Jobs · Information Technology

Intelligence Analyst

ZeroFox · United States · 1 mo ago
RemoteRemoteInformation TechnologyFull-time

ZeroFox protects what's real by removing what isn't. We steadfastly safeguard organizations from fraud, abuse, misinformation, and attack by preemptively exposing, disrupting, and eliminating external threats across the public attack surface. ZeroFox uniquely fuses Cyber Threat Intelligence, Brand and Domain Protection, Attack Surface Intelligence, Executive Protection, and Physical Security Intelligence in one platform packed with intelligence you'll actually use.

About the role

ZTAC (ZeroFox Threat Analysis Center) is where ZeroFox's intelligence promise gets stress-tested every single day — real clients, real deadlines, threats that don't wait for business hours. This team doesn't just monitor the internet; it decides what actually matters on it, across physical security, cyber, geopolitical, and reputational risk at once.

You'll use ZeroFox's patented technology to pull relevant signal out of noisy, high-volume data — from mainstream social platforms to deep and dark web forums — and turn it into intelligence that actually changes what a client does next. The work spans physical security threats, cyber risk, geopolitical developments, reputational exposure, and compliance concerns, often in the same week, sometimes in the same report. This isn't queue-clearing. You'll research a threat, decide what's credible and what's noise, and write it up in a BLUF-first format a client's security team can act on without a follow-up call. You'll work daily security and incident alerts, support recurring intelligence deliverables, brief clients directly, and partner with Collection Management to keep the intelligence pipeline getting sharper — not just bigger.

In your first 90 days, you'd be expected to run point on at least one recurring client deliverable, complete ZTAC's onboarding certifications, and independently produce a BLUF-format report your manager signs off on without edits.

You'll thrive here if...

  • You've done real OSINT and social media investigation work — 2-3 years of it — and know the difference between a lead and a rabbit hole
  • You can hold four threat categories (physical, cyber, geopolitical, reputational) in your head at once without losing the thread on any of them
  • You've written a BLUF-format report under deadline and had a client act on it the same day
  • You're comfortable being the one who decides something is credible enough to escalate — nobody's rubber-stamping your judgment
  • Getting better at this daily — sharper tradecraft, new certifications, better sourcing — actually motivates you

This probably isn't for you if...

  • You want a fully scoped ticket queue where someone else has already decided what's relevant — this role requires deciding that yourself
  • You've never had to defend why you called something credible, or not, to someone who disagreed
  • You're not comfortable working the deep and dark web as part of the job — this role goes there regularly
  • Briefing a customer directly, live, makes you want to hand it off to someone else
  • You're looking for a single-domain specialty — this role moves across physical, cyber, and geopolitical risk, and narrow focus isn't the job

Requirements

  • 2-3 years of OSINT and social media research experience, including executive threat assessments or investigations
  • Ability to judge the credibility, value, and relevance of information across sources — and say so clearly in writing
  • Strong written and oral communication skills; comfortable producing BLUF-style reports and briefing customers directly
  • Experience with at least one online investigative tool (Whois, Ping, Traceroute, or similar), plus proficiency in Google Suite
  • Working familiarity with surface web platforms, blogs, IRC, message boards, and deep/dark web environments

Nice to have

  • Experience conducting studies on threat vectors, actors, or trends and turning them into recommendations
  • Deep familiarity with deep/dark web tradecraft and the platforms threat actors actually use
  • Project management instincts and a track record of managing customer relationships well
  • Some college coursework in cybersecurity, intelligence studies, or homeland security
  • Working knowledge of a specific threat landscape — cybercrime, fraud, physical/corporate security, hacktivism, or geopolitical risk

Benefits

  • Comprehensive health, dental, and vision (Cigna)
  • 401(k) with 3% match, 100% immediately vested — no cliff
  • HSA with quarterly company contributions
  • Company-paid disability and life insurance
  • Generous time off

About ZeroFox

ZeroFox is on a mission to make the internet safer for all. Innovation is at our core — we are relentless in the pursuit of finding new ways to disrupt external cyber threats on the surface, deep, and dark web. ZeroFox offers the only unified cybersecurity platform combining advanced AI analytics, digital risk and privacy protection, full-spectrum threat intelligence, and a robust portfolio of breach, incident and takedown response capabilities to protect customers from growing threats across the external attack surface.

Similar jobs

Intelligence Analyst

US Army Medical Department (AMEDD)San Antonio, TX· Yesterday
Information Technologyapply on goarmy.com

Intelligence Analyst

PeratonBethesda, MD· 1 mo ago
Information Technology$179k/yrapply on careers.peraton.com

Intelligence Analyst

BioSpaceTarrytown, NY· 1 mo ago
Information Technology$98k–$160k/yrapply on jobs.biospace.com

Intelligence Analyst

CGS Federal (Contact Government Services)Arlington, VA· 6 mo ago
Information Technologyapply on jobs.lever.co

Intelligence Analyst

CGS Federal (Contact Government Services)Atlanta, GA· 6 mo ago
Information Technologyapply on jobs.lever.co

Intelligence Analyst

PINKERTON | Comprehensive Risk ManagementRedmond, WA· 2 mo ago
RemoteInformation Technology$110k/yrapply on uscareers-pinkerton.icims.com