Posted on: 06/10/2026
Role Summary :
We are seeking a Lead CTI Analyst to work as a Cyber Threat Intelligence (CTI) domain SME supporting AI-driven automation of cybersecurity use cases. The role will focus on CTI data collection, analysis, curation, normalization, enrichment, and quality validation to build high-quality datasets and knowledge sources for AI automation, LLM/RAG solutions, and cybersecurity analytics. The role is for a Lead Engineer who will provide technical leadership, mentor and manage team members, guide solution design and implementation, and ensure timely delivery of project outcomes.
Responsibilities :
- Act as a Cyber Threat Intelligence (CTI) domain SME for AI automation of cybersecurity use cases.
- Collect, analyze, validate, curate, and normalize CTI data from open-source, commercial, and internal sources to support AI automation.
- Apply CTI analysis frameworks such as the CTI lifecycle, Diamond Model, Cyber Kill Chain, and Analysis of Competing Hypotheses (ACH) to structure and assess intelligence.
- Perform MITRE ATT&CK mapping and maintain contextual relationships between threat actors, campaigns, malware, vulnerabilities, techniques, and indicators.
- Handle IoCs using industry best practices, including defanging, hash-type identification, contextual validation, deduplication, and false-positive avoidance.
- Work with TLP 2.0 and PAP markings and ensure appropriate handling and dissemination of CTI data.
- Create, validate, and enrich STIX 2.1 objects and support TAXII 2.1-based CTI exchange and ingestion workflows.
- Operate and manage CTI platforms such as MISP and OpenCTI, including data models, APIs, feed management, PyMISP, and GraphQL.
- Use CTI enrichment services such as VirusTotal, URLScan, AbuseIPDB, Shodan, Censys, OTX, Whois, and PassiveDNS to enrich and validate indicators and entities.
- Apply OSINT tradecraft and security fundamentals while maintaining appropriate operational security (OPSEC).
- Support the creation of high-quality, traceable, and reusable CTI datasets for LLM fine-tuning, RAG, automated analysis, and other AI-driven cybersecurity applications.
- Manage the team of junior analysts and provide technical guidance.
- Collaborate with cybersecurity, data, AI/ML, and engineering teams to translate CTI analyst knowledge into structured data, rules, prompts, evaluation datasets, and automation workflows.
- Stay current with emerging threats, vulnerabilities, threat actor activity, malware, and CTI analysis methodologies.
Communication and Documentation :
- Excellent written and oral communication, presentation, listening and interpersonal skills.
- Collaborating effectively with internal and external team.
- Excellent reporting, time management, analytical & communication skills.
Preferred Skills :
- Experience with commercial Cyber Threat Intelligence (CTI) platforms and vendors.
- Familiarity with detection rule standards such as YARA, Sigma, Snort, and Suricata.
- Exposure to AI/ML, LLM, RAG, data curation, or cybersecurity automation use cases.
- Surface-level malware analysis and DFIR fundamentals.
- Knowledge of cloud security concepts.
- Certifications such as GCTI, GCIH, GCFA, CTIA, eCTHPv2, OSCP, or equivalent would be good to have.
Qualifications and Technical Skills :
- 4 - 6 years of previous experience in Cyber Threat Intelligence, threat research, security analysis, or a related cybersecurity domain.
- Strong knowledge of CTI analysis frameworks including CTI lifecycle, Diamond Model, Cyber Kill Chain, and ACH.
- Hands-on experience with MITRE ATT&CK mapping, TLP 2.0/PAP marking, STIX 2.1/TAXII 2.1, and IoC handling best practices.
- Experience with OSINT tradecraft, security fundamentals, and OPSEC principles.
- Hands-on experience with MISP and/or OpenCTI, including data models, APIs, PyMISP, GraphQL, and feed management.
- Experience using CTI enrichment tools/services such as VirusTotal, URLScan, AbuseIPDB, Shodan, Censys, OTX, Whois, and PassiveDNS.
- Good understanding of detection content standards including YARA, Sigma, Snort, and Suricata.
- Python knowledge, preferably with libraries such as stix2, PyMISP, taxii2-client, and vt-py.
- Working knowledge of SQL and one or more security query/search languages such as KQL, SPL, or Elastic DSL.
- Strong analytical, troubleshooting, problem-solving, and data-curation skills.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1676806