Cyber Intelligence Analyst
Eli Lilly
- Location
- Indianapolis, Indiana, United States of America
- Employment
- Full Time
- Work model
- On-Site
- Level
- Mid
- Posted
- Aug 17, 2026
Skills
About this role
At Lilly, the work is demanding because patients are waiting. We unite caring with discovery to help make life better for people around the world, knowing that every decision, every detail, and every day matters. Headquartered in Indianapolis, Indiana, our over 50,000 employees around the globe take on complex challenges to discover and deliver life-changing medicines, strengthen how health is understood and managed, and support the communities we serve. This is hard, urgent, selfless work—but it’s work worth doing. If you’re driven by purpose and ready to bring your best to work that truly matters for patients, we invite you to join us. Do you like to be in the heart of the action, on the front lines of cybersecurity defense, creating a defense system to thwart cyber-attacks? Join us as we do this daily to protect our patients, employees, and shareholders. The Global Cyber Defense Operations (GCDO) team is dedicated to active defense through analysis, innovation, and collaboration. Our mission focuses on unifying detection, analysis, and response strategies to safeguard Lilly's ability to develop life-changing medicines. The threat of cybersecurity attacks has never been greater, and the GCDO’s mission has never been more important.
What You Will Be Doing
The Cyber Intelligence Analyst will operate in a functional group focusing on any of the following: Attack Surface Management, Cyber Threat Intelligence, Detection and Automation Operations, Cyber Defense Readiness, External Threat Response, and Insider Threat Response. Analysts typically begin with an assignment in the External Threat Response (ETR) function; however, you may be assigned to any of the core GCDO functions (Attack Surface Management, Cyber Threat Intelligence, Cyber Defense Readiness, Detection and Analysis Operations, Internal Threat Response) based on skills, development needs, and specific needs of the team. The functions of the GCDO are as follows: External Threat Response (ETR): Responsible for the monitoring, detection, analysis, investigation, and response to cybersecurity related events and incidents. Attack Surface Management (ASM): Responsible for reducing the overall attack surface of the Enterprise, including the identification, analysis, and remediation of vulnerabilities. Cyber Threat Intelligence (CTI): Leading efforts across the organization to consume, contribute, and produce threat intelligence, both internal and external to Lilly. Maintain, develop, and evangelize to partner functions an understanding of threats, attack campaigns and intrusion sets targeting Lilly. Cyber Defense Readiness (CDR): Responsible for the integration of key initiatives between the GCDO and the rest of Cybersecurity and other business partners. Detection and Analysis Operations (DAO): Responsible for general SecOps and DevOps of GCDO owned capability to empower the organization. Establishing the platform and services to enable the effective detection and monitoring of security events, as well as providing a means to analyze and improve detections. Internal Threat Response (ITR): Responsible for the monitoring, analysis, and investigation of cybersecurity related events and incidents, with a focus on the internal workforce. How You Will Succeed: Through the effective performance of the following responsibilities: Supporting: Assisting in various cybersecurity and other work as assigned. Analyzing: Examining cyber threats and incidents. Developing: Creating capability to enable each core function. Documenting: Thorough documentation of your analysis. Detecting: Identifying potential security issues. Prioritizing: Ranking threats based on severity. Responding: Taking action to mitigate threats. Recommending Strategic Changes: Drive security improvements that will increase our ability to defend the Enterprise. Provide rotational on-call availability for cybersecurity incidents raised outside of normal business working hours.
Basic Qualifications
HS