Careers

Careers in OSINT

OSINT is not a job title you collect. It is a way of working: start from what is public, prove what connects, and write it so someone else can reopen the trail. These careers use that craft every week — some as the whole job, some as the hour that decides the case.

When OSINT is the job

The title is the craft. You are paid to collect, corroborate, and hand off a trail someone else can follow.

OSINT analyst

Also called Open-source intelligence analyst, collection analyst.

The job

You turn a thin identifier into a picture someone can act on. An email, a handle, a domain, a photo. You run sources, keep what holds, drop what does not, and write the trail so the next person does not start from zero.

Where OSINT sits

This is the job. Breach, WHOIS, people search, host intel, and image lookups are the daily tools — not a side skill you dust off for a special request.

A day looks like

  • Take a queue of identifiers and decide which sources are worth the query
  • Pivot from a hit — another email, a domain, a username — without losing the first thread
  • Keep notes and source links in one place so a reopen is not a scavenger hunt
  • Hand a Case or a short brief to whoever owns the next decision

You will be asked

  • “Where did this come from, and can I reopen it?”
  • “What did you not search, and why?”
  • “Is this the same person, or just the same name?”

OSINT analyst use case

Threat intelligence analyst

Also called CTI analyst, cyber threat intel.

The job

You watch how adversaries show up in the open: infrastructure, aliases, leak chatter, reused tooling. The output is not a vibe. It is attribution you can defend, or a lead you can kill.

Where OSINT sits

OSINT is how you see what they left public before you spend a classified or paid feed. Domains, IPs, wallets, and handles are the first pass — then you decide what is worth deeper collection.

A day looks like

  • Cluster domains and hosts that look like the same campaign
  • Check whether a handle or email already sits in a known leak set
  • Map infrastructure so a SOC ticket has context, not just an IOC list
  • Write what is confirmed versus what is still a hypothesis

You will be asked

  • “Is this the same actor, or just the same TTP?”
  • “What is public versus what came from a closed feed?”
  • “Can the SOC action this today?”

Threat intelligence use case

Investigative journalist

Also called Reporter, documentary researcher.

The job

You publish what you can stand behind. Documents, companies, people, and money trails — checked twice, written so an editor and a lawyer can follow the same path you did.

Where OSINT sits

Open sources are how you find the second source. Company officers, domain history, leaked credentials used as leads (never as spectacle), and photo context when a claim hangs on a place or a face.

A day looks like

  • Confirm a person or company is the same entity across records
  • Pull WHOIS and tech fingerprints when a site is part of the story
  • Treat breach hits as leads to verify, not copy to publish
  • Keep a Case so fact-check and legal can reopen every lookup

You will be asked

  • “Who else can confirm this?”
  • “Did we pay for a source we cannot name on the record?”
  • “What would a hostile lawyer attack first?”

Investigative journalism use case

Private investigator

Also called PI, skip tracer, due-diligence investigator.

The job

Someone hired you to find a person, check a story, or prove a connection. You work to a brief and a clock. The file has to survive a client who will ask how you know.

Where OSINT sits

OSINT is the first hour: locate, corroborate, then decide if you need fieldwork. Email, phone, username, and photo searches cut the list before you spend a day on the wrong address.

A day looks like

  • Start from the identifier the client actually has — often a phone or an old email
  • Cross-check people-search and leak sources before you treat a hit as an address
  • Keep each subject in a Case so you can show what you ran and what it cost
  • Write the finding in language a lawyer or insurer can use

You will be asked

  • “How sure are you this is the same person?”
  • “What did this search cost, and was it worth another run?”
  • “Can I show this to counsel?”

Private investigations use case

Fraud investigator

Also called Financial crime investigator, AML investigator.

The job

You decide whether a claim, an account, or a payment is real. The work is pattern, not panic: same device, same email, same wallet, reused story.

Where OSINT sits

OSINT is how you connect the account in your system to the person (or network) outside it. Breach hits, people search, and on-chain lookups sit next to internal case notes.

A day looks like

  • Take an email or phone from a claim and see where else it lives
  • Check wallets and counterparties when the money left the platform
  • Flag mule patterns: same recovery email, same handle, new name
  • Keep the trail in a Case for SAR writers and legal

You will be asked

  • “Is this one person or a ring?”
  • “What is on-chain versus what is just a reused email?”
  • “Can we explain this to a regulator?”

Fraud investigations use case

When OSINT is the hour that matters

The title is something else. Open sources still decide whether you have a lead, a name, or a dead end.

SOC analyst

Also called Detection analyst, incident responder (tier 1–2).

The job

You triage alerts. Most are noise. A few are a compromised mailbox, a leaked password, or an exposed host. You have minutes, not a research week.

Where OSINT sits

OSINT is the enrichment step: is this email already in a leak set, is this IP a known scanner, does this domain have a history. It does not replace the SIEM. It answers the question the ticket cannot.

A day looks like

  • Look up the user or sender before you escalate a phishing ticket
  • Check host and domain context when an IP shows up in detections
  • Save only the lookups that matter so the next shift can reopen them
  • Leave the rest of the stack — EDR, SIEM, ticketing — where it is

You will be asked

  • “Is this user already exposed?”
  • “Do we page someone, or close it?”
  • “What did we look up, and what did it cost?”

Cybersecurity use case

Law enforcement analyst

Also called Crime analyst, intelligence officer (unclassified work).

The job

You support officers and investigators with what can be said in a brief: associations, online presence, infrastructure. You stay inside policy. You write so a supervisor can follow it.

Where OSINT sits

OSINT is the unclassified first pass — usernames, phones, domains, photos — before you spend a legal process or a closed database query. It is collection, not a shortcut around process.

A day looks like

  • Work from identifiers already in the file, not from curiosity
  • Record every lookup so the trail is auditable
  • Separate what is public from what still needs a warrant or a partner agency
  • Hand off a Case, not a pile of screenshots

You will be asked

  • “Is this in policy?”
  • “Can we say this in court or in a briefing?”
  • “What is still unconfirmed?”

Law enforcement use case

Corporate intelligence analyst

Also called Due diligence analyst, third-party risk, KYC analyst.

The job

You check people and companies before money, a hire, or a partnership moves. The product is a memo: who they are, what is public, what still needs a human call.

Where OSINT sits

OSINT is the open layer of due diligence: officers, domains, leaked credentials as risk signal, tech stack on a site that claims to be something else. It sits next to registries and paid credit files — it does not replace them.

A day looks like

  • Confirm the company and the people match the story in the pitch deck
  • Check domains and mail infrastructure when a vendor looks thin
  • Note exposure that legal or compliance should see before close
  • Keep each subject in a Case for the next review cycle

You will be asked

  • “Is this the same company we think it is?”
  • “What is public that they did not put in the pack?”
  • “What still needs a licensed check?”

Corporate due diligence use case

Geolocation analyst

Also called GEOINT / image analyst (open sources).

The job

You answer where a photo or video was taken — or whether it could have been. Terrain, shadows, signage, metadata when it exists. Wrong place, wrong story.

Where OSINT sits

OSINT here is visual and spatial: reverse image, photo geolocation, and the identifiers that fall out of a frame (a username on a shirt, a domain on a van). People-search and leak sources only matter after you have a place or a name.

A day looks like

  • Run a still through geolocation and reverse-image sources before you theorize
  • Pull identifiers from the frame and search them as a second step
  • Write confidence, not certainty, unless the ground truth is in hand
  • Keep the image and the lookups together so an editor or officer can reopen both

You will be asked

  • “How sure are you of the place?”
  • “Could this be a reused or AI-generated frame?”
  • “What would change your mind?”

OSINT engineer

Also called Detection engineer, intel engineer, automation analyst.

The job

You turn repeatable lookups into something the team does not have to click. Pipelines, keys, schemas, and a queue that does not invent charges.

Where OSINT sits

OSINT is the data plane. You care that every provider answers the same way, that a failed lookup does not silently eat the wallet, and that an analyst can still run the same query by hand when the pipeline is wrong.

A day looks like

  • Wire one API instead of one integration per vendor
  • Price a job before it runs so finance does not discover it later
  • Log search IDs so a bad result can be refunded or replayed
  • Leave the investigation writing to the analyst — you own the pipe

You will be asked

  • “What does this cost at volume?”
  • “What happens when a provider is down?”
  • “Can an analyst reproduce this without the script?”

Cybersecurity use case

FAQ

Questions, answered

Is OSINT analyst a real job title, or just a skill?

Both. Some teams hire OSINT analysts as a dedicated role. Many more ask a SOC analyst, journalist, PI, or fraud investigator to do the same work under another title. The craft is the same: public sources, a written trail, a decision at the end.

Do I need a clearance or a license?

Depends on the employer. Law enforcement and some corporate intel roles have policy and licensing rules. Journalism and most private investigation work do not require a clearance. OSINT itself is the use of public information — the job around it is what is regulated.

Is this a list of open roles at OSINTverse?

No. This page explains the careers. We are a small team. Write hi@osintverse.com if you have a question — do not treat this as a jobs board.

Where should I start if I want this work?

Learn to run one identifier across more than one source, write what you found, and say what you did not search. The learning path and the communities list are the honest next step.