обновлено 1 месяц назад
Threat Analyst (Cyber Threat Intelligence | Threat Hunting | GCTI)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Threat Analyst (Cyber Threat Intelligence | Threat Hunting | GCTI) (Cyber Threat Intelligence and Threat Hunting): Identifying, analyzing, and operationalizing cyber threats targeting SITA, its customers, and the aviation sector with an accent on threat actor profiling, dark web monitoring, and intelligence integration. Focus on developing hypothesis-driven hunts, analyzing SIEM and XDR telemetry, supporting incident response, and improving automated detection capabilities.
Location: Cairo, Egypt or Singapore; hybrid work with up to 2 days per week from home
Company
provides technology and communications solutions for the air transport industry, serving airports, airlines, transportation organizations, and government clients worldwide.
What you will do
- Collect and analyze OSINT, commercial threat feeds, dark web data, internal telemetry, and industry intelligence.
- Profile nation-state APTs, cybercriminal groups, and hacktivists targeting aviation, critical infrastructure, and .
- Produce threat newsletters, threat landscape reports, actor profiles, flash alerts, and vulnerability intelligence briefs.
- Develop and execute MITRE ATT&CK-based threat hunts across endpoints, networks, cloud workloads, and airport infrastructure.
- Analyze SIEM, EDR, XDR, network, and system telemetry to identify anomalies, lateral movement, privilege escalation, and persistence.
- Support incident response, adversary emulation, detection engineering, and continuous improvement of CTI and threat hunting programs.
Requirements
- Bachelor’s degree in cybersecurity, computer science, information security, intelligence studies, or a related field.
- At least 2 years of experience in cyber threat intelligence, threat hunting, SOC L2+, or incident response.
- Experience with Elastic SIEM and CrowdStrike Falcon, Cortex, Defender, or comparable EDR/XDR platforms.
- Experience with Recorded Future, MISP, OpenCTI, and familiarity with SOAR/XSOAR workflows.
- Proficiency in OSINT, log analysis, endpoint/network/memory forensics, Windows/Linux internals, and common attack vectors.
- Scripting experience with Python, PowerShell, or KQL/EQL, plus knowledge of MITRE ATT&CK, Diamond Model, Cyber Kill Chain, and STIX/TAXII.
Nice to have
- Arabic fluency for the Cairo role or Mandarin fluency for the Singapore role.
- Experience in aviation, operational or tactical threat intelligence, or AttackIQ and other BAS tools.
Culture & Benefits
- Participation in a globally distributed CSIRT threat team supporting 24/7/365 operations coverage.
- Up to 30 days per year to work from any location in the world as a flex-location benefit.
- Employee assistance program for employees and dependents available 24/7.
- Professional development through LinkedIn Learning, SANS training, and industry certifications.
- Competitive benefits aligned with the local market.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
CrowdStrike
8 дней назад
Channel Solution Architect (Cybersecurity)
6 дней назад
Solution Engineer (Cybersecurity)
6 дней назад
Cybersecurity Analyst (IAM)
10 дней назад
Technical Specialist
Razer
7 дней назад
Senior Cyber Security Manager (AI Security)
5 дней назад
Senior Threat Intelligence Analyst (Blockchain Intelligence)
140 000 - 168 000$