Cyber Threat Intelligence Engineer IV

Edward D Jones & Co LP

  • Saint Louis, MO
  • 4 days ago

    Highlights

    Team Overview: We're looking for a Cyber Threat Intelligence (CTI) Analyst to join our security organization and serve as a connective force across our Security Operations Center (SOC), Detection Engineering, Red Team, and Exposure Management functions. You'll translate raw threat data into decisions: which adversary behaviors get new detections, which techniques the red team should emulate next, and which exposures matter most given who's actually targeting organizations like ours.

    Numbers & Facts

    LocationSaint Louis, MO

    Description

    This job posting is anticipated to remain open for 30 days, from 27-Jul-2026. The posting may close early due to the volume of applicants.

    Join a financial services firm where your contributions are valued. Edward Jones is a Fortune 500¹ company where people come first. With over 9 million clients and 20,000 financial advisors across the U.S. and Canada, we're proud to be privately-owned, placing the focus on our clients rather than shareholder returns.

    Behind everything we do is our purpose: We partner for positive impact to improve the lives of our clients and colleagues, and together, better our communities and society. We are an innovative, flexible, and inclusive organization that attracts, develops, and inspires performance excellence and a sense of belonging.

    People are at the center of our partnership. Edward Jones associates are seen, heard, respected, and supported. This is what we believe makes us the best place to start or build your career.

    View our Purpose, Inclusion and Citizenship Report.

    ¹Fortune 500, published June 2024, data as of December 2023. Compensation provided for using, not obtaining, the rating.

    Team Overview:

    We're looking for a Cyber Threat Intelligence (CTI) Analyst to join our security organization and serve as a connective force across our Security Operations Center (SOC), Detection Engineering, Red Team, and Exposure Management functions. This is a highly cross functional role for someone who wants their intelligence work to directly shape what we detect, what we test, and what we prioritize fixing.

    You'll translate raw threat data into decisions: which adversary behaviors get new detections, which techniques the red team should emulate next, and which exposures matter most given who's actually targeting organizations like ours.

    What You'll Do:

    • Track threat actors, campaigns, and TTPs relevant to our industry, geography, and technology stack, and translate findings into actionable intelligence products (briefs, actor profiles, trend reports).
    • Partner with the SOC to enrich alerts and investigations with threat context, helping analysts triage faster and more accurately during active incidents.
    • Work with Detection Engineering to identify coverage gaps against known adversary behavior (e.g., mapped to MITRE ATT&CK) and help prioritize new detections based on real world threat relevance.
    • Collaborate with the Red Team to shape threat informed emulation plans, ensuring exercises reflect the tactics of adversaries most likely to target the organization.
    • Feed intelligence into Exposure Management to help prioritize vulnerabilities, misconfigurations, and attack surface findings based on active exploitation trends and threat actor intent.
    • Monitor open-source intelligence (OSINT), dark web sources, ISACs, and commercial threat feeds; assess relevance and reliability of incoming intelligence.
    • Produce and maintain adversary tracking documentation, including TTP matrices, campaign timelines, and indicator repositories.
    • Deliver both tactical (IOC/TTP-level) and strategic (executive-level trend and risk) intelligence outputs tailored to different stakeholders.
    • Participate in incident response as a threat intelligence liaison, providing attribution context and likely adversary next-steps.
    • Contribute to purple team exercises by bridging red team findings with detection and intelligence perspectives.

    What Experience You'll Need:

    • 5+ years of experience in cyber threat intelligence, SOC, incident response, or a closely related security discipline.
    • Solid working knowledge of the MITRE ATT&CK framework and experience mapping adversary behavior to it.
    • Familiarity with threat intelligence platforms and OSINT collection/analysis techniques.
    • Experience working with SIEM/EDR tooling to pivot on and validate intelligence.
    • Understanding of vulnerability management and exposure management concepts.
    • Strong written and verbal communication skills, with the ability to tailor technical intelligence for both analysts and executives.
    • Analytical mindset with sound tradecraft: structured analytic techniques, confidence levels, and source reliability assessment.

    What Could Set You Apart:

    • Familiarity with scripting or data analysis (Python, SQL) for intelligence automation or enrichment.
    • Experience with STIX/TAXII or other structured threat data sharing standards.
    • Prior experience in a fusion-center or cross-functional security model bridging detection, red teaming, and exposure/vulnerability management.

    Candidates that live within a commutable distance from our Tempe, AZ and St. Louis, MO home office locations are expected to work in the office four days per week effective June 1, 2026. Before June 1, 2026, candidates that live within a commutable distance from our Tempe, AZ and St. Louis, MO home office locations are expected to work in the office three days per week, with preference for Tuesday through Thursday.

    At Edward Jones, we are building a place where everyone feels like they belong. We're proud of our associates' contributions to the firm and the recognitions we have received.

    Check out our U.S. awards and accolades: Insights & Information Blog Postings about Edward Jones

    Check out our Canadian awards and accolades: Insights & Information Blog Postings about Edward Jones

    Edward Jones does not discriminate on the basis of race, color, gender, religion, national origin, age, disability, sexual orientation, pregnancy, veteran status, genetic information or any other basis prohibited by applicable law.

    Edward Jones' compensation and benefits package includes medical and prescription drug, dental, vision, voluntary benefits (such as accident, hospital indemnity, and critical illness), short- and long-term disability, basic life, and basic AD&D coverage. Short- and long-term disability, basic life, and basic AD&D coverage are provided at no cost to associates. Edward Jones offers a 401k retirement plan, and tax-advantaged accounts: health savings account, and flexible spending account. Edward Jones observes ten paid holidays and provides 15 days of vacation for new associates beginning on January 1 of each year, as well as sick time, personal days, and a paid day for volunteerism. Associates may be eligible for bonuses and profit sharing. All associates are eligible for the firm's Employee Assistance Program. For more information on the Benefits available to Edward Jones associates, please visit our benefits page.

    Similar Jobs

    See more jobs