Senior Cyber Threat Intelligence (CTI) Analyst
Live Nation
- Location
- Farringdon, London, United Kingdom
- Work model
- On-Site
- Level
- Senior
- Posted
- Aug 12, 2026
Skills
About this role
Job Summary
Senior Cyber Threat Intelligence (CTI) Analyst UK (9:00 AM – 18:00 PM GMT) Live Nation Entertainment – Cyber Security Operations, Cyber Security THE TEAM Live Nation is seeking a Senior Cyber Threat Intelligence (CTI) Analyst to drive hands-on intelligence analysis and research across our global environment. This role sits within the Detection and Response Engineering, CTI, and Threat Hunting team. The team focuses on identifying emerging threats, conducting in-depth analysis of malicious activity, and enhancing the organization’s security posture, detection, and incident response capabilities.
THE ROLE
This is a hands-on senior individual contributor role for an analyst who wants to stay technical: researching threat actors and their infrastructure, digging into malware and phishing campaigns, tracking ransomware and the cybercrime ecosystems targeting live entertainment, ticketing, and e-commerce, and turning that research into intelligence that drives decisions. The CTI Analyst will work cross-functionally with Detection Engineering, Incident Response, Threat Hunting, Vulnerability Management, Fraud, and external partners to provide actionable intelligence, and will help mature the CTI program while remaining closely engaged in day-to-day analysis. WHAT THIS ROLE WILL DO Conduct hands-on cyber threat intelligence analysis focused on threat actors, campaigns, tactics, techniques, procedures, infrastructure, malware, phishing activity, ransomware, and the cybercrime ecosystems targeting live entertainment, ticketing, and e-commerce. Produce tactical, operational, and strategic intelligence products including threat assessments, intelligence reports, executive briefings, RFIs, threat actor profiles, and actionable recommendations for stakeholders. Own and support the intelligence lifecycle, including requirements gathering, collection, analysis, enrichment, dissemination, and feedback. Translate raw threat data, OSINT, vendor intelligence, dark web research, internal telemetry, and partner reporting into clear, actionable intelligence. Conduct technical research on malicious infrastructure, tooling, and tradecraft used by threat actors, including infrastructure pivoting, malware and phishing kit triage, and campaign attribution analysis. Surface detection opportunities from technical research and partner with Detection Engineering to turn them into detection content such as YARA, Sigma, or SIEM queries. Support threat hunting, detection engineering, incident response, vulnerability management, fraud, and broader cyber defense teams with intelligence-driven context and prioritization. Develop and refine Priority Intelligence Requirements, collection priorities, analytical workflows, and reporting processes to improve the quality and relevance of CTI outputs. Analyze threat actor behavior and map activity to frameworks such as MITRE ATT&CK to support defensive strategy and risk-based decision-making. Brief technical, business, and senior leadership stakeholders on cyber threats, trends, potential business impact, and recommended actions. Mentor and guide other analysts through influence, tradecraft coaching, intelligence writing, and analytical review. Help mature CTI processes, tools, reporting standards, and intelligence outputs while remaining closely engaged in hands-on analysis. Support the development and automation of threat analysis workflows and tooling, and operate threat intelligence platforms such as MISP, ThreatConnect, EclecticIQ, or Anomali. Periodically participate in on-call rotations and support incident response efforts. WHAT THIS PERSON WILL BRING 5+ years of hands-on cyber threat intelligence experience in a dedicated CTI, cyber intelligence, or threat intelligence function. Demonstrated experience conducting threat actor analysis, adversary tracking, campaign analysis, IOC/TTP analysis, and intelligence production, including use of MITRE ATT&CK or similar frameworks to structure