HOME Cybersecurity & Info Security Principal Analyst, Mandiant Threat Intelligence Services
  • Google
  • Durham, NC
  • Full-Time
  • <48 Hours
Google VERIFIED EMPLOYER

Principal Analyst, Mandiant Threat Intelligence Services.

Remote Cybersecurity & Info Security Full-Time

Principal Analyst, Mandiant Threat Intelligence Services: our view in 3 lines...

  • The Role:This role is for a principal analyst delivering cyber threat intelligence services for a key account within Google Cloud.
  • The Person:The person will analyse adversarial cyber threats, correlate intelligence from multiple sources, and prepare briefings and reports for customer stakeholders and executives.
  • Requirements:The ideal candidate has a bachelor’s degree or equivalent practical experience, 8 years in a customer-facing investigative cybersecurity role, and experience with project management, packet capture, log data, malware triage, and information security operations.

About the role

Minimum qualifications:

  • Bachelor's degree or equivalent practical experience.
  • 8 years of experience in a customer-facing investigative role in cyber security (e.g., Network Forensics Analyst, Threat Intelligence Analyst).
  • Experience engaging with, and presenting to, technical stakeholders and executive leaders.
  • Experience with project management.

Preferred qualifications:

  • 10 years of experience evaluating forensic reports of electronic media, packet capture, log data, malware triage, or enterprise-level information security operations.
  • Direct experience processing and analyzing tactical Cyber Threat Intelligence (CTI) within an fast-paced operational environment, supporting monitoring, detection, and response capabilities.
  • Experience evaluating host and network forensic reports of electronic media, packet capture, log data analysis, malware triage and network devices in support of information security operations.
  • Ability to correlate raw intelligence from sensors, incident response engagements, and other sources into reports and briefings.
  • Ability to take complex, ambiguous topics, build strategy, and influence stakeholders.

About the job:

Mandiant is a recognized leader in dynamic cyber defense, threat intelligence and incident response services. By scaling decades of frontline experience, Mandiant helps organizations to be confident in their readiness to defend against and respond to cyber threats. Mandiant Threat Intelligence Services is a part of Google’s Threat Intelligence Group under Google Cloud.

Advanced Intelligence Access (AIA) is Mandiant’s premium cyber threat intelligence subscription, offering customers access to a wide range of Mandiant data, tooling, and expertise via a dedicated Mandiant employee, providing support within the customer’s network. AIA is tailored to the needs of each customer, allowing for improved integration and outcomes.

As a Principal Analyst, you will provide Mandiant Threat Intelligence Services supporting a key account—your role will be to deliver intelligence expertise to various client stakeholders. You will serve as a tactical liason to Cyber Defense stakeholders in Detection Engineering, Threat Hunt, and Threat Emulation functions.

The position is fully remote with limited to no client onsite requirement.

Part of Google Cloud, Mandiant is a recognized leader in dynamic cyber defense, threat intelligence and incident response services. Mandiant's cybersecurity expertise has earned the trust of security professionals and company executives around the world. Our unique combination of renowned frontline experience responding to some of the most complex breaches, nation-state grade threat intelligence, machine intelligence, and the industry's best security validation ensures that Mandiant knows more about today's advanced threats than anyone.

Individual pay is determined by factors including job-related skills, experience, and relevant education or training.

US: $168000 - $243000 (USD) + 20% bonus target + equity + benefits

Learn more about benefits at Google.

Responsibilities:

  • Evaluate tools and best practices for tracking advanced threats, tools, techniques, and procedures (TTPs) of attacker’s motivations, and industry and attacker trends.
  • Perform strategic, tactical, and operational research and analysis of adversarial cyber threats.
  • Correlate intelligence to develop deeper understandings of tracked threat activity.
  • Communicate complex technical findings clearly to technical and non-technical stakeholders, while partnering with operational and tactical intelligence practitioners to identify and action evolving intelligence needs and request for information (RFIs).
  • Work with customers to determine their intelligence needs and requirements and prepare and deliver briefings and reports to the customers' executives, security team, and fellow analysts.

Published September 30, 2026
Location Durham, NC
Job Type Full-Time