Назад
Company hidden
10 дней назад

Senior Analyst – Cyber Threat Intelligence (AI)

105 000 - 115 000CAD
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Analyst – Cyber Threat Intelligence (AI) (Cybersecurity/AI): Monitoring and investigating cyber threats across open, deep, and dark web sources to identify risks affecting Brookfield, its people, clients, brands, and technology environment with an accent on threat actor research, intelligence validation, and AI-enabled threat analysis. Focus on correlating external intelligence with internal telemetry, mapping adversary activity to MITRE ATT&CK, validating data-leak and ransomware claims, and producing actionable reports for security and executive audiences.

Location: hirify.global Place, 181 Bay Street, Toronto, Ontario, Canada

Salary: C$105,000–C$115,000 annually

Company

hirify.global’s Technology Services organization delivers enterprise infrastructure, applications, and end-user technology services across its business groups.

What you will do

  • Monitor dark web, underground forums, marketplaces, messaging platforms, paste sites, and leak sites for threats targeting hirify.global and its business environment.
  • Track threat actors, ransomware groups, initial access brokers, malware operators, fraud networks, and other criminal collectives.
  • Investigate credential exposure, data leaks, ransomware, phishing, business email compromise, fraud, vulnerability exploitation, and third-party compromises.
  • Collect, validate, enrich, and correlate OSINT, commercial intelligence, internal security data, threat feeds, and specialized cybercrime intelligence.
  • Maintain threat actor profiles, watchlists, case records, IOCs, infrastructure details, and intelligence artifacts using MITRE ATT&CK and related frameworks.
  • Produce intelligence reports, tactical alerts, executive briefings, and time-sensitive support for Security Operations, Incident Response, Legal, Privacy, and Fraud teams.

Requirements

  • Three to seven years of experience in cyber threat intelligence, cyber investigations, SOC operations, incident response, digital forensics, or security research.
  • Demonstrated experience researching cybercrime activity, dark web ecosystems, OSINT, and investigative sources.
  • Strong understanding of threat actors, cybercrime business models, attack methodologies, source validation, IOCs, and adversary infrastructure.
  • Experience producing concise intelligence reports and briefings for technical and executive audiences.
  • Working knowledge of MITRE ATT&CK, Cyber Kill Chain, Diamond Model, or similar analytical frameworks.
  • Participation in a scheduled after-hours on-call rotation is required.

Nice to have

  • Experience with ransomware groups, initial access brokers, credential theft, data extortion, malware-as-a-service, or underground marketplaces.
  • Experience with cyber threat intelligence platforms, dark web monitoring tools, SIEM, EDR/XDR, and OSINT tooling.
  • Knowledge of cryptocurrency and blockchain activity related to cybercrime investigations.
  • Familiarity with STIX/TAXII, NIST AI Risk Management Framework, or Generative AI Profile.
  • PowerShell and/or Python experience, relevant security certifications, or education in cybersecurity, computer science, intelligence studies, or a related field.

Culture & Benefits

  • Work in a collaborative, entrepreneurial, and disciplined environment.
  • Receive challenging assignments and exposure to diverse business areas.
  • Provide timely support during significant incidents, critical vulnerabilities, and other urgent security events.
  • Work in a respectful, safe, and accessible environment with equal employment opportunities.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →