Lead Threat Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Lead Threat Analyst (Cybersecurity): Leading regional CTI and threat hunting operations to proactively identify adversary activity targeting aviation infrastructure with an accent on the MEA regional threat landscape. Focus on developing hunting hypotheses, automating intelligence workflows, and translating technical findings into executive-level intelligence products.
Location: Cairo, Egypt (Hybrid: work from home up to 2 days/week)
Company
Global leader in air transport communication and information technology, serving 95% of international hubs.
What you will do
- Lead and mentor the Cairo-based Cyber Threat Intelligence and Threat Hunting team, setting targets and fostering growth.
- Oversee the full intelligence lifecycle: collection, analysis, production, dissemination, and feedback.
- Develop hypothesis-driven threat hunts aligned with MITRE ATT&CK during the MEA time zone.
- Translate hunt findings into updated SOC use cases, detection rules, and SIEM content.
- Manage relationships with intelligence sources including Recorded Future, Mandiant, and government CERTs.
- Coordinate global coverage through seamless shift handoffs with Singapore and Montreal hubs.
Requirements
- 5+ years of experience in CTI, threat hunting, or incident response, with at least 2 years in a leadership role.
- Bachelor’s Degree in Cybersecurity, Computer Science, Information Security, or equivalent.
- One or more recognized certifications: GCTI, GCIH, GCFA, GREM, OSCP, CEH, CISM, or CISSP.
- Hands-on expertise with SIEM (Elastic), EDR/XDR (CrowdStrike Falcon, Cortex XDR), and TIPs (Recorded Future, MISP, OpenCTI).
- Strong scripting skills in Python, PowerShell, KQL/EQL for hunting and automation.
- Must be based in Cairo, Egypt.
Nice to have
- Fluency in Arabic for regional OSINT and local stakeholder engagement.
- Experience in the aviation sector.
- Familiarity with Breach and Attack Simulation (BAS) tools such as AttackIQ.
Culture & Benefits
- Flex Week: Work from home up to 2 days per week.
- Flex Location: Opportunity to work from any location in the world for up to 30 days a year.
- Professional development through LinkedIn Learning, SANS training, and industry certifications.
- Comprehensive employee wellbeing support via a 24/7 EAP for employees and dependents.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →