3 дня назад
Threat Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Threat Analyst (Cybersecurity): Analyzing cyber threat intelligence and hunting for adversary activity across endpoints, networks, cloud workloads, and airport infrastructure with an accent on OSINT, SIEM/XDR telemetry, threat actor profiling, and MITRE ATT&CK. Focus on developing hypothesis-driven hunts, integrating IoCs into detection platforms, supporting incident response, and improving detection engineering across 24/7/365 operations.
Location: Singapore, Singapore; hybrid arrangement with work from home up to 2 days per week, subject to team needs. The role contributes to 24/7/365 operations coverage.
Company
provides technology and communications solutions for airports, airlines, borders, and transportation and government organizations worldwide.
What you will do
- Collect and analyze OSINT, commercial threat feeds, Aviation-ISAC data, dark web sources, law enforcement information, government intelligence, and internal telemetry.
- Profile nation-state APTs, cybercriminal groups, and hacktivists targeting aviation, critical infrastructure, , and its customers.
- Produce threat newsletters, threat landscape reports, actor profiles, flash alerts, and vulnerability and exploit intelligence briefs.
- Develop and execute hypothesis-driven threat hunts across endpoints, networks, cloud workloads, and airport infrastructure using SIEM and XDR telemetry.
- Integrate IoCs and intelligence into Elastic, XSOAR, CrowdStrike Falcon, Palo Alto Cortex, Microsoft Defender, and related detection platforms.
- Support incident response, adversary emulation, detection engineering, hunt reporting, and continuous improvement of CTI and threat hunting programs.
Requirements
- Bachelor’s degree in cybersecurity, computer science, information security, intelligence studies, or a related field.
- At least 2 years of experience in cyber threat intelligence, threat hunting, SOC L2+, or incident response.
- At least one relevant certification, such as GCTI, GCIH, GCFA, CEH, CySA+, GIAC, OSCP, Security+, CREST, CTIA, or CCTHP.
- Hands-on experience with Elastic SIEM and CrowdStrike Falcon, Cortex, or Microsoft Defender, plus familiarity with threat intelligence platforms and SOAR/XSOAR.
- Practical knowledge of MITRE ATT&CK, the Diamond Model, or the Cyber Kill Chain; proficiency in OSINT, log analysis, forensic techniques, networking, Windows/Linux internals, and malware analysis concepts.
- Scripting experience with Python, PowerShell, or KQL/EQL, along with strong analytical, communication, reporting, and collaboration skills.
Nice to have
- Fluency in Mandarin for APAC-focused APT tracking and intelligence in the Singapore role.
- Experience in the aviation sector or producing operational and tactical threat intelligence for technical audiences.
- Familiarity with Breach and Attack Simulation tools such as AttackIQ.
Culture & Benefits
- Globally distributed team spanning primarily Montreal, Singapore, and Cairo.
- Up to 30 days per year of work from any location in the world as part of the Flex Location policy.
- Employee assistance program for employees and dependents, available 24/7/365.
- Access to LinkedIn Learning, SANS training, and industry certifications.
- Competitive benefits aligned with the local market.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
6 дней назад
Threat Analyst 1 (Cybersecurity)
56 000 - 93 000CAD
5 дней назад
Threat Specialist (Cybersecurity)
5 дней назад
HK Senior Detection and Response Engineer (Cybersecurity)
7 дней назад
Staff Information Security Engineer (Cybersecurity)
130 000 - 170 000$
6 дней назад
Senior SOC Analyst (Cybersecurity)
108 000 - 135 000CAD
3 дня назад
Security Operations Specialist (Cybersecurity)
80 000 - 90 000CAD