Navigation
AboutExperienceBlogResourcesMerchContact

inquiries@ctijen.com

← Back to Resources
CTIJen Resources

Frequently Asked Questions

The questions Jen gets asked most often, answered honestly.

What is Cyber Threat Intelligence?

CTI is the practice of collecting, processing, and analyzing information about threats, then turning it into recommendations that stakeholders can actually act on. For the fuller picture, including the frameworks and terms everyone in the field uses, check out Where to Start.

Do I need to know how to code?

Nope, not to get started. Plenty of CTI work is research, analysis, and writing rather than scripting. That said, being able to write basic Python or work with regex will make you faster at parsing data and automating the boring parts. It's a nice-to-have, not a gatekeeper.

How is CTI different from SOC, DFIR, or pentesting?

They're related but distinct. A SOC analyst watches for and responds to alerts in real time. DFIR (Digital Forensics & Incident Response) investigates what already happened on a compromised system. A pentester tries to break into systems on purpose to find weaknesses before an attacker does. CTI sits a layer above all of that: less "what's happening on this machine right now" and more "who's likely to target us, how do they operate, and what should we do about it."

Do I need a degree to work in CTI?

Nope, but it can help depending on the org. What matters more in practice is demonstrated research ability, writing and communication skills, and some foundation in how networks and attacks actually work. A degree is one way to build that, but it's definitely not the only one.

How do I get into Cyber Threat Intelligence?

There's no single path, but if I had to describe the most common progression: it often starts with a SOC analyst role. From there, a more specialized role follows, maybe IAM engineer or Insider Threat Analyst. CTI roles often come next. Outside of your day job, I highly recommend creating your own content: a Medium blog with posts mapping intrusions to the Diamond Model, or researching an APT and writing your mitigation recommendations. This demonstrates field experience without needing an official title.

What certifications should I get?

The annoying answer is 'it depends.' Certs show a baseline level of knowledge and can definitely help, but no set of certs guarantees a role. If you're brand new to cybersecurity, start with Security+. If you're already seasoned in cyber and ready to go deep on CTI, I'd recommend GCTI right out of the gate. For the full landscape, Paul Jerimy's Security Certification Roadmap is indispensable. Hit me up for a tailored recommendation.

What resources are available to learn more?

Well, well, well. You're never going to believe this… but I happen to have a repository right here.

Have a question that's not answered here? Send it over and I may add it to the list!

Ask a question →