обновлено 1 месяц назад
Lead Threat Analyst (Cyber Threat Intelligence | Threat Hunting | GCTI) (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Lead Threat Analyst (Cyber Threat Intelligence | Threat Hunting | GCTI) (Cybersecurity): Leading Cairo-based CTI and threat hunting operations for aviation-sector security with an accent on intelligence production, dark web investigations, detection engineering, and incident response. Focus on developing hypothesis-driven hunts aligned with MITRE ATT&CK, coordinating global coverage across Cairo, Singapore, and Montreal, and translating findings into stronger SOC detections.
Location: Cairo, Egypt (MEA); hybrid work with work from home up to 2 days per week
Salary: Not disclosed
Company
provides technology, communications, and cybersecurity solutions for the global air travel industry, serving airports, airlines, transportation organizations, and government clients.
What you will do
- Lead and mentor the Cairo-based Cyber Threat Intelligence and Threat Hunting team, set objectives, and support professional development.
- Coordinate shift handoffs between Cairo, Singapore, and Montreal to maintain 24/7x365 global coverage.
- Oversee the intelligence lifecycle and produce threat landscape reports, threat actor profiles, flash alerts, and executive briefings focused on MEA threats.
- Lead dark web monitoring, credential exposure investigations, and escalation and remediation coordination.
- Develop MITRE ATT&CK-aligned hunting hypotheses and oversee detection engineering, SOC use cases, SIEM content, and detection rules.
- Coordinate purple team and attack simulation exercises and support major security incidents with intelligence and forensic hunting expertise.
Requirements
- Bachelor’s degree in cybersecurity, computer science, information security, intelligence studies, or an equivalent field.
- At least one relevant certification, such as GCTI, GCIH, GCFA, GREM, OSCP, CEH, CISM, or CISSP.
- 5+ years of experience in cyber threat intelligence, threat hunting, or incident response, including at least 2 years in a lead or supervisory role.
- Experience mentoring security analysts or threat hunters and coordinating regional operations.
- Hands-on expertise with Elastic SIEM, CrowdStrike Falcon, Cortex XDR, Recorded Future, MISP, OpenCTI, and SOAR/XSOAR.
- Advanced skills in log analysis, forensics, endpoint, network, cloud, and identity telemetry, plus Python, PowerShell, KQL/EQL, OSINT, dark web intelligence, and malware analysis.
Nice to have
- Arabic fluency for regional OSINT and local stakeholder engagement.
- Experience in the aviation sector.
- Familiarity with Breach and Attack Simulation tools such as AttackIQ.
- Experience establishing or scaling a regional security team.
Culture & Benefits
- Flex Location allows up to 30 days per year of work from any location worldwide.
- Employee assistance program for employees and dependents, available 24/7.
- Professional development through LinkedIn Learning, SANS training, and industry certifications.
- Competitive benefits aligned with the local market.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →