Pre-Screening Interview Questions to Ask a Cyber Threat Intelligence Analyst

Last updated on

Banks, managed security service providers, defence contractors, and large SaaS platforms all hire threat intelligence analysts. These questions cover adversary tradecraft, sourcing, attribution judgement, and reporting, with what to listen for in each answer and the patterns that should end a screen.

TL;DR, what to screen for

The best pre-screening questions for a Cyber Threat Intelligence Analyst test four things: technical depth in adversary tradecraft and frameworks, real findings that changed a defensive decision, judgement about attribution and confidence when evidence is partial, and writing that lands with a SOC analyst and an executive in the same week. Push past tool lists: ask which detection, block, or patch decision their reporting actually caused, and who acted on it.

  • Adversary tradecraft and frameworks
  • Findings that changed defences
  • Attribution and confidence calls
  • Writing for two audiences

Why pre-screen cyber threat intelligence analysts before the panel interview

Pre-screening threat intelligence analysts saves your panel from resume theatre. Applicants arrive from SOC tier two roles, military and government units, vendor research teams, and MSSPs, and every resume lists MITRE ATT&CK, MISP, and Recorded Future. What a resume cannot show is whether they produced intelligence someone acted on, or just forwarded feeds. Ten minutes of recorded answers surfaces how they reason about confidence, source reliability, and who their reporting was written for.

What actually matters when screening Cyber Threat Intelligence Analyst candidates

  1. 01

    Technical depth

    Probe adversary tradecraft, intelligence frameworks, and their sourcing beyond vendor feeds.

  2. 02

    Real incidents and findings

    Look for intelligence they produced that changed a defensive decision, not just reports they circulated.

  3. 03

    Risk judgement

    Test how they handle attribution and confidence when the evidence is partial and the pressure is to name someone.

  4. 04

    Getting things fixed

    Assess how they write for a SOC analyst and an executive in the same week without saying the same thing twice.

Pre-screening questions to ask Cyber Threat Intelligence Analyst candidates

12 questions grouped by what they test. Ask the same set in every screen and score answers on a consistent scale, or send them as an async video screen and compare answers side by side.

Frameworks and tradecraft

3 questions
  1. 01Explain the difference between tactical, operational, and strategic threat intelligence, and say which one you have produced most of.

    Listen for

    Clear separation of IOC level output, campaign and TTP level analysis, and board level trend reporting, plus an honest statement of where their own output sat.

    They define the three tiers from a textbook but cannot say which they personally produced or for whom.

  2. 02How familiar are you with the MITRE ATT&CK framework, and how have you actually applied it in a past role?

    Listen for

    Concrete use: mapping detections to techniques, building a Navigator heat map of coverage gaps, or profiling an intrusion set against sub-techniques like T1566.001.

    They recite tactic names or treat ATT&CK as a reporting label rather than something they used to find or close a gap.

  3. 03What types of indicators of compromise have you worked with, and what did you do with them beyond adding them to a blocklist?

    Listen for

    Range across hashes, domains, JA3 or JARM fingerprints, and registry artefacts, with awareness of indicator decay and the pyramid of pain.

    Only file hashes and IPs, with no sense that low-value indicators expire within days of publication.

Sourcing and validation

3 questions
  1. 04What is your process for validating the credibility and reliability of a threat intelligence source?

    Listen for

    A repeatable method: admiralty style source and information grading, corroboration across independent sources, and checks on whether a vendor is recycling another vendor's reporting.

    They treat paid vendor reporting as inherently reliable and describe no way of catching circular sourcing.

  2. 05What experience do you have with open-source intelligence gathering, and which sources do you actually rely on?

    Listen for

    Named sources they work daily: Shodan or Censys, VirusTotal retrohunts, certificate transparency logs, criminal forums, Telegram channels, or CISA and national CERT advisories.

    OSINT means reading security news sites, with no primary collection and no operational security discipline around it.

  3. 06Which threat intelligence platforms and tools have you used, and what did you build or maintain inside them?

    Listen for

    Hands-on detail on MISP, OpenCTI, Anomali, Recorded Future, or ThreatConnect, including data model work, enrichment pipelines, or STIX and TAXII integrations they set up.

    A tool list with no description of what they configured, curated, or fixed inside any of them.

Analysis and impact

4 questions
  1. 07What methods do you use to analyse and prioritise threats for your organisation specifically?

    Listen for

    Prioritisation tied to their own environment: crown jewel systems, sector targeting, exposed technology stack, and intelligence requirements agreed with stakeholders.

    Prioritisation by CVSS score or media coverage, with no reference to what their organisation actually runs.

  2. 08How do you handle false positives and false negatives in your analysis, and how do you express confidence when the evidence is partial?

    Listen for

    Separation of observation from assessment, calibrated confidence language, analysis of competing hypotheses, and a real example where they refused to name an actor.

    They attribute to a nation state from thin infrastructure overlap or claim their analysis is never wrong.

  3. 09Walk me through a time your threat intelligence work helped mitigate an actual incident. What changed because of your report?

    Listen for

    A specific chain: what they saw, who they told, and the resulting action (detection rule shipped, credential reset, egress block, emergency patch) with rough timing.

    The story ends when the report was published, with no owner, no action taken, and no measurable outcome.

  4. 10What is your approach to running a threat hunting exercise, and what hypothesis did your last hunt start from?

    Listen for

    A hypothesis driven method grounded in a specific technique, named data sources (EDR telemetry, DNS logs, proxy, Sysmon), and what happened when the hunt found nothing.

    Hunting described as searching a SIEM for the latest published IOC list with no hypothesis behind it.

Reporting and collaboration

2 questions
  1. 11Brief me for sixty seconds on a recent campaign as if I am a CFO with no security background.

    Listen for

    Plain language, business impact first, no unexplained jargon, a clear ask or recommendation, and a stated confidence level inside the time limit.

    Malware family names, technique IDs, and infrastructure detail delivered with no answer to why the executive should care.

  2. 12How have you worked with incident response and vulnerability management teams, and what did they need from you that you were not already producing?

    Listen for

    Named handoffs: enriching an IR case during containment, feeding exploitation evidence into patch prioritisation, and a specific change they made after stakeholder feedback.

    They describe intelligence as a standalone function and cannot name a single consumer or their requirements.

How to score responses

Score every candidate on the same four criteria immediately after the screen. At this stage you are shortlisting for panel interviews, not making the final call.

  1. Technical depth

    35%

    5Knows adversary tradecraft and frameworks properly, with sourcing that goes well past vendor feeds.

  2. Real incidents and findings

    30%

    5Names intelligence they produced that changed a defensive decision, and how they knew it landed.

  3. Risk judgement

    20%

    5States confidence levels explicitly, resists premature attribution, and revises publicly when new evidence lands.

  4. Getting things fixed

    15%

    5Writes for both SOC and executive audiences so each can act, without diluting or inflating the assessment.

Threat intelligence lives or dies on the briefing. Async video lets you hear whether they can explain an intrusion set to a non-technical executive in sixty seconds without jargon, which no written application will ever show you.

Try it on Hirevire

Screening FAQ

Process basics

What should a threat intelligence analyst screen cover before the technical panel?

Cover four areas before the panel: frameworks and adversary tradecraft (ATT&CK, Diamond Model, kill chain), where their intelligence comes from beyond paid feeds, one finding that changed a defensive control, and how they write for different readers. Leave deep malware analysis, pivoting exercises, and infrastructure hunting demonstrations to the live technical round where you can watch them work.

Should I ask for a writing sample from a threat intelligence analyst?

Yes, but ask for a redacted or public one. Most operational reporting is client confidential, so request a published blog post, a conference talk, a sanitised threat profile, or an ATT&CK Navigator layer they built. If nothing shareable exists, ask them to brief a recent public campaign on video for sixty seconds instead.

Evaluating answers

How do I tell a real intelligence analyst from someone who just forwards vendor feeds?

Listen for the decision their work triggered. Real analysts name the detection rule written, the control tuned, the patch prioritised, or the executive who changed spend, and they say who consumed the report. Feed forwarders describe volume (IOCs ingested, reports circulated) and cannot explain what happened after the report went out.

What is a good answer on attribution and confidence?

A good answer separates observation from assessment and uses calibrated language. Look for analytic confidence levels, willingness to say "moderate confidence, based on infrastructure overlap and shared tooling", and awareness that shared tooling is weak evidence. Confident naming of a nation state actor from a single IP or a vendor cluster name is the pattern to distrust.

Go deeper on this role

Sanat Hegde
Sanat Hegde
Founder, Hirevire

Sanat has been hiring since 2012 and watching the recruitment industry change up close ever since, and turned that screening process into Hirevire's video screening platform. LinkedIn

Trusted by 500+ Companies

Screen Cyber Threat Intelligence Analyst candidates on Hirevire

Hirevire lets you send threat intelligence candidates a short set of recorded questions, including a sixty second executive briefing task. You review the answers when it suits you and send only the analysts worth your panel's time.