Why pre-screen cyber threat intelligence analysts before the panel interview
Pre-screening threat intelligence analysts saves your panel from resume theatre. Applicants arrive from SOC tier two roles, military and government units, vendor research teams, and MSSPs, and every resume lists MITRE ATT&CK, MISP, and Recorded Future. What a resume cannot show is whether they produced intelligence someone acted on, or just forwarded feeds. Ten minutes of recorded answers surfaces how they reason about confidence, source reliability, and who their reporting was written for.
What actually matters when screening Cyber Threat Intelligence Analyst candidates
- 01
Technical depth
Probe adversary tradecraft, intelligence frameworks, and their sourcing beyond vendor feeds.
- 02
Real incidents and findings
Look for intelligence they produced that changed a defensive decision, not just reports they circulated.
- 03
Risk judgement
Test how they handle attribution and confidence when the evidence is partial and the pressure is to name someone.
- 04
Getting things fixed
Assess how they write for a SOC analyst and an executive in the same week without saying the same thing twice.
Pre-screening questions to ask Cyber Threat Intelligence Analyst candidates
12 questions grouped by what they test. Ask the same set in every screen and score answers on a consistent scale, or send them as an async video screen and compare answers side by side.
Frameworks and tradecraft
3 questions01Explain the difference between tactical, operational, and strategic threat intelligence, and say which one you have produced most of.
Listen forClear separation of IOC level output, campaign and TTP level analysis, and board level trend reporting, plus an honest statement of where their own output sat.
They define the three tiers from a textbook but cannot say which they personally produced or for whom.
02How familiar are you with the MITRE ATT&CK framework, and how have you actually applied it in a past role?
Listen forConcrete use: mapping detections to techniques, building a Navigator heat map of coverage gaps, or profiling an intrusion set against sub-techniques like T1566.001.
They recite tactic names or treat ATT&CK as a reporting label rather than something they used to find or close a gap.
03What types of indicators of compromise have you worked with, and what did you do with them beyond adding them to a blocklist?
Listen forRange across hashes, domains, JA3 or JARM fingerprints, and registry artefacts, with awareness of indicator decay and the pyramid of pain.
Only file hashes and IPs, with no sense that low-value indicators expire within days of publication.
Sourcing and validation
3 questions04What is your process for validating the credibility and reliability of a threat intelligence source?
Listen forA repeatable method: admiralty style source and information grading, corroboration across independent sources, and checks on whether a vendor is recycling another vendor's reporting.
They treat paid vendor reporting as inherently reliable and describe no way of catching circular sourcing.
05What experience do you have with open-source intelligence gathering, and which sources do you actually rely on?
Listen forNamed sources they work daily: Shodan or Censys, VirusTotal retrohunts, certificate transparency logs, criminal forums, Telegram channels, or CISA and national CERT advisories.
OSINT means reading security news sites, with no primary collection and no operational security discipline around it.
06Which threat intelligence platforms and tools have you used, and what did you build or maintain inside them?
Listen forHands-on detail on MISP, OpenCTI, Anomali, Recorded Future, or ThreatConnect, including data model work, enrichment pipelines, or STIX and TAXII integrations they set up.
A tool list with no description of what they configured, curated, or fixed inside any of them.
Analysis and impact
4 questions07What methods do you use to analyse and prioritise threats for your organisation specifically?
Listen forPrioritisation tied to their own environment: crown jewel systems, sector targeting, exposed technology stack, and intelligence requirements agreed with stakeholders.
Prioritisation by CVSS score or media coverage, with no reference to what their organisation actually runs.
08How do you handle false positives and false negatives in your analysis, and how do you express confidence when the evidence is partial?
Listen forSeparation of observation from assessment, calibrated confidence language, analysis of competing hypotheses, and a real example where they refused to name an actor.
They attribute to a nation state from thin infrastructure overlap or claim their analysis is never wrong.
09Walk me through a time your threat intelligence work helped mitigate an actual incident. What changed because of your report?
Listen forA specific chain: what they saw, who they told, and the resulting action (detection rule shipped, credential reset, egress block, emergency patch) with rough timing.
The story ends when the report was published, with no owner, no action taken, and no measurable outcome.
10What is your approach to running a threat hunting exercise, and what hypothesis did your last hunt start from?
Listen forA hypothesis driven method grounded in a specific technique, named data sources (EDR telemetry, DNS logs, proxy, Sysmon), and what happened when the hunt found nothing.
Hunting described as searching a SIEM for the latest published IOC list with no hypothesis behind it.
Reporting and collaboration
2 questions11Brief me for sixty seconds on a recent campaign as if I am a CFO with no security background.
Listen forPlain language, business impact first, no unexplained jargon, a clear ask or recommendation, and a stated confidence level inside the time limit.
Malware family names, technique IDs, and infrastructure detail delivered with no answer to why the executive should care.
12How have you worked with incident response and vulnerability management teams, and what did they need from you that you were not already producing?
Listen forNamed handoffs: enriching an IR case during containment, feeding exploitation evidence into patch prioritisation, and a specific change they made after stakeholder feedback.
They describe intelligence as a standalone function and cannot name a single consumer or their requirements.
How to score responses
Score every candidate on the same four criteria immediately after the screen. At this stage you are shortlisting for panel interviews, not making the final call.
Technical depth
35%5Knows adversary tradecraft and frameworks properly, with sourcing that goes well past vendor feeds.
Real incidents and findings
30%5Names intelligence they produced that changed a defensive decision, and how they knew it landed.
Risk judgement
20%5States confidence levels explicitly, resists premature attribution, and revises publicly when new evidence lands.
Getting things fixed
15%5Writes for both SOC and executive audiences so each can act, without diluting or inflating the assessment.
Threat intelligence lives or dies on the briefing. Async video lets you hear whether they can explain an intrusion set to a non-technical executive in sixty seconds without jargon, which no written application will ever show you.
Try it on HirevireScreening FAQ
Process basics
What should a threat intelligence analyst screen cover before the technical panel?
Cover four areas before the panel: frameworks and adversary tradecraft (ATT&CK, Diamond Model, kill chain), where their intelligence comes from beyond paid feeds, one finding that changed a defensive control, and how they write for different readers. Leave deep malware analysis, pivoting exercises, and infrastructure hunting demonstrations to the live technical round where you can watch them work.
Should I ask for a writing sample from a threat intelligence analyst?
Yes, but ask for a redacted or public one. Most operational reporting is client confidential, so request a published blog post, a conference talk, a sanitised threat profile, or an ATT&CK Navigator layer they built. If nothing shareable exists, ask them to brief a recent public campaign on video for sixty seconds instead.
Evaluating answers
How do I tell a real intelligence analyst from someone who just forwards vendor feeds?
Listen for the decision their work triggered. Real analysts name the detection rule written, the control tuned, the patch prioritised, or the executive who changed spend, and they say who consumed the report. Feed forwarders describe volume (IOCs ingested, reports circulated) and cannot explain what happened after the report went out.
What is a good answer on attribution and confidence?
A good answer separates observation from assessment and uses calibrated language. Look for analytic confidence levels, willingness to say "moderate confidence, based on infrastructure overlap and shared tooling", and awareness that shared tooling is weak evidence. Confident naming of a nation state actor from a single IP or a vendor cluster name is the pattern to distrust.
























