Senior Threat Intelligence Analyst
Company | Recorded Future |
---|---|
Location | Boston, MA, USA, Arlington, VA, USA |
Salary | $Not Provided – $Not Provided |
Type | Full-Time |
Degrees | Bachelor’s, Master’s |
Experience Level | Senior |
Requirements
- 5+ years experience as a threat intelligence analyst or in similar position
- BA/BS or MA/MS degree or equivalent experience in Computer Science, Information Security, or a related field.
- Demonstrable experience conducting technical threat analysis and research
- In-depth understanding of TCP/IP and other networking protocols and network traffic analysis techniques
- Detailed understanding of at least one nation-state APT group – past activities, TTPs, motivations, etc.
- Fluency in common CTI research and data analysis platforms/tools such as ELK Stack (ElasticSearch, Kibana), Maltego, Shodan, DomainTools, or other similar tools/datasets
- Managing client expectations based on pre-established scope of work and delivery timeframe
- Ability to demonstrate strong writing ability, to be assessed via a writing sample
- Practical experience using common threat intelligence analysis models such as MITRE ATT&CK, the Diamond Model, and the Cyber Kill Chain to incorporate into client reports
Responsibilities
- Produce and review finished intelligence reports that address clients’ priority intelligence requirements related to activity from APT groups, particularly originating from the “Big 4” countries of Russia, China, North Korea, and Iran
- Engage with clients across report lifecycle: Initial scoping, finished intelligence delivery, and follow-up review / support
- Develop novel, automated, or simpler processes for research and analysis
- Work on projects across multiple research teams with sometimes tight deadlines
Preferred Qualifications
- Working knowledge of at least one language other than English, with relevance preferred for Russian, Chinese, Korean, and/or Farsi
- Experience working with clients to produce intelligence requirements, or reports / research in line with such requirements
- Demonstrable experience of conducting cyber threat investigations