Most people think breaking into cyber threat intelligence (CTI) is a skills problem. It is not. It is a signal problem.
I came up through a managed security services provider (MSSP) security operations center (SOC), triaging alerts before I could even define a threat actor. I have since walked the path from SOC analyst to threat hunter to CTI analyst, and the biggest lesson from that climb is this: CTI is not an entry-level discipline.
The process of taking raw inputs, such as indicators of compromise (IOCs), packet captures (PCAPs), and open-source intelligence (OSINT), and turning them into intelligence that drives a decision takes experience and context.
This article maps out the real CTI career path, the competency framework that separates good analysts from great ones, and the specific CTI skills, portfolio projects, and action steps that will make you impossible to overlook. By the end, you will know exactly where you sit on the path and what to do next. Let’s get started.
The Four CTI Career Tiers
So how do you go from “interested in CTI” to “CTI expert”? My personal experience (as well as coaching many others) has taught me there are four tiers one progresses through on their way to a senior/lead CTI position.

Tier 1: SOC Foundation
This is where you learn how attackers actually behave, not in theory but in alerts. You are triaging endpoint detection and response (EDR) alerts, reviewing security information and event management (SIEM) logs, and chasing down false positives. It feels like grunt work, but it builds the contextual foundation on which your entire career rests. You cannot assess intelligence if you have never seen what real intrusion activity looks like.
The minimum viable time in tier one is 12 to 18 months. Less than that, and you will lack the pattern recognition that makes everything downstream make sense.
Tier 2: Threat Hunting
This is the bridge most people skip, and it is the one that matters most. Threat hunting forces you out of a reactive posture, where an alert arrives, and you investigate, into a proactive one. Here, you form a hypothesis about adversary behavior and then go find the evidence. If you cannot form a hypothesis, you cannot do CTI. It is that simple.
Tier 3: CTI Analyst
Now you are producing intelligence products. OSINT collection, threat actor profiling, threat modeling, and mapping tactics, techniques, and procedures (TTPs) against the MITRE ATT&CK framework all live here.
You are writing finished intelligence, not just sharing raw indicators. You provide context and measured assessments. You are bridging the gap between SOC and the executive suite.
I have met analysts holding the Certified Threat Intelligence Analyst (CTIA), the CREST Practitioner Threat Intelligence Analyst (CPTIA), and even the GIAC Cyber Threat Intelligence certification (GCTI) who have never triaged a real alert. They know the vocabulary. They do not know the terrain.
A certification validates a skill. It does not create one. You still need the reps. The certification just makes those reps eligible to a hiring manager.
Tier 4: Senior/Lead Analyst
This is the tier everyone is chasing. Strategic intelligence becomes your bread and butter. You are briefing the chief information security officer (CISO), running threat modeling workshops, and building the program rather than just feeding it.
The jump from tier three to tier four is not about more technical skill. It is about the depth of communication and program ownership.
Now you know the path. But hundreds of people are walking it right now. What separates the ones who actually land senior roles?
Good Analyst vs. Great Analyst
Let’s do a quick comparison so you can see the difference between someone just starting their journey in CTI and someone who’s been around the block.
Picture this: that same suspicious IP address lands on two different desks.
- The good analyst’s ticket says “blocked, closed.” The great analyst’s write-up pivots on the infrastructure, using the Diamond Model, and asks what this tells us about the adversary’s capability, what the targeting pattern reveals about intent, and what the second-order effect would be if the attribution holds.
- Good analysts know MITRE ATT&CK exists. Great analysts use it to build detection hypotheses and threat hunts, and can explain the gap between what the ATT&CK framework documents and what the adversary actually does inside your specific environment.
- Good analysts write reports. Great analysts write reports calibrated to the audience they serve. A SOC needs a different intelligence product than a CISO does.
The underlying intelligence might be identical, but the packaging is not!
A good analyst finds indicators of compromise. A great analyst tells you what the adversary is going to do next.
| Situation | Good analyst | Great analyst |
|---|---|---|
| Suspicious IP address | Documents it, opens a ticket, moves on | Pivots on the infrastructure to assess capability and intent using the Diamond Model |
| MITRE ATT&CK | Knows the framework exists | Uses it to build detection hypotheses and explain the gap between documented TTPs and what the adversary does in your environment |
| Intelligence reports | Writes a report | Calibrates the same intelligence into different products for a SOC audience versus a CISO audience |
Now you might be thinking, “How can I make this leap?” That’s where Mandiant’s CTI competency framework comes in.
Mandiant’s CTI Competency Framework

Mandiant’s Cyber Threat Intelligence (CTI) Analyst Core Competencies Framework operationalizes that good-to-great jump into four pillars.
Problem Solving
Structured analytic techniques, bias reduction, and the analysis of competing hypotheses all live here.
Professional Effectiveness
Probabilistic language, stakeholder communication, and product calibration.
Technical Literacy
Malware behavior, file artifacts, and log triage. You do not need to reverse engineer malware, but you must be able to extract its intent.
Cyber Threat Proficiency
Diamond Model pivots, ATT&CK mapping, and attribution methodology.
These pillars work together to fulfill the core security, analytical, and soft skills required to become a well-rounded analyst. Unfortunately, most analysts develop one or two and quietly neglect the rest. Great analysts are strong across all four pillars
The pillar I see analysts skip most often, and the one that matters the most, is professional effectiveness. Analysts treat it like a soft skill they can only practice when someone hands them a debrief or a project to lead. That framing is wrong.
Professional effectiveness is a hard output, and you can practice it in every single write-up you produce.
A senior analyst does not write “the Russians did it.” A senior analyst writes something closer to this: “Based on infrastructure overlap and TTP alignment, it is highly likely this activity originates from a group associated with SVR operations.”
That single sentence does three things:
- It conveys confidence calibrated to the evidence.
- It provides attribution with appropriate uncertainty.
- It gives a decision-maker something they can act on. Learn to write at that level of estimative language, and you will stand out on every CTI team you join.
Here you see each of the CTI competency pillars working together to produce actionable intelligence that a business can use to make an informed decision.
So how can you demonstrate this level of expertise to potential employers?
Portfolio Projects
Everything covered so far happens inside the job. But the analysts who break through to senior roles fastest have built something on the outside that makes them impossible to ignore.
Here is the uncomfortable truth: your employer’s threat intelligence is not your portfolio. You cannot show it to a hiring panel. You cannot reference specifics. It sits behind a non-disclosure agreement (NDA), and it is often classified outright.
Picture this: a hiring panel asks you to walk them through a real piece of analysis. If the only honest answer is “I cannot talk about that; it is confidential,” you have just lost the room. The fix is a portfolio of finished deliverables that you produce yourself, on your own time, that prove what you can do.
Portfolio Project benefits
- Public Proof of Competency
A portfolio shows a hiring panel what you can actually do, not just what test you passed. - Differentiation From Credential Stacking
Anyone can collect certifications. Far fewer people publish finished intelligence products. - A Talking Point in Every Interview
A real project gives you something concrete to walk a panel through, instead of reciting your resume back at them.
Three projects consistently carry the highest signal with a hiring panel, and you can start all three today.
Project 1: APT Group TTP Mapping
Pick a specific campaign and map it against MITRE ATT&CK. Document the mitigation gaps that the campaign would have exploited. This proves you can use the industry’s primary framework productively, not just name-drop it in an interview.
Project 2: A Threat Hunting Playbook
Build a structured detection playbook for one specific tactic, technique, or procedure. Take lateral movement via pass-the-hash as an example. Use Kusto Query Language (KQL) or a Sigma rule that a team could realistically deploy. This bridges CTI and detection engineering, and that combination is a premium skill set most organizations will fight to hire for.
Project 3: A Python IOC Enrichment Script
Write a simple script that calls the VirusTotal and AbuseIPDB application programming interfaces (APIs) to automatically enrich suspicious IP addresses and produce a tiered report. This proves you can scale your own workflow with automation and a bit of scripting.
Each of these projects is public proof of competency. That is what turns your CV from a list of job titles into an actual portfolio. Remember, certifications tell a hiring manager you can pass a test. A portfolio tells them you can do the job.
The Truth About Hiring for Senior CTI Roles
All of these point to a hard truth nobody in the certification industry wants you to hear: most senior CTI roles are not posted publicly. They are filled through referrals within a trust network. If you are not in that network and do not have these conversations, you are competing for the leftover seats.
So how can you join these conversations?

Cyber Security Conferences, Talks, & Meet Ups
CTI has an unusually generous knowledge-sharing culture for a competitive field, and you should take advantage of it. CTI League, Information Sharing and Analysis Centers (ISACs), and sector-specific sharing groups all welcome volunteer contributors, not just consumers. Attending them opens the door to job opportunities, new connections, and first-hand knowledge of who is hiring.
Conferences like B-Sides, FIRST, and DEF CON are worth attending even if you never speak. Ask real questions during Q&A, approach speakers afterward, and network with other attendees. One genuinely good conversation compounds differently than fifty generic LinkedIn connection requests.
Content Creation
Public writing matters too. A single blog post analyzing a single campaign, complete with ATT&CK mapping and a pyramid of pain breakdown, is worth hundreds of generic LinkedIn posts. It demonstrates your analytical process instead of your credential count.
Creating content showcases your ability to communicate technical information to a non-technical audience, your mastery of CTI skills/concepts, and your up-to-date knowledge of the latest threats.
Targeting Certifications for Your Next Job
Don’t blindly chase certifications! They are not Pokémon cards that you need to collect. Rank the certifications you pursue by signal value to the specific hiring managers and roles you are targeting, not by price or difficulty.
Target the environment first, then choose the certification.
| Certification | Strongest signal for |
|---|---|
| GCTI | Government and defense roles |
| CTIA | EMEA and APAC roles |
| CPTIA (CREST) | UK-based consultancies |
So, what’s next? Let’s explore some concrete actions you can get started on today!
Action Steps
You have the map. Here is the exact sequence for building momentum, broken down by tier.
- If you are in tier 1, the SOC: log every incident you investigate, not just the resolution. Record your hypothesis, what you ruled out, and why. In six months, that log becomes your portfolio narrative. Your way to showcase your technical chops, analytical thinking skills, and ability to think proactively about threats.
- If you are in tier 2, threat hunting: pick one threat actor relevant to your sector. Build a two-page intelligence profile using open-source sources such as MISP, AlienVault Open Threat Exchange (OTX), or public ISAC reports. Map their TTPs and write a finished intelligence product, not just raw notes, then publish it on your own blog.
- If you are in tier 3 and want to move up: the gap is almost never technical. Take the last intelligence product you wrote and ask yourself one question. Could your CISO read this and make a decision without asking a single follow-up question? If the answer is no, that is your development edge.
- For everyone, regardless of tier: add a “so what” section to every intelligence report you produce, whether at work or in your portfolio. This section translates your technical findings into business impact, and it will separate you faster than any certification ever could.
Here is what that looks like in practice.
While I was working at a telecommunications organization in the UK, I picked up an IP address associated with Volt Typhoon, a threat group known for targeting edge devices as initial access points before hiding behind residential IP addresses for command-and-control (C2) communication. Most teams would have blocked the indicator and closed the ticket, maybe with a bit of external threat hunting around the hosting infrastructure using a tool like Shodan. I went further.
I built a honeypot network that mimics those edge devices, specifically to attract Volt Typhoon, observe their behavior, and extract intelligence to harden the organization’s real edge devices and build new detection mechanisms around that behavior pattern.
That is the “so what.” That is the difference between a good analyst who blocks an indicator and a great one who builds entirely new defensive capability on top of it.
Conclusion
This guide has walked you through the four CTI career tiers, the Mandiant competency framework that separates good analysts from great ones, and the specific portfolio projects and action steps that make you visible in a field where most senior roles are never posted publicly. None of this requires more certifications. It requires reps, a portfolio, and the discipline to write your findings the way a CISO needs to read them.
Pick your tier, pick one action step, and start today. The analysts who stand out are not the ones who waited for permission. They are the ones who built the proof themselves. Good luck!
Frequently Asked Questions
What Are the Four Tiers of a CTI Career Path?
The four tiers are SOC foundation, threat hunting, CTI analyst, and senior or lead analyst. Most analysts try to skip the threat hunting tier and end up stalling, since it is where you learn to form and test a hypothesis, a skill the later tiers depend on.
What is the Mandiant CTI Analyst Core Competencies Framework?
It is a four-pillar framework that Mandiant developed to define the skills a CTI analyst needs: problem-solving, technical literacy, cyber threat proficiency, and professional effectiveness. Most analysts develop strength in one or two pillars and underinvest in the rest, with professional effectiveness being the most commonly neglected.
Do I Need Certifications to Get a CTI Job?
Certifications like the GCTI, CTIA, and CPTIA can validate your knowledge and help you pass initial screening, but they do not prove you can do the job. A portfolio of finished intelligence products carries more weight with hiring panels because it shows your actual analytical process.
What Portfolio Projects Are Best for an Aspiring CTI Analyst?
Three high-signal projects are an APT group TTP mapping exercise against MITRE ATT&CK, a threat hunting playbook with a working Sigma or KQL detection rule, and a Python script that automates IOC enrichment using APIs like VirusTotal or AbuseIPDB.
Why Are Most Senior CTI Roles Not Posted Publicly?
Senior CTI roles are frequently filled through referrals inside trust networks built at conferences, sharing communities, and through public writing. Building a presence in these spaces, through volunteering with ISACs or publishing your own analysis, puts you inside that network instead of competing for leftover public postings.




