Назад
Company hidden
обновлено 1 месяц назад

Threat Analyst (Cyber Threat Intelligence | Threat Hunting | GCTI)

Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
Singapore/Egypt
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Threat Analyst (Cyber Threat Intelligence | Threat Hunting | GCTI) (Cyber Threat Intelligence and Threat Hunting): Identifying, analyzing, and operationalizing cyber threats targeting SITA, its customers, and the aviation sector with an accent on threat actor profiling, dark web monitoring, and intelligence integration. Focus on developing hypothesis-driven hunts, analyzing SIEM and XDR telemetry, supporting incident response, and improving automated detection capabilities.

Location: Cairo, Egypt or Singapore; hybrid work with up to 2 days per week from home

Company

hirify.global provides technology and communications solutions for the air transport industry, serving airports, airlines, transportation organizations, and government clients worldwide.

What you will do

  • Collect and analyze OSINT, commercial threat feeds, dark web data, internal telemetry, and industry intelligence.
  • Profile nation-state APTs, cybercriminal groups, and hacktivists targeting aviation, critical infrastructure, and hirify.global.
  • Produce threat newsletters, threat landscape reports, actor profiles, flash alerts, and vulnerability intelligence briefs.
  • Develop and execute MITRE ATT&CK-based threat hunts across endpoints, networks, cloud workloads, and airport infrastructure.
  • Analyze SIEM, EDR, XDR, network, and system telemetry to identify anomalies, lateral movement, privilege escalation, and persistence.
  • Support incident response, adversary emulation, detection engineering, and continuous improvement of CTI and threat hunting programs.

Requirements

  • Bachelor’s degree in cybersecurity, computer science, information security, intelligence studies, or a related field.
  • At least 2 years of experience in cyber threat intelligence, threat hunting, SOC L2+, or incident response.
  • Experience with Elastic SIEM and CrowdStrike Falcon, Cortex, Defender, or comparable EDR/XDR platforms.
  • Experience with Recorded Future, MISP, OpenCTI, and familiarity with SOAR/XSOAR workflows.
  • Proficiency in OSINT, log analysis, endpoint/network/memory forensics, Windows/Linux internals, and common attack vectors.
  • Scripting experience with Python, PowerShell, or KQL/EQL, plus knowledge of MITRE ATT&CK, Diamond Model, Cyber Kill Chain, and STIX/TAXII.

Nice to have

  • Arabic fluency for the Cairo role or Mandarin fluency for the Singapore role.
  • Experience in aviation, operational or tactical threat intelligence, or AttackIQ and other BAS tools.

Culture & Benefits

  • Participation in a globally distributed CSIRT threat team supporting 24/7/365 operations coverage.
  • Up to 30 days per year to work from any location in the world as a flex-location benefit.
  • Employee assistance program for employees and dependents available 24/7.
  • Professional development through LinkedIn Learning, SANS training, and industry certifications.
  • Competitive benefits aligned with the local market.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →