Назад
Company hidden
3 дня назад

Threat Analyst (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
Singapore/Canada/Egypt
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Threat Analyst (Cybersecurity): Analyzing cyber threat intelligence and hunting for adversary activity across endpoints, networks, cloud workloads, and airport infrastructure with an accent on OSINT, SIEM/XDR telemetry, threat actor profiling, and MITRE ATT&CK. Focus on developing hypothesis-driven hunts, integrating IoCs into detection platforms, supporting incident response, and improving detection engineering across 24/7/365 operations.

Location: Singapore, Singapore; hybrid arrangement with work from home up to 2 days per week, subject to team needs. The role contributes to 24/7/365 operations coverage.

Company

hirify.global provides technology and communications solutions for airports, airlines, borders, and transportation and government organizations worldwide.

What you will do

  • Collect and analyze OSINT, commercial threat feeds, Aviation-ISAC data, dark web sources, law enforcement information, government intelligence, and internal telemetry.
  • Profile nation-state APTs, cybercriminal groups, and hacktivists targeting aviation, critical infrastructure, hirify.global, and its customers.
  • Produce threat newsletters, threat landscape reports, actor profiles, flash alerts, and vulnerability and exploit intelligence briefs.
  • Develop and execute hypothesis-driven threat hunts across endpoints, networks, cloud workloads, and airport infrastructure using SIEM and XDR telemetry.
  • Integrate IoCs and intelligence into Elastic, XSOAR, CrowdStrike Falcon, Palo Alto Cortex, Microsoft Defender, and related detection platforms.
  • Support incident response, adversary emulation, detection engineering, hunt reporting, and continuous improvement of CTI and threat hunting programs.

Requirements

  • Bachelor’s degree in cybersecurity, computer science, information security, intelligence studies, or a related field.
  • At least 2 years of experience in cyber threat intelligence, threat hunting, SOC L2+, or incident response.
  • At least one relevant certification, such as GCTI, GCIH, GCFA, CEH, CySA+, GIAC, OSCP, Security+, CREST, CTIA, or CCTHP.
  • Hands-on experience with Elastic SIEM and CrowdStrike Falcon, Cortex, or Microsoft Defender, plus familiarity with threat intelligence platforms and SOAR/XSOAR.
  • Practical knowledge of MITRE ATT&CK, the Diamond Model, or the Cyber Kill Chain; proficiency in OSINT, log analysis, forensic techniques, networking, Windows/Linux internals, and malware analysis concepts.
  • Scripting experience with Python, PowerShell, or KQL/EQL, along with strong analytical, communication, reporting, and collaboration skills.

Nice to have

  • Fluency in Mandarin for APAC-focused APT tracking and intelligence in the Singapore role.
  • Experience in the aviation sector or producing operational and tactical threat intelligence for technical audiences.
  • Familiarity with Breach and Attack Simulation tools such as AttackIQ.

Culture & Benefits

  • Globally distributed team spanning primarily Montreal, Singapore, and Cairo.
  • Up to 30 days per year of work from any location in the world as part of the Flex Location policy.
  • Employee assistance program for employees and dependents, available 24/7/365.
  • Access to LinkedIn Learning, SANS training, and industry certifications.
  • Competitive benefits aligned with the local market.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →