Cyber Threat Intelligence Analyst, Associate
Morgan Stanley
- Location
- Singapore, Singapore
- Work model
- On-Site
- Level
- Entry
- H-1B history
- 39 approvals (FY2023)
- Posted
- Aug 21, 2026
Skills
About this role
We're seeking someone to join our team as a Cyber Threat Intelligence Analyst in Technology to support technical threat investigations, track cyber adversaries, and produce actionable intelligence that strengthens detection, response, and risk-informed decision-making. In the Technology division, we leverage innovation to build the connections and capabilities that power our Firm, enabling our clients and colleagues to redefine markets and shape the future of our communities. What you'll do in the role: > Conduct proactive threat research and investigative analysis to identify adversary campaigns, capabilities, infrastructure, targeting, and tactics, techniques, and procedures (TTPs) using internal collection, OSINT, and commercial intelligence sources. > Research and track relevant threat actors, malware families, vulnerabilities, campaigns, and emerging threats, maintaining current knowledge of adversary behaviors and tradecraft. > Triage cyber threat intelligence alerts and incoming intelligence, assessing relevance, credibility, severity, and potential impact, and escalating actionable findings as appropriate. > Author clear, concise, and actionable threat intelligence reports, including tactical and technical reporting, threat assessments, investigative summaries, and intelligence briefings tailored to operational and non-technical audiences. > Enrich, validate, and characterize threat indicators and technical artifacts using open-source, commercial, and internal security tooling, and curate high-confidence indicators of compromise (IOCs) for operational use. > Apply analytic frameworks such as MITRE ATT&CK and the Diamond Model to characterize adversary activity, infrastructure, capabilities, and relationships. > Analyze internal and external security data to identify patterns, correlations, and emerging trends that support threat investigations and intelligence assessments. > Partner with threat hunting, security monitoring, incident response, detection engineering, and other cybersecurity teams to translate threat intelligence into detection opportunities, investigative leads, mitigations, and control validation activities. > Maintain and update threat profiles aligned to assigned areas of responsibility and contribute intelligence that supports proactive detection and discovery. > Contribute to the development and improvement of CTI analytic processes, investigative tradecraft, playbooks, and automation to improve the consistency and efficiency of intelligence workflows. > Where applicable, use scripting and data analysis techniques, including Python, to support investigations, enrichment, data processing, and analytic workflows. What you'll bring to the role: > Min 4 years of experience in cyber threat intelligence, cybersecurity investigations, threat hunting, security operations, incident response, or a related cybersecurity discipline. > Experience researching cyber threat actors, malware, campaigns, vulnerabilities, and adversary TTPs using internal, open-source, and/or commercial intelligence sources. > Familiarity with intelligence analysis frameworks and methodologies such as MITRE ATT&CK, the Diamond Model, intelligence lifecycle, and structured analytic techniques. > Experience conducting alert triage and investigative analysis, including evaluating intelligence for relevance, credibility, and potential organizational impact. > Strong report writing and analytic communication skills, with the ability to clearly articulate evidence, assessments, confidence levels, implications, and recommended actions. > Understanding of intelligence requirements and collection management concepts, including identifying information gaps and aligning collection activity to priority intelligence needs. > Familiarity with SIEM, endpoint, network, threat intelligence platform, or other security tooling and the ability to interpret relevant security telemetry in support of investigations. > Experience enriching and analyzing