Lead Cyber Intelligence Analyst

McKesson•Irving, TX
•$151,600 - $252,600•Hybrid

About The Position

McKesson is seeking a highly skilled Lead Information Security Analyst to strengthen our cyber threat intelligence capabilities. This role serves as a senior intelligence leader responsible for identifying, analyzing, and communicating cyber threats that may affect the enterprise, its business operations, and the healthcare sector. As a lead analyst, you will partner with cybersecurity, technology, risk, legal, and business teams to define intelligence needs, assess emerging threats, translate complex findings into relevant business insights, and guide risk-informed decisions. You will also mentor analysts, strengthen analytic tradecraft, and improve how intelligence is collected, produced, and shared.

Requirements

  • 10+ years of cybersecurity, information security, cyber threat intelligence, threat research, or related experience.
  • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Systems, or related field; equivalent experience will be considered.
  • Experience developing a telemetry-to-intelligence model that reduces reliance on third-party feeds and vendors—shifting teams from intel consumers to intel producers
  • Experience with open source research tools, including Virus Total, Domain Tools, Censys, Grey Noise, and other similar tools.
  • Experience in tactical threat intelligence, specifically identifying IOCs, tools, and behavioral fingerprints left by adversaries across our telemetry (endpoint, network, cloud, and identity)
  • Mine SIEM, EDR, NDR, firewall, DNS, proxy, and cloud logging data to identify adversary tradecraft, infrastructure, and behavioral patterns unique McKesson
  • Experience using MITRE ATT&CK, Cyber Kill Chain, or similar frameworks to structure and communicate threat analysis.
  • Experience with threat intelligence platforms, link analysis, data enrichment, or scripting and automation that support intelligence workflows.

Nice To Haves

  • Advanced cyber threat intelligence experience using TIPs, commercial reporting, OSINT, information-sharing communities, and dark web intelligence sources.
  • Experience building or maturing a cyber threat intelligence program, operating model, or intelligence lifecycle.
  • Knowledge of intelligence collection management, source validation, confidence assessments, and structured analytic techniques.
  • Experience with design, build, and optimize intelligence systems for structured storage, correlation, and analytics of large-scale threat intelligence data sets.
  • Experience supporting regulatory, audit, compliance, or healthcare security environments.
  • Relevant certifications such as CISSP, GCTI, OSCP, GREM, or equivalent intelligence, cybersecurity, or analytic credentials.
  • Experience coaching technical teams and leading cross-functional security initiatives.

Responsibilities

  • Identify and track emerging threats by discovering untracked adversary activity, developing new threat clusters into tracked actor groups across McKesson telemetry
  • Deliver time-sensitive behavioral attack chains supporting active incident response and threat hunting operations to drive cross-team detection and protection actions.
  • Lead attribution and threat actor analysis by collecting, modeling, attributing, and documenting intelligence gathered during investigations. Serve as the primary owner for attribution efforts while partnering with incident response teams.
  • Author actor profiles for the CIRT, Red Team, Threat Hunt, and Detection Engineering-- leveraging internal signals, open-source, vendor research, and sharing community reporting
  • Leverage AI to guide investigations and automation (e.g., intel-to-detection pipelines, infrastructure clustering, cross-actor TTP analysis) to scale production beyond manual analysis
  • Provide technical mentorship to mid-level analysts on tradecraft, source evaluation, and production standards
  • Represent the intelligence function in cross-functional planning with SOC, threat hunting, red team, and incident response
  • Contribute to strategic planning on how internal telemetry investments map to intelligence production goals

Benefits

  • Annual bonus or long-term incentive opportunities may be offered.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service