About this role
Job title: Sr. Analyst, Cyber Threat Intelligence
About the Role As a member of the Cybersecurity Team, you will be responsible for supporting the cyber threat intelligence program mission, architecture and operation. The output of your research will be timely, actionable analysis and recommendations while remaining sensitive to changing business requirements. You will perform technical analysis of malware, phishing infrastructure, and attacker tooling to extract indicators, TTPs, and other attribution signals. You will stay deeply informed of commodity cybercrime threats, retail and hospitality-specific fraud types, emerging vulnerabilities, and threat actor tradecraft tooling.
What You'll Do
- Perform regular threat intelligence research into cybercrime and nation-state threat actor tradecraft and produce threat intelligence products and profiles based on defined intelligence requirements for selected stakeholders, with some products automated with human-review.
- Support planning and maintenance of tooling and automated pipelines to collect, enrich, correlate, and operationalize all-source intelligence into our detection and reporting stack.
- Assist in triage and review of security events by analyzing malicious artifacts from forensic workflows using static and dynamic analysis techniques.
- Apply knowledge of in-the-wild threats and TTPs to provide intelligence context for Security Operations and Detection Engineering during triage and incident response operations.
- Collaborate with Detection Engineering and Incident Response to translate intelligence into applicable detection rules, hunting hypotheses, red team and detection validation scenarios; inform incident context.
- Build and maintain external intelligence-sharing relationships with peer organizations, RH-ISAC, and other select partners.
- Attend conferences, vendor Technical or Customer Advisory Boards and other industry events virtually or in-person.
- Leverage 3+ years of hands-on experience in cyber threat intelligence, threat hunting, intrusion analysis or incident response to inform work and drive action.
What We're Looking For
- 3+ years of hands-on experience in cyber threat intelligence, threat hunting, intrusion analysis or incident response at an organization facing sophisticated cybercrime adversaries.
- Ability to bring new ideas, challenge the status quo, and show passion for cybersecurity; enjoy reading industry news or podcasts.
- Strong engineering background; built computers, managed networks, and potentially coded tools.
- Strong foundation in network security, vulnerability exploitation concepts, and technical threat analysis.
- Experience with Threat Intelligence Platforms (TIPs) and technologies for intelligence integration within a modern Security Operations Center.
- Experience leveraging MITRE ATT&CK, MITRE D3FEND, CTI-CMM, Cyber Kill Chain, and other security frameworks.
- Demonstrated organized, focused research habits and the ability to leverage internet tools, including AI assistance.
- Comfortable performing malware analysis, infrastructure analysis, OSINT, and log analysis to develop and validate findings.
- Ability to communicate complex ideas to non-technical audiences; formal technical writing skills; experience delivering senior leadership-ready deliverables.
- Comfortable speaking in front of large audiences and leading calls.
- Ability to multi-task and manage time; existing network in threat intelligence community and a track record of productive bidirectional sharing.
Nice to Have
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related field preferred but not required.
- Certifications (SANS, COMPTIA, ISC2, etc) preferred, not required.
Compensation & Benefits
- Competitive compensation and benefits.
- Vacation, team member appreciation days, workplace flexibility and much more.