Threat Intelligence Researcher (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Threat Intelligence Researcher (Cybersecurity): Tracking threat actors and their infrastructure to produce actionable intelligence reports with an accent on TTP analysis and detection engineering. Focus on identifying APTs, developing high-fidelity detection signatures, and leveraging AI/LLM automation to scale analysis.
Location: Remote (US)
Salary: $100,000 - $120,000
Company
Global leader in cybersecurity ratings providing patented technology for risk management and self-monitoring.
What you will do
- Identify, track, and analyze APTs, their TTPs, and live infrastructure to gain insights into attack vectors and victimology.
- Produce timely and actionable intelligence reports for customers, press, and partners.
- Develop and maintain high-fidelity detection signatures using YARA, Snort, and Sigma.
- Query massive datasets using SQL, Python, or Splunk to identify anomalies and map adversary infrastructure.
- Design and leverage AI and LLM automations to support analysis workload.
Requirements
- Bachelor's or Master's in Computer Science, Cybersecurity, or a highly technical equivalent.
- 3–5 years of experience in a hands-on threat intelligence research role.
- Proficiency with large dataset querying and dashboard design using Splunk, SQL, or similar platforms.
- Must be based in the US (no immigration sponsorship provided).
- Strong written and spoken English proficiency.
Nice to have
- Experience with open source/commercial attack surface, malware analysis, and network intelligence tools.
- Native-level reading and writing proficiency in Russian, Mandarin, Korean, or Farsi.
Culture & Benefits
- Competitive salary and stock options.
- Health benefits and unlimited PTO.
- Parental leave and tuition reimbursements.
- Recognized by Inc Magazine and Fast Company as a top workplace and innovator.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →