threat Intelligence Analyst

Posted on 5/9/2026

S&P Global

S&P Global

10,001+ employees

Global financial data, analytics, ratings

Compensation Overview

$100k - $185k/yr

+ Annual Incentive Plan

Washington, DC, USA + 7 more

More locations: Texas, USA | Jackson Township, NJ, USA | Virginia, USA | Colorado, USA | New York, NY, USA | Massachusetts, USA | North Carolina, USA

Remote

Category
IT & Security (1)
Required Skills
TCP/IP
Splunk
Requirements
  • Working knowledge of common cyber attacks, tools, and attacker tradecraft; ability to map activity to MITRE ATT&CK and articulate likely TTPs.
  • Demonstrated experience handling security events in critical environments and applying intelligence to accelerate triage and response.
  • Experience analyzing system, application, and cloud/SaaS logs to investigate security and operational issues; comfort enriching with IOCs and behaviours.
  • Hands-on experience with a SIEM (Splunk preferred) for investigations, alert creation, reporting, and threat hunting.
  • Ability to produce clear, actionable intel and incident reports, including executive-ready summaries and visuals.
  • Familiarity with threat intel workflows: collection planning, source evaluation, indicator lifecycle, PIRs, TLP, and feedback loops to detections.
  • Experience with one or more TIPs or intel data sources (e.g., MISP, OpenCTI, Recorded Future) and STIX/TAXII concepts.
  • 3+ years of information security experience with a focus on incident response, threat hunting, or threat intelligence.
  • Excellent communication skills for varied business and technical audiences; strong presentation skills.
  • Comfortable working in a fast-paced environment; passion for cyber security.
  • Advanced knowledge of network protocols (TCP/IP, HTTP) and operating systems.
Responsibilities
  • Coordinate and triage response to cybersecurity events and conduct forensic analysis across endpoints, networks, cloud, and SaaS.
  • Integrate threat intelligence into investigations (e.g., enrich IOCs, map activity to MITRE ATT&CK, identify likely threat actors/TTPs, and assess potential impact).
  • Understand the threat landscape through collaboration with industry peers, FS-ISAC, trust groups, and commercial/open-source intelligence, translating insights into actionable recommendations.
  • Develop, maintain, and operationalize Incident Response playbooks and SOPs; include PIRs (Priority Intelligence Requirements), collection plans, and feedback loops to refine detections.
  • Work closely with the SOC to investigate incidents and deliver containment, remediation, and root cause analysis; produce high-quality intel-informed incident reports.
  • Create and tune detections (e.g., SIEM/SOAR, EDR) using intelligence signals (TTPs, behaviors, YARA/Sigma where applicable).
  • Produce and present consumable intelligence outputs (e.g., flash alerts, threat overviews, executive briefs) tailored to technical and non-technical stakeholders.
  • Contribute to vulnerability/threat surfacing (e.g., emerging CVEs, exploit trends) and advise on risk-based prioritization.
  • Deliver actionable incident and hunting metrics to management; assess detection coverage and recommend improvements.
  • Follow the end-to-end incident response lifecycle and support post-incident lessons learned with intelligence-driven enhancements.
  • Build an understanding of key S&P technology, systems, and business practices to contextualize threats and drive pragmatic defenses.
  • Participate in information-sharing activities (e.g., FS-ISAC submissions) in line with TLP and legal/compliance requirements.
Desired Qualifications
  • Experience in the financial services industry.
  • Familiarity with threat hunting techniques (hypothesis-driven, ATT&CK-aligned, behavior-based).
  • Windows and Linux administration tools and concepts.
  • Understanding of threat actors and the cybercrime ecosystem, including initial access vectors, monetization paths, and supply-chain/SaaS attack patterns.
  • Exposure to malware/TTP analysis at a functional level (family identification, persistence/discovery behaviors) and creation of detections (e.g., Sigma/YARA) is a plus.
  • Experience producing finished intelligence products (tactical through executive) and briefing senior stakeholders.
  • Relevant certifications (e.g., GCTI, GCFA/GCFR, GCIH, FOR578) or equivalent experience.
  • Familiarity with information-sharing standards and practices (FS-ISAC, TLP) and legal/compliance considerations.
  • Knowledge of cloud provider threat models and telemetry (AWS, Azure, GCP, M365/SaaS).
  • Second language and/or geopolitical awareness for actor context is a plus.

S&P Global provides financial information and analytics to investors, corporations, and governments. Its offerings include credit ratings, market intelligence, and indices, delivered through subscription models, licensing, and transaction-based services. The company’s products combine ratings assessments, data-driven research, and benchmark indices to help clients assess risk, evaluate markets, and make informed decisions. Unlike firms that specialize in a single domain, S&P Global combines multiple core businesses—Ratings, Market Intelligence, Dow Jones Indices, and Platts—into an integrated platform that delivers comprehensive insights across credits, markets, energy, and ESG data. The company’s goal is to enable better decision-making, risk management, and growth for its clients while upholding corporate responsibility and sustainable practices.

Company Size

10,001+

Company Stage

IPO

Headquarters

New York City, New York

Founded

1917

Simplify Jobs

Simplify's Take

What believers are saying

  • Q1 2026 revenue surged 10% to $4.171 billion on ratings and indices growth.
  • With Intelligence $1.8 billion acquisition bolsters markets data in October 2025.
  • Mobility spinoff mid-2026 refocuses on high-margin ratings and data moat.

What critics are saying

  • Mobility spinoff mid-2026 triggers investor sell-off and multiple contraction.
  • Bloomberg captures cement benchmark share with faster feeds in 3-6 months.
  • Iran conflict escalation slashes Energy revenue 20% beyond Q2 2026.

What makes S&P Global unique

  • S&P Global Ratings commands 25.4% US credit ratings market share.
  • HorizonsAgents AI suite benchmarks decarbonisation using proprietary Energy Horizons data.
  • 16 new Platts cement benchmarks enhance transparency amid EU carbon rules.

Help us improve and share your feedback! Did you find this helpful?

Your Connections

People at S&P Global who can refer or advise you

Benefits

Health Insurance

Unlimited Paid Time Off

Professional Development Budget

401(k) Company Match

Family Planning Benefits

Employee Discounts

Growth & Insights and Company News

Headcount

6 month growth

-3%

1 year growth

0%

2 year growth

-3%
PR Newswire
Mar 31st, 2026
S&P Global, Cambridge Associates and Mercer launch private markets datasets for credit and real assets

S&P Global has launched the S&P Global, Cambridge Associates, Mercer Private Markets Performance Analytics datasets, the first release from a collaboration announced in 2025. The datasets provide standardised data across thousands of funds in private credit and real assets, with private equity datasets following later in 2026. Powered by S&P Global's iLEVEL platform, the datasets use a proprietary taxonomy to standardise, aggregate and anonymise data, enabling investors to compare performance, manage risk and assess portfolio impacts. The service supports both limited partners and general partners in analysing performance and making allocation decisions. The datasets are now available globally, with use cases including portfolio monitoring, risk management and competitive insights. Future releases will include data feed APIs and integrated software solutions.

PR Newswire
Mar 31st, 2026
S&P Global names Firdaus Bhathena as chief technology and transformation officer

S&P Global has appointed Firdaus Bhathena as Executive Vice President and Chief Technology and Transformation Officer, effective 27 April 2026. Bhathena will lead a unified enterprise technology organisation to accelerate growth, AI capabilities and strategic transformation, reporting directly to President and CEO Martina Cheung. Bhathena joins from FIS Global, where he served as Global Chief Technology Officer, leading a team of over 24,000 colleagues responsible for technology infrastructure, software product development and data and AI innovation. Previously, he was Senior Vice President and Enterprise Chief Digital Officer at CVS Health and co-founded several venture-backed startups, including WebLine Communications, which was acquired by Cisco Systems. The newly created role reflects S&P Global's strategy to enhance its AI capabilities and technology-driven transformation.

Yahoo Finance
Mar 29th, 2026
S&P Global shares drop 22% despite 54-year dividend streak and $14B revenue

S&P Global Inc. has declined roughly 22% over the past six months despite generating over $14 billion in annual revenue and maintaining a 54-year dividend increase streak. The decline reflects market concerns around AI disruption and uncertainty from its IHS Markit integration. The company operates across five segments—Market Intelligence, Ratings, Commodity Insights, Indices and Mobility—with largely recurring revenues. Its competitive advantage stems from network effects, regulatory entrenchment and proprietary data, including assets like CARFAX. The credit ratings division operates within an oligopoly alongside Moody's and Fitch. Analysts from Compounding Dividends highlight secular tailwinds from rising global debt and passive investing growth. Whilst risks include regulatory scrutiny, issuance volatility and AI disruption, the company's entrenched market position and data advantage present a compelling long-term investment case.

Yahoo Finance
Mar 24th, 2026
Micron Technology and S&P Global: Two growth stocks that could double your $2,000 investment

S&P Global, a finance-focused company with credit rating and market intelligence businesses, has averaged annual returns of 16.6% over the past decade. The company owns the S&P 500 index and operates the world's largest credit rating service. The stock has declined 18% recently following weaker-than-expected management projections. However, S&P Global is spinning off its Mobility segment, which includes CarFax, to generate funds for growth whilst focusing more on its core financial businesses. Micron Technology, a semiconductor company specialising in memory and storage chips, has averaged nearly 45% annual gains over the past decade and surged over 300% in the past year. Second-quarter revenue tripled year-over-year driven by strong AI-related demand. The stock trades at a forward price-to-earnings ratio of 12.0, slightly above its five-year average of 11.4.

Yahoo Finance
Mar 19th, 2026
S&P 500 drops below 200-day average as oil surges to $112 amid Middle East escalation

The S&P 500 fell below its 200-day moving average for the first time since May 2023 as US stocks declined on Thursday amid surging oil prices and escalating Middle East conflict. The S&P 500 dropped 0.7%, whilst the Dow Jones Industrial Average fell 0.8% and the Nasdaq Composite slid 0.8%. Brent crude rose 4% to $112 per barrel, and West Texas Intermediate climbed nearly 1% to $97 following attacks by Iran and Israel on energy facilities in Qatar and Iran. President Donald Trump threatened retaliatory strikes if further damage occurs. Micron Technology shares fell 4% despite beating analyst expectations with revenue of $23.86 billion and adjusted earnings of $12.20 per share. Analysts attributed the decline to profit-taking.