28 tasks, each one witnessed by the sources that watched the job — and behind every one, a prompt you can use tonight.
You usually split time between reading raw data and turning it into products leaders can act on. Mornings often mean ingesting feeds — surveillance logs, intercepted comms, or business data — and checking alerts from systems like Apache Kafka or ESRI ArcGIS.
Afternoons are for analysis and writing: correlating data in Hadoop/Spark or Hive, validating leads, interviewing a source if needed, and drafting a report or map. Expect admin tasks: maintaining records, updating case files, and testing a new tool or script in Linux.
Start with ESRI ArcGIS if you will map locations and visualize assets or movement — many investigations need maps. Learn basic GIS workflows: layers, geocoding, and exporting map images for reports.
If your work handles big datasets, next learn Hadoop and Spark (Spark runs analytics faster on top of Hadoop). Practice querying and processing data; Hive helps write SQL-style queries. Knowing Linux helps run these tools.
Use AI to find patterns — for example, clustering suspicious transactions or flagging anomalous communications — but never let it decide alone. Always validate AI outputs with human review and multiple data sources, as one task is to "validate known intelligence with data from other sources."
Keep models auditable: log inputs, versions, and why a model flagged something. That helps interpret deceptive or adversarial information and supports the analyst’s judgment when presenting findings.
The Bureau of Labor Statistics (BLS) reports 114,430 employed intelligence analysts with a median annual wage of $93,790. The lowest 10% earn about $55,390 and the top 10% about $160,540 per year (BLS, 2025).
These are national figures; actual pay varies by employer (federal agency, private company) and location. Expect higher pay in cities with many agencies or contractors.
Begin with Python or JavaScript basics and a Linux command-line course; they let you run scripts and use open-source tools. Then take a short ESRI ArcGIS course for mapping and practice SQL-style queries in Apache Hive on sample datasets.
Next, learn Hadoop and Spark concepts (batch vs. stream processing) and try small projects: process logs with Spark, or set up Kafka to stream messages. Build a portfolio: a map, a cleaned dataset, and a short written intelligence product.
Compared with a data analyst, you focus less on business metrics (like quarterly growth) and more on threats, vulnerabilities, and influence — plus human sources and interviews. You still use BI tools and present visual data, but the goal is actionable intelligence, not sales dashboards.
Compared with a cybersecurity analyst, you might still analyze cyber threats, but you also handle human intelligence, financial flows, language translation, and field surveillance. You need broader judgment across technical and nontechnical sources.
Clear, concise writing that turns messy analysis into an actionable product. Many candidates are strong with tools — Hadoop, Spark, ArcGIS — but struggle to write a brief that leaders can act on.
Being able to validate intelligence with multiple sources and explain uncertainties in plain language matters. That includes saying which data came from ESRI maps, Kafka streams, or interviews, and what gaps remain.