Threat Analyst (Cyber Threat Intelligence | Threat Hunting | GCTI)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Threat Analyst (Cyber Threat Intelligence | Threat Hunting | GCTI): Identifying, analyzing, and hunting cyber threats targeting aviation infrastructure, transportation clients, and enterprise environments with an accent on threat intelligence, adversary tracking, and SIEM/XDR-driven detection. Focus on developing hypothesis-driven hunts, analyzing endpoint and network telemetry, integrating IoCs, and supporting incident response across 24/7/365 operations.
Location: Hybrid role based in Cairo, Egypt, or Singapore; work from home is available up to 2 days per week, subject to team needs. The role contributes to rotating 24/7/365 operations coverage.
Company
provides technology, communications, and cybersecurity solutions for the global air transport industry, serving airports, airlines, and transportation and government clients.
What you will do
- Collect and analyze OSINT, commercial threat feeds, dark web intelligence, government sources, Aviation-ISAC data, and internal telemetry.
- Profile nation-state APTs, cybercriminal groups, and hacktivists targeting aviation, critical infrastructure, and operations.
- Produce threat newsletters, landscape reports, actor profiles, flash alerts, and vulnerability and exploit intelligence briefs.
- Develop and execute MITRE ATT&CK-based threat hunts across endpoints, networks, cloud workloads, and airport infrastructure.
- Analyze SIEM, EDR, XDR, network, and system telemetry to identify anomalies, lateral movement, privilege escalation, and persistence.
- Support incident response, detection engineering, red and purple team exercises, and continuous improvement of CTI and threat-hunting programs.
Requirements
- Bachelor’s degree in cybersecurity, computer science, information security, intelligence studies, or a related field.
- At least 2 years of experience in cyber threat intelligence, threat hunting, SOC L2+, or incident response.
- At least one relevant certification, such as GCTI, GCIH, GCFA, CEH, CySA+, GIAC, OSCP, Security+, CREST, CTIA, or CCTHP.
- Hands-on experience with Elastic SIEM and CrowdStrike Falcon, Cortex, Defender, or comparable EDR/XDR platforms.
- Experience with Recorded Future, MISP, OpenCTI, SOAR/XSOAR, MITRE ATT&CK, Diamond Model, or Cyber Kill Chain.
- Proficiency in OSINT, forensic and log analysis, Windows/Linux internals, networking, malware analysis concepts, and Python, PowerShell, KQL, or EQL.
Nice to have
- Arabic fluency for the Cairo role or Mandarin fluency for the Singapore role.
- Experience in the aviation sector or producing operational and tactical threat intelligence.
- Familiarity with AttackIQ or other breach and attack simulation tools.
Culture & Benefits
- Globally distributed cybersecurity team spanning Montreal, Singapore, and Cairo.
- Up to 30 days per year to work from any location in the world as a temporary flexibility benefit.
- Employee assistance program for employees and dependents, available 24/7.
- LinkedIn Learning, SANS training, and support for industry certifications.
- Competitive benefits aligned with the local market.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →