HamburgerMenu
hirist

Job Description

We are looking for an experienced Cyber Threat Intelligence (CTI) Engineer with 6+ years of relevant experience in cyber threat intelligence, threat research, adversary analysis, and intelligence production.

The ideal candidate will be responsible for monitoring and analyzing threat actors, campaigns, attack techniques, tactics, procedures (TTPs), malware trends, vulnerabilities, and emerging cyber threats. The role will focus on converting raw threat data into actionable intelligence that can support security teams, risk stakeholders, and organizational decision-making.

This is a dedicated Threat Intelligence role and is not intended for candidates whose primary experience is in SOC operations, security monitoring, incident response, or operational security administration.

Key Responsibilities:

- Monitor and analyze evolving cyber threat landscapes, threat actors, adversary groups, campaigns, and emerging attack patterns.

- Conduct detailed research on Tactics, Techniques and Procedures (TTPs) used by threat actors.

- Track threat actor motivations, targeting patterns, infrastructure, tools, malware families, and attack methodologies.

- Perform analysis of emerging threats, vulnerabilities, exploits, ransomware campaigns, phishing campaigns, and other relevant cyber risks.

- Correlate information from multiple intelligence sources to identify meaningful threats and trends.

- Develop and maintain profiles of relevant threat actors and adversary groups.

- Collect, validate, analyze, and contextualize threat intelligence from internal and external sources.

- Produce high-quality strategic, tactical, and operational threat intelligence reports.

- Translate technical threat intelligence into clear and actionable insights for relevant stakeholders.

- Prepare intelligence briefs, threat assessments, executive summaries, and periodic threat reports.

- Identify emerging trends and provide assessments of their potential impact on the organization.

- Perform intelligence-driven analysis to identify gaps, risks, and potential areas of exposure.

- Apply industry-standard threat intelligence methodologies and frameworks.

- Demonstrate strong knowledge of MITRE ATT&CK and map adversary behavior to relevant tactics and techniques.

- Work with frameworks and standards such as Cyber Kill Chain, Diamond Model, STIX/TAXII, and other CTI methodologies.

- Develop and maintain threat intelligence processes, workflows, standards, and analytical frameworks.

- Contribute to improving the organization's threat intelligence lifecycle and analytical capabilities.

- Provide contextualized intelligence to support SOC, Incident Response, Vulnerability Management, Detection Engineering, Threat Hunting, and Cyber Risk teams.

- Enrich security investigations with relevant threat actor, malware, infrastructure, and campaign intelligence.

- Provide intelligence-led recommendations to improve defensive capabilities.

- Collaborate with security and technology stakeholders to ensure intelligence is converted into actionable security outcomes.

- Work with Threat Intelligence Platforms (TIPs), open-source intelligence (OSINT), commercial intelligence feeds, and other intelligence sources.

- Evaluate the relevance, reliability, and confidence level of intelligence sources.

- Develop processes for intelligence collection, enrichment, analysis, dissemination, and feedback.

- Where applicable, work with IOC enrichment, indicators, threat feeds, malware intelligence, domains, IPs, hashes, and attacker infrastructure as inputs to intelligence analysis.

Required Skills & Experience:

- 6+ years of relevant experience in Cyber Threat Intelligence, Threat Research, Threat Analysis, or Security Intelligence.

- Strong understanding of the cyber threat landscape, threat actors, attack campaigns, malware, vulnerabilities, and adversary behavior.

- Strong hands-on knowledge of MITRE ATT&CK and adversary TTP analysis.

- Experience creating CTI reports, threat assessments, intelligence briefs, and analytical outputs.

- Strong analytical and research skills with the ability to correlate information from multiple intelligence sources.

- Experience with OSINT, threat feeds, intelligence platforms, and threat research techniques.

- Good understanding of intelligence lifecycle processes, including collection, processing, analysis, dissemination, and feedback.

- Ability to convert complex technical intelligence into clear operational and business-relevant insights.

- Strong written and verbal communication skills.

- Ability to independently conduct threat research and develop intelligence assessments.

- Experience with STIX/TAXII, Threat Intelligence Platforms (TIPs), MISP, or similar technologies.

- Knowledge of Cyber Kill Chain and Diamond Model.

- Experience analyzing malware, phishing campaigns, ransomware groups, or advanced persistent threat (APT) activity.

- Knowledge of threat actor tracking and infrastructure analysis.

- Familiarity with scripting/programming languages such as Python for intelligence enrichment and automation.

- Exposure to dark web/deep web monitoring and relevant intelligence collection techniques.

- Relevant industry certifications such as CTIA, GCTI, GCIA, GCTI, CISSP, or equivalent certifications.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...