Jobs and Careers
BL

Threat Intelligence Analyst, Associate - Security Operations

Blackstone
New York 601 Lex, United States, United Statesfull_timeVerifiedPosted 10 Jul 2026
💰 $170,000/yr($135,000/yr$170,000/yr)

About the role

Blackstone is the world’s largest alternative asset manager. Blackstone seeks to deliver compelling returns for institutional and individual investors by strengthening the companies in which the firm invests. Blackstone’s over $1.3 trillion in assets under management include global investment strategies focused on real estate, private equity, credit, infrastructure, life sciences, growth equity, secondaries and hedge funds. Further information is available at www.blackstone.com. Follow @blackstone on LinkedInX (Twitter), and Instagram

Business Unit Overview

Blackstone Technology & Innovations (BXTI) is the technology team at the core of each of Blackstone's businesses and new growth initiatives. Serving both internal and external clients, we work to build the next generation of systems that manage risk, create efficiency and improve transparency within the firm and across our broad community of investors and portfolio companies.

BXTI is entrepreneurial – our open, iterative design processes and rapid pace of development mean that everyone on the team has the opportunity to make an impact from day one. We are problem solvers who can take projects from idea to implementation. We believe in active mentoring and developing excellence. We collaborate to find the best answers for our customers and for our firm.

Position Overview

The Cyber Threat Intelligence (CTI) team within Blackstone Security Operations identifies, tracks, and assesses cyber threats relevant to Blackstone and its portfolio companies. The Associate Threat Intelligence Analyst conducts tactical, operational, and strategic analysis to inform defensive operations, risk decisions, and executive awareness. This is a team at the cutting edge of cyber defense: we are pioneering the use of AI and automation to outpace adversaries, we move quickly from idea to production, and we give analysts real ownership to shape how intelligence is practiced rather than slot into a routine. This is hands-on intelligence and engineering work: monitoring the evolving threat landscape, producing finished intelligence products and reports, extracting and enriching indicators of compromise (IOCs), and helping manage the firm's external attack surface and exposure risk. The analyst leverages AI and automation tooling to collect, enrich, and operationalize intelligence at scale, and develops clear visual products such as diagrams to make threats understandable to both technical and non-technical audiences. The role works closely with detection engineering, incident response, and vulnerability management to turn intelligence into new detections and preventions, helping protect one of the world's leading investment platforms where cybersecurity and global finance meet.

Responsibilities

• Monitor and analyze cyber threat activity targeting the financial sector, alternative asset management, and adjacent industries using open-source, commercial, and internal sources, correlating across them to identify patterns and provide early warning of emerging campaigns

• Produce finished intelligence products and reports including recurring threat reporting, advisories, campaign profiles, actor dossiers, executive briefings, and visual products such as diagrams, tailored to both technical and non-technical audiences

• Map adversary behaviors to the MITRE ATT&CK framework and maintain threat actor profiles covering TTPs, intent, and relevance to Blackstone

• Extract, validate, enrich, and operationalize indicators of compromise (IOCs) to support detection engineering and incident response workflows

• Leverage AI and automation tooling to scale collection, enrichment, and operationalization of intelligence

• Partner with Alert, Detection & Response and Incident Response teams to translate intelligence into production detections (Splunk SPL, Sigma, YARA)

• Track zero-day and critical vulnerabilities, assess Blackstone's exposure, and translate findings into new detections and preventions in coordination with detection and security engineering

• Support threat-informed vulnerability prioritization (CVSS, EPSS, CISA KEV) and coordinate remediation tracking with asset owners

• Operate and evolve the firm's external Attack Surface Management (ASM) program, discovering and inventorying internet-facing assets across Blackstone and its portfolio companies, triaging newly discovered exposures and misconfigurations, and

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Blackstone

View company profile →