About the Role
The Cyber Threat Intelligence (CTI) team within Blackstone Security Operations identifies, tracks, and assesses cyber threats relevant to Blackstone and its portfolio companies. The Associate Threat Intelligence Analyst conducts tactical, operational, and strategic analysis to inform defensive operations, risk decisions, and executive awareness. This role is at the cutting edge of cyber defense, pioneering the use of AI and automation to outpace adversaries, moving quickly from idea to production, and giving analysts real ownership to shape how intelligence is practiced. This is hands-on intelligence and engineering work involving monitoring the threat landscape, producing intelligence products, extracting indicators of compromise, and managing the firm's external attack surface. The analyst leverages AI and automation tooling to collect, enrich, and operationalize intelligence at scale, and develops clear visual products to make threats understandable to both technical and non-technical audiences. The role works closely with detection engineering, incident response, and vulnerability management to protect one of the world's leading investment platforms.
Responsibilities
- Monitor and analyze cyber threat activity targeting the financial sector, alternative asset management, and adjacent industries using open-source, commercial, and internal sources, correlating across them to identify patterns and provide early warning of emerging campaigns.
- Produce finished intelligence products and reports including recurring threat reporting, advisories, campaign profiles, actor dossiers, executive briefings, and visual products such as diagrams, tailored to both technical and non-technical audiences.
- Map adversary behaviors to the MITRE ATT&CK framework and maintain threat actor profiles covering TTPs, intent, and relevance to Blackstone.
- Extract, validate, enrich, and operationalize indicators of compromise (IOCs) to support detection engineering and incident response workflows.
- Leverage AI and automation tooling to scale collection, enrichment, and operationalization of intelligence.
- Partner with Alert, Detection & Response and Incident Response teams to translate intelligence into production detections (Splunk SPL, Sigma, YARA).
- Track zero-day and critical vulnerabilities, assess Blackstone's exposure, and translate findings into new detections and preventions in coordination with detection and security engineering.
- Support threat-informed vulnerability prioritization (CVSS, EPSS, CISA KEV) and coordinate remediation tracking with asset owners.
- Operate and evolve the firm's external Attack Surface Management (ASM) program, discovering and inventorying internet-facing assets across Blackstone and its portfolio companies, triaging newly discovered exposures and misconfigurations, and coordinating remediation.
- Support Fusion Center digital-threat monitoring, including brand, executive, and reputational exposure across OSINT, social media, and dark web sources.
- Contribute to intelligence sharing with trusted industry partners, ISACs (such as FS-ISAC), government partners (such as JCDC), and peer financial institutions.
- Participate in incident response and the SOC on-call rotation (occasional, roughly every other month) to respond to escalated security incidents.
Requirements
- 2+ years of experience in cyber threat intelligence, security operations, incident response, or a related cybersecurity discipline.
- Demonstrated understanding of the cyber threat landscape, including prominent threat actor groups, campaigns, and TTPs.
- Working knowledge of intelligence frameworks such as MITRE ATT&CK, the Diamond Model, or the Intelligence Cycle.
- Experience with threat intelligence platforms (TIPs), SIEM tools (e.g., Splunk), OSINT research methodologies, or attack surface management / vulnerability management tooling.
- Scripting or programming experience (Python preferred) for automating data collection, enrichment, and analytic workflows.
- Demonstrated, hands-on experience applying AI tooling (such as LLMs and coding assistants) to real work, and can clearly speak to several projects where you used AI to automate or accelerate a task.
- Capable of writing clearly and developing visual products (such as diagrams) to communicate complex cyber threats to both technical and non-technical stakeholders, including executive leadership.
- Strong analytical reasoning, attention to detail, and capable of prioritizing effectively in a fast-paced environment.
Skills
- Cyber Threat Intelligence
- Security Operations
- Incident Response
- Cybersecurity
- MITRE ATT&CK
- Diamond Model
- Intelligence Cycle
- Threat Intelligence Platforms (TIPs)
- SIEM tools (e.g., Splunk)
- OSINT research methodologies
- Attack Surface Management tooling
- Vulnerability Management tooling
- Python scripting
- AI tooling (LLMs, coding assistants)
- Visual product development (diagrams)
- Splunk SPL
- Sigma
- YARA
- CVSS
- EPSS
- CISA KEV
- Attack Surface Management platforms
- LLM assistants and APIs (e.g., ChatGPT/OpenAI, Claude/Anthropic, Gemini)
- Coding assistants (e.g., GitHub Copilot, Cursor)
- Agentic and automation frameworks
- Vulnerability management programs
- Structured analytic techniques
- Intelligence writing standards
- Detection content development
- Cloud environments (AWS, Azure)
- Cloud-specific threat vectors
Experience Level
- 2+ years of experience
Education Level
- B.S. in Computer Science, Cybersecurity, Intelligence Studies, International Relations, or a related field
Salary/Compensations
- $135,000 - $170,000
Benefits
- Comprehensive health benefits, including medical, dental, vision, and FSA benefits
- Paid time off
- Life insurance
- 401(k) plan
- Discretionary bonuses
- Equity and other incentive compensation (potential)
About the Company
- Blackstone is the world’s largest alternative asset manager.
- Blackstone seeks to deliver compelling returns for institutional and individual investors by strengthening the companies in which the firm invests.
- Blackstone’s over $1.3 trillion in assets under management include global investment strategies focused on real estate, private equity, credit, infrastructure, life sciences, growth equity, secondaries and hedge funds.
- Blackstone Technology & Innovations (BXTI) is the technology team at the core of each of Blackstone's businesses and new growth initiatives.
- Serving both internal and external clients, BXTI works to build the next generation of systems that manage risk, create efficiency and improve transparency within the firm and across its broad community of investors and portfolio companies.
- BXTI is entrepreneurial, with open, iterative design processes and a rapid pace of development.
- BXTI believes in active mentoring and developing excellence.
- BXTI collaborates to find the best answers for customers and the firm.
Equal Opportunity
- Blackstone is committed to providing equal employment opportunities to all employees and applicants for employment without regard to race, color, creed, religion, sex, pregnancy, national origin, ancestry, citizenship status, age, marital or partnership status, sexual orientation, gender identity or expression, disability, genetic predisposition, veteran or military status, status as a victim of domestic violence, a sex offense or stalking, or any other class or status in accordance with applicable federal, state and local laws.
- This policy applies to all terms and conditions of employment, including but not limited to hiring, placement, promotion, termination, transfer, leave of absence, compensation, and training.
- All Blackstone employees, including but not limited to recruiting personnel and hiring managers, are required to abide by this policy.
- If you need a reasonable accommodation to complete your application, please contact Human Resources at 212-583-5000 (US), +44 (0)20 7451 4000 (EMEA) or +852 3656 8600 (APAC).
