Senior Cyber Threat Response Advisor (Critical Infrastructure Cyber Resilience)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Location: Remote, must be based in the United States; U.S. citizenship is required. Travel up to 50% within the United States is required for onsite work with critical-infrastructure operators, government partners, and ISACs. Primary time zone overlap: US Eastern / Central.
Salary: $140,000–$168,000 per year, plus potential equity.
Company
provides AI-powered intelligence solutions that help public and private-sector organizations investigate crime, trace illicit activity, and improve security.
What you will do
- Analyze critical-infrastructure sectors, identify high-priority organizations, and drive exposures from initial signals through actionable remediation notifications.
- Conduct cyber threat collection using OSINT, external attack-surface and exposure discovery, and direct threat-actor collection.
- Build AI-assisted and agentic research workflows with human quality control and feed effective methods into investigative tooling.
- Map command-and-control infrastructure, malware families, TTPs, and threat actors across fragmented sources.
- Produce finished intelligence, including exposure notifications, actor and campaign profiles, IOC packages, and infrastructure attributions.
- Advise critical-infrastructure entities, government partners, ISACs, engineers, and internal teams on active threats and time-sensitive remediation.
Requirements
- 5+ years of experience in cyber threat intelligence, incident response, or a closely related analytical field.
- Experience serving as the primary contact for an outside organization during a live incident or remediation effort.
- Ability to independently turn fragmented information into actionable outcomes and deliver under RFI-style deadlines.
- Applied AI fluency, including building or adapting AI-assisted workflows and validating their outputs.
- Hands-on collection experience in open-web, social, forum, attack-surface, exposure, or threat-actor sources.
- Must be based in the United States and be a U.S. citizen; willingness to travel up to 50% within the United States is required.
Nice to have
- Experience with critical-infrastructure sectors such as ICS/OT/SCADA, healthcare, energy, or financial services.
- Experience delivering intelligence to government partners, ISACs, or sector coordinating bodies.
- Operational working proficiency in a language heavily used by cyber actors.
- Public presence through conference talks, published research, or invite-only sharing circles.
Culture & Benefits
- Distributed team with an async-first approach using Slack and Notion, supported by structured syncs.
- High autonomy, high standards, and low bureaucracy.
- Weekly team syncs and daily asynchronous standups for active investigations.
- Surge availability during active disruption windows, without a formal on-call rotation.
- Equity plan eligibility may be available.
Hiring process
- Recruiter introduction, hiring-manager interview, first-round interviews, and final-round interviews.
- Most processes include a case study, AI skills assessment, and Leadership Principles interview.
- References are collected before an offer.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →