The most frustrating conversations I've had this year all follow the same pattern: talented people who can't get their foot in the threat intelligence door because they've never held a job with 'CTI' in the title. Circular logic at its finest.
"We like your application, but you don't have threat intelligence experience."
The circular logic is maddening.
Seven years sweating in a bank SOC before moving to consultancy showed me what hiring managers are looking for beneath the job spec rhetoric. And it's rarely what candidates think.
The market for cyber threat intelligence talent has never been hotter than in mid-2026. The NCSC's latest sector health report shows demand spiking, especially since the Financial Conduct Authority mandated threat-led resilience testing in the finance sector last autumn.
The Catch-22 of CTI Careers
The entry bar to threat intelligence work seems impossibly high. Job ads demand years of experience alongside impossible combinations of technical skills, language proficiency, and industry knowledge. Junior roles barely exist.
There's a side entrance.
Increasingly, I'm seeing candidates land CTI roles without formal experience by building a body of work that demonstrates capability, rather than waiting for permission to start. They're creating portfolios that speak louder than CVs.
Beyond Tick Boxes: Diversity Recruitment Strategies That Actually Transform UK Workplaces
Master the Virtual Hot Seat: 7 Video Interview Techniques Recruiters Don't Tell You
How to Master 'Tell Me About Yourself' Interview Question: UK Expert Insights
Open-source contributions are the new internship
Nobody will hand you threat intelligence experience. The smartest candidates I've placed this year built credibility through sustained, visible contribution to open-source intelligence projects.
Three approaches stand out:
Build your own intelligence feed
A junior analyst I placed at a major retailer in March created a GitHub repository tracking supply chain compromise techniques. He monitored public breaches, categorised them using MITRE ATT&CK, and published quarterly trend analysis.
Consistent, methodical work that demonstrated:
- Understanding of intelligence collection methodology
- Ability to use structured frameworks
- Writing skills for threat reporting
- Persistence (he maintained it for 9 months)
He landed a £45K role despite zero formal CTI experience, competing against candidates with years on paper but nothing tangible to show.
Contributing to existing OSINT communities
The Open Threat Research community has become a kingmaker for entry-level talent. Regular contribution to their projects gives you both visibility and validation from established professionals.
One standout example was a former helpdesk technician who spent six months contributing to OTR's election security monitoring in the run-up to the UK general election. Her consistent work mapping disinformation campaigns using MITRE ATT&CK's influence operations tactics got her noticed by a consultancy that ultimately hired her.
She demonstrated the methodical thinking and communication skills that matter more than programming ability in many CTI roles.
MITRE ATT&CK: The universal language of threat intelligence
Become fluent in MITRE ATT&CK. It's gone from useful framework to industry lingua franca.
The power of ATT&CK lies in how it bridges technical and non-technical domains. Knowing how to map real-world activity to the framework demonstrates you can translate between technical findings and business impact.
Two practical ways to demonstrate ATT&CK proficiency:
1. Retroactive breach analysis
A candidate who caught my eye took publicly disclosed breaches and created comprehensive ATT&CK mappings of the tactics and techniques used. The concept was straightforward. The execution was what stood out.
She published these on a personal blog, showing how an attack might have progressed and where detection opportunities were missed. This demonstrated both technical understanding and the ability to tell a coherent story about an incident.
2. Technology-specific mappings
Another approach that's worked well is creating ATT&CK mappings for specific technologies. One candidate mapped potential attack paths through Microsoft 365, documenting techniques and mitigations.
This kind of focused work demonstrates technical depth and the ability to think like an attacker, which is what CTI roles require.
The CTI home lab that actually impresses
Every candidate claims to have a home lab. Most are just generic IT setups. The CTI home labs that actually impress hiring managers show specialisation and purpose.
A former desktop support engineer I placed built a lab specifically focused on tracking and analysing malware behaviour. Nothing fancy - just a well-documented environment for safely detonating samples and documenting TTPs using the ATT&CK framework.
What impressed wasn't technical sophistication but his process and documentation. He maintained a personal MITRE ATT&CK navigator layer based on his findings and published it regularly. This demonstrated the methodical approach needed in threat intelligence.
Community credibility trumps certificates
Active participation in CTI communities often carries more weight than certifications.
That's not to say certs are worthless. The SANS FOR578 (Cyber Threat Intelligence) remains well-regarded, and the relatively new CTIA (Cyber Threat Intelligence Analyst) certification from EC-Council has gained traction this year.
But I've repeatedly seen hiring managers choose candidates with community recognition over those with certifications but no visible work. Forums like CTI League and the UK's Cyber Security Information Sharing Partnership (CiSP) have become talent spotting grounds.
A candidate who regularly shares quality insights in these communities builds credibility that no certificate can match. I placed someone last month who had zero formal qualifications but had built a reputation through consistent contribution to CiSP. The hiring manager already knew their work.
Breaking in through adjacent roles
If direct entry still proves difficult, consider the side door. Certain roles frequently transition into threat intelligence:
- SOC analysts with a knack for pattern recognition
- Vulnerability management specialists who understand exploitation paths
- Digital forensics practitioners who naturally think in attack narratives
- Even fraud analysts from financial services who understand how to track criminal behaviours
What these roles share is exposure to attack patterns and defensive thinking. I made this transition myself, leveraging SOC experience into a threat intelligence position by demonstrating how I'd already been doing intelligence work in all but name.
Soft skills
Communication skills often matter more than technical ability in CTI roles.
The most brilliant technical analysis is worthless if nobody understands it or acts on it. The best threat intelligence professionals I know are translators between technical findings and business decisions.
So how do you prove these skills? Through your existing contributions. Write clearly about complex topics. Create visualisations that make data meaningful. Explain why things matter, not just what they are.
Demonstrating these skills in public work - whether blog posts, GitHub repositories, or community forums - gives hiring managers confidence you can perform a crucial part of the job that's hard to teach.
Just start
Nobody will invite you to practise threat intelligence. You have to start doing the work before you have the job.
Imposter syndrome hits hard. The questions are predictable: who am I to publish this? What if I get something wrong?
But starting is what separates those who break in from those who don't. Everyone gets things wrong. What matters is the process, the thinking, the communication.
Pick an area that interests you. Start small, be consistent, and build in public.
Threat intelligence isn't about having all the answers or access to classified information. It's about asking good questions and following a rigorous process. That, you can start demonstrating today.
The best CTI candidates I've placed didn't wait for permission. They started doing the work, and hiring managers noticed.
