Назад
Company hidden
5 дней назад

Threat Analyst (Cyber Threat Intelligence | Threat Hunting | GCTI)

Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
Singapore/Egypt
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Threat Analyst (Cyber Threat Intelligence | Threat Hunting | GCTI): Identifying, analyzing, and hunting cyber threats targeting aviation infrastructure, transportation clients, and enterprise environments with an accent on threat intelligence, adversary tracking, and SIEM/XDR-driven detection. Focus on developing hypothesis-driven hunts, analyzing endpoint and network telemetry, integrating IoCs, and supporting incident response across 24/7/365 operations.

Location: Hybrid role based in Cairo, Egypt, or Singapore; work from home is available up to 2 days per week, subject to team needs. The role contributes to rotating 24/7/365 operations coverage.

Company

hirify.global provides technology, communications, and cybersecurity solutions for the global air transport industry, serving airports, airlines, and transportation and government clients.

What you will do

  • Collect and analyze OSINT, commercial threat feeds, dark web intelligence, government sources, Aviation-ISAC data, and internal telemetry.
  • Profile nation-state APTs, cybercriminal groups, and hacktivists targeting aviation, critical infrastructure, and hirify.global operations.
  • Produce threat newsletters, landscape reports, actor profiles, flash alerts, and vulnerability and exploit intelligence briefs.
  • Develop and execute MITRE ATT&CK-based threat hunts across endpoints, networks, cloud workloads, and airport infrastructure.
  • Analyze SIEM, EDR, XDR, network, and system telemetry to identify anomalies, lateral movement, privilege escalation, and persistence.
  • Support incident response, detection engineering, red and purple team exercises, and continuous improvement of CTI and threat-hunting programs.

Requirements

  • Bachelor’s degree in cybersecurity, computer science, information security, intelligence studies, or a related field.
  • At least 2 years of experience in cyber threat intelligence, threat hunting, SOC L2+, or incident response.
  • At least one relevant certification, such as GCTI, GCIH, GCFA, CEH, CySA+, GIAC, OSCP, Security+, CREST, CTIA, or CCTHP.
  • Hands-on experience with Elastic SIEM and CrowdStrike Falcon, Cortex, Defender, or comparable EDR/XDR platforms.
  • Experience with Recorded Future, MISP, OpenCTI, SOAR/XSOAR, MITRE ATT&CK, Diamond Model, or Cyber Kill Chain.
  • Proficiency in OSINT, forensic and log analysis, Windows/Linux internals, networking, malware analysis concepts, and Python, PowerShell, KQL, or EQL.

Nice to have

  • Arabic fluency for the Cairo role or Mandarin fluency for the Singapore role.
  • Experience in the aviation sector or producing operational and tactical threat intelligence.
  • Familiarity with AttackIQ or other breach and attack simulation tools.

Culture & Benefits

  • Globally distributed cybersecurity team spanning Montreal, Singapore, and Cairo.
  • Up to 30 days per year to work from any location in the world as a temporary flexibility benefit.
  • Employee assistance program for employees and dependents, available 24/7.
  • LinkedIn Learning, SANS training, and support for industry certifications.
  • Competitive benefits aligned with the local market.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →