
Lead Cyber Intelligence Analyst
McKesson
Job description
Conceptual Proactive Problem-Solver Strategic Technologically Savvy Visual Thinker <meta data-json="{"ModuleType":13,"ApplyButtonText":"Apply","JobDetailsAlign":0,"JobDetailsDate":0,"JobDetailsJobTypeId":1,"JobDetailsSelectedDate":"2026-10-07T20:31:52.939Z","JobDetailsJobDateFormat":0,"JobDetailsJobLabelId":"Job ID","JobDetailsJobDatePosting":"Date posted","JobDetailsDescriptionFormat":0,"ShowApplyLater":false,"ShowApplyMobile":true,"ShowApplyLaterMobile":false,"ShowApplyLaterWeb":false,"ApplyLaterText":"Apply Later","ApplyLaterAlign":0,"ApplyLaterSubject":"[[JOB_TITLE]] at [[COMPANY_NAME]]","PublishedCandidateCardPageId":null,"ReferrerPageId":null,"ReferrerPageButtonText":"","ShowSavedJobsIcon":false,"IconLabel":"Save for Later","OverrideCandidateCard":false,"ModulePageType":2,"ModulePageName":"AJD - Design 1","DisplayJobDateFormat":"MM/dd/yyyy","JobDetailsSelectedId":"JR0154970","ApplyUrl":"https://mckesson.wd3.myworkdayjobs.com/External_Careers/job/USA-TX-Irving/Lead-Cyber-Intelligence-Analyst_JR0154970-1/apply","JobDescription":"\u003Cp style=\u0022text-align:left\u0022\u003EMcKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being of you and those we serve \u2013 we care.\u003C/p\u003E\u003Cp style=\u0022text-align:inherit\u0022\u003E\u003C/p\u003E\u003Cp style=\u0022text-align:left\u0022\u003EWhat you do at McKesson matters. We foster a culture where you can grow, make an impact, and are empowered to bring new ideas. Together, we thrive as we shape the future of health for patients, our communities, and our people. If you want to be part of tomorrow\u2019s health today, we want to hear from you.\u003C/p\u003E\u003Cp style=\u0022text-align:inherit\u0022\u003E\u003C/p\u003E\u003Cp style=\u0022text-align:inherit\u0022\u003E\u003C/p\u003E\u003Ch2\u003E\u003Cb\u003EAbout the Role\u003C/b\u003E\u003C/h2\u003E\u003Cbr /\u003E\u003Cp\u003EMcKesson is seeking a highly skilled Lead Information Security Analyst to strengthen our cyber threat intelligence capabilities. This role serves as a senior intelligence leader responsible for identifying, analyzing, and communicating cyber threats that may affect the enterprise, its business operations, and the healthcare sector.\u003C/p\u003E\u003Cp\u003EAs a lead analyst, you will partner with cybersecurity, technology, risk, legal, and business teams to define intelligence needs, assess emerging threats, translate complex findings into relevant business insights, and guide risk-informed decisions. You will also mentor analysts, strengthen analytic tradecraft, and improve how intelligence is collected, produced, and shared.\u003C/p\u003E\u003Cbr /\u003E\u003Cp\u003E\u003Cb\u003EWhat You\u0027ll Do\u003C/b\u003E\u003C/p\u003E\u003Cbr /\u003E\u003Cul\u003E\u003Cli\u003EIdentify and track emerging threats by discovering untracked adversary activity, developing new threat clusters into tracked actor groups across McKesson telemetry\u003C/li\u003E\u003Cli\u003EDeliver time-sensitive behavioral attack chains supporting active incident response and threat hunting operations to drive cross-team detection and protection actions.\u003C/li\u003E\u003Cli\u003ELead attribution and threat actor analysis by collecting, modeling, attributing, and documenting intelligence gathered during investigations. Serve as the primary owner for attribution efforts while partnering with incident response teams.\u003C/li\u003E\u003Cli\u003EAuthor actor profiles for the CIRT, Red Team, Threat Hunt, and Detection Engineering-- leveraging internal signals, open-source, vendor research, and sharing community reporting\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ELeverage AI to guide investigations and automation (e.g., intel-to-detection pipelines, infrastructure clustering, cross-actor TTP analysis) to scale production beyond manual analysis\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EProvide technical mentorship to mid-level analysts on tradecraft, source evaluation, and production standards\u003C/li\u003E\u003Cli\u003ERepresent the intelligence function in cross-functional planning with SOC, threat hunting, red team, and incident response\u003C/li\u003E\u003Cli\u003EContribute to strategic planning on how internal telemetry investments map to intelligence production goals\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003E\u003C/p\u003E\u003Ch2\u003E\u003Cb\u003EBasic Requirements\u003C/b\u003E\u003C/h2\u003E\u003Cbr /\u003E\u003Cul\u003E\u003Cli\u003E\u003Cb\u003E10\u002B years of cybersecurity, information security, cyber threat intelligence, threat research, or related experience.\u003C/b\u003E\u003C/li\u003E\u003Cli\u003EBachelor\u0027s degree in Cybersecurity, Information Security, Computer Science, Information Systems, or related field; equivalent experience will be considered.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience developing a telemetry-to-intelligence model that reduces reliance on third-party feeds and vendors\u2014shifting teams from intel consumers to intel producers\u003C/li\u003E\u003Cli\u003EExperience with open source research tools, including Virus Total, Domain Tools, Censys, Grey Noise, and other similar tools.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience in tactical threat intelligence, specifically identifying IOCs, tools, and behavioral fingerprints left by adversaries across our telemetry (endpoint, network, cloud, and identity)\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EMine SIEM, EDR, NDR, firewall, DNS, proxy, and cloud logging data to identify adversary tradecraft, infrastructure, and behavioral patterns unique McKesson\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience using MITRE ATT\u0026CK, Cyber Kill Chain, or similar frameworks to structure and communicate threat analysis.\u003C/li\u003E\u003Cli\u003EExperience with threat intelligence platforms, link analysis, data enrichment, or scripting and automation that support intelligence workflows.\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003E\u003C/p\u003E\u003Ch2\u003E\u003Cb\u003EPreferred Skills/Experience\u003C/b\u003E\u003C/h2\u003E\u003Cbr /\u003E\u003Cul\u003E\u003Cli\u003EAdvanced cyber threat intelligence experience using TIPs, commercial reporting, OSINT, information-sharing communities, and dark web intelligence sources.\u003C/li\u003E\u003Cli\u003EExperience building or maturing a cyber threat intelligence program, operating model, or intelligence lifecycle.\u003C/li\u003E\u003Cli\u003EKnowledge of intelligence collection management, source validation, confidence assessments, and structured analytic techniques.\u003Cul\u003E\u003Cli\u003EExperience with design, build, and optimize intelligence systems for structured storage, correlation, and analytics of large-scale threat intelligence data sets.\u003C/li\u003E\u003C/ul\u003E\u003C/li\u003E\u003Cli\u003EExperience supporting regulatory, audit, compliance, or healthcare security environments.\u003C/li\u003E\u003Cli\u003ERelevant certifications such as CISSP, GCTI, OSCP, GREM, or equivalent intelligence, cybersecurity, or analytic credentials.\u003C/li\u003E\u003Cli\u003EExperience coaching technical teams and leading cross-functional security initiatives.\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003E\u003C/p\u003E\u003Ch2\u003E\u003Cb\u003ETravel / Work Environment / Physical Requirements\u003C/b\u003E\u003C/h2\u003E\u003Cbr /\u003E\u003Cul\u003E\u003Cli\u003EMay require occasional travel (up to 10%) based on business needs.\u003C/li\u003E\u003Cli\u003EHybrid or remote work arrangements may be available based on location and business requirements.\u003C/li\u003E\u003Cli\u003EAbility to work extended hours during critical security incidents when necessary.\u003C/li\u003E\u003C/ul\u003E\u003Cbr /\u003E\u00
Verified and listed by ActiveJobs. Applications are made directly on McKesson's own career page — we never sit in the middle.