6 часов назад
Threat Intelligence Analyst, Associate - Security Operations (Cybersecurity)
135 000 - 170 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Threat Intelligence Analyst, Associate - Security Operations (Cybersecurity): Monitoring and analyzing cyber threats, producing intelligence reports, enriching indicators of compromise, and managing external attack surface exposure with an accent on AI-assisted automation, threat actor analysis, and detection engineering. Focus on mapping adversary behavior to MITRE ATT&CK, developing Splunk SPL, Sigma, and YARA detections, prioritizing vulnerabilities, and supporting incident response.
Location: New York, United States
Expected annual base salary: $135,000–$170,000
Company
is a global alternative asset manager, and Technology & Innovations develops systems that manage risk, improve efficiency, and increase transparency across the firm and its investment ecosystem.
What you will do
- Monitor and analyze cyber threats targeting the financial sector, alternative asset management, and related industries using open-source, commercial, and internal intelligence sources.
- Produce threat reports, advisories, campaign profiles, actor dossiers, executive briefings, and visual diagrams for technical and non-technical audiences.
- Map adversary behavior to MITRE ATT&CK and maintain profiles covering threat actor tactics, techniques, procedures, intent, and relevance.
- Extract, validate, enrich, and operationalize indicators of compromise for detection engineering and incident response.
- Use AI and automation to scale intelligence collection and enrichment, and help develop Splunk SPL, Sigma, and YARA detections.
- Track critical vulnerabilities, manage external attack surface monitoring, coordinate remediation, and participate in incident response and the occasional SOC on-call rotation.
Requirements
- 2+ years of experience in cyber threat intelligence, security operations, incident response, or a related cybersecurity discipline.
- Knowledge of cyber threat actors, campaigns, TTPs, MITRE ATT&CK, the Diamond Model, or the Intelligence Cycle.
- Experience with threat intelligence platforms, SIEM tools such as Splunk, OSINT research, attack surface management, or vulnerability management tooling.
- Python or other scripting experience for automating collection, enrichment, and analysis workflows.
- Hands-on experience applying AI tooling, including LLMs or coding assistants, to real work and automation projects.
- B.S. in Computer Science, Cybersecurity, Intelligence Studies, International Relations, or a related field, plus strong analytical and technical writing skills.
Nice to have
- Financial-sector experience or experience working with a global threat landscape.
- Attack Surface Management platforms such as Mandiant ASM, CrowdStrike Falcon Surface, or Microsoft Defender EASM.
- Vulnerability prioritization using CVSS, EPSS, and CISA KEV, plus remediation tracking experience.
- Detection content development with Sigma, YARA, Splunk SPL, or KQL.
- Industry certifications, ISAC or CTI community participation, and exposure to AWS, Azure, or cloud-specific threats.
Culture & Benefits
- Entrepreneurial, collaborative, and iterative technology environment.
- Active mentoring and opportunities to take projects from idea to implementation.
- Medical, dental, vision, and FSA benefits.
- Paid time off, life insurance, 401(k), and discretionary bonuses.
- Potential eligibility for equity and other incentive compensation.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →