Cybersecurity Threat Intelligence Analyst
Full Time Perm
Shift: Hybrid - 3 days on location
Salary: $96,600 - $144,900 with 8% annual bonus
Location: Columbus, OH or Merrillville, IN
Relocation Assistance Provided
NiSource is one of the largest fully regulated utility companies in the U.S., serving millions of customers across six states. We’re more than an energy provider—we’re a team committed to innovation, inclusion, and growth. At NiSource, you’ll find a workplace that encourages collaboration, supports professional development, and empowers employees to make an impact.
The Cybersecurity department ensures the confidentiality, integrity, and availability of NiSource assets to achieve the company mission.
What you'd do
- Monitor, analyze, track, and report on evolving threat trends related to the company, industry, or critical infrastructure and national security more broadly
- Conduct advanced open-source intelligence (OSINT) research and investigations into cyber threat actors, origins, motives, TTPs, emerging trends, and geopolitical developments.
- Assess how geopolitical and societal developments drive cyber activity over time and impact the organization
- Synthesize large volumes of multi-source intelligence and technical processes into concise products and executive-level briefings to ensure that senior leaders get a clear understanding of threat activity, related risks, business implications, and recommended mitigations or controls
- Support tactical intelligence collection and reporting, including monitoring for indicators like IOCs or malicious IPs, leveraging tools for detection, and validation within NiSource systems, and providing actionable intelligence to Incident Response
- Respond and support Cybersecurity or Physical Security teams during high-impact incidents. Compile available intelligence into timely, high-confidence products
- Continue to update key stakeholders throughout a security or crisis event to provide essential information, translate technical information for a business audience, and support overall business response and recovery efforts
- Assist in developing new intelligence reporting thresholds, templates, products, and data collection mechanisms
- Develop and maintain intelligence metrics, dashboards, investigative records, and KPIs to ensure that team activities are measurable and aligned to business objectives
- Utilize intelligence tools and platforms such as Dataminr, Recorded Future, ZeroFox, and other OSINT capabilities to support routine monitoring, investigations, and analysis
- Facilitate and develop new data connections for Power BI dashboards (database development) used for insider risk detection and tracking.
- Perform regular updates to API connections and dashboards as the Insider Risk and Threat programs evolve
What they want
- Bachelor’s degree or equivalent experience
- 4+ years of experience in Cyber Threat Intelligence, Cyber Security Operations, Incident Response, Intelligence Analysis, or related fields in the public or private sectors
- 4+ years of experience applying the intelligence lifecycle, MITRE ATT&CK framework, cybercrime analysis, threat actor tactics and techniques, or cyber risk management principles
- 4+ years of experience producing all-source intelligence reports, briefings, and assessments for both technical and senior business audiences
- 4+ years of experience utilizing threat intelligence platforms and OSINT tools such as Dataminr, Recorded Future, ZeroFox, Flashpoint, CrowdStrike, or Google SecOps/CTI
- 2+ years of experience in database and dashboard development, ideally with the Azure Databricks Lakehouse platform and Power BI
- Proficiency in Python (PySpark) and Spark SQL for large-scale data transformation
- Starts
- 2026-09-25