Назад
Company hidden
4 дня назад

Senior Cyber Threat Intelligence Analyst (CTI)

Формат работы
remote (только United_kingdom)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Cyber Threat Intelligence Analyst (Cybersecurity): Conducting hands-on analysis of threat actors, malicious infrastructure, malware, phishing campaigns, ransomware, and cybercrime targeting live entertainment, ticketing, and e-commerce with an accent on actionable intelligence, adversary tracking, and detection opportunities. Focus on researching underground ecosystems, triaging malware and phishing kits, mapping activity to MITRE ATT&CK, and developing YARA, Sigma, and SIEM detection content.

Location: Farringdon, London, United Kingdom; working hours are 9:00 AM–6:00 PM GMT. The role is described as remote-friendly with a flexible work culture.

Company

hirify.global operates across live entertainment, ticketing, e-commerce, and cloud infrastructure.

What you will do

  • Analyze threat actors, campaigns, tactics, techniques, procedures, infrastructure, malware, phishing activity, ransomware, and cybercrime ecosystems.
  • Produce tactical, operational, and strategic intelligence reports, threat assessments, executive briefings, threat actor profiles, RFIs, and recommendations.
  • Manage intelligence lifecycle activities including requirements gathering, collection, enrichment, analysis, dissemination, and feedback.
  • Research adversary infrastructure, malware, phishing kits, attacker tooling, dark web activity, and underground forums using OSINT, vendor intelligence, internal telemetry, and partner reporting.
  • Identify detection opportunities and collaborate with Detection Engineering on YARA, Sigma, Suricata, and SIEM content.
  • Support threat hunting, incident response, vulnerability management, fraud, and cyber defense while mentoring analysts and improving CTI processes and tooling.

Requirements

  • 5+ years of hands-on experience in cyber threat intelligence, cyber intelligence, or threat intelligence.
  • Experience with threat actor, campaign, IOC, and TTP analysis; intelligence production; MITRE ATT&CK; and Priority Intelligence Requirements.
  • Strong knowledge of system, network, application, Windows, and Linux security, with experience using SIEM, EDR, and threat intelligence platforms.
  • Hands-on experience investigating infrastructure with passive DNS, WHOIS, TLS certificates, internet-scan data, malware sandboxes, and phishing-kit analysis.
  • Proficiency in at least one query language such as KQL, SPL, CQL, or SQL, plus working scripting ability in Python or Bash and the ability to read code.
  • Experience with malware analysis, reverse engineering, detection content, C2 frameworks, dark web research, cloud security, and technical and executive briefings.

Nice to have

  • Experience in live entertainment, ticketing, e-commerce, payments, or another high-volume consumer transaction environment.
  • Security certifications such as GCTI, GCFA, GREM, OSCP, or CISSP.
  • Familiarity with STIX/TAXII, TIP administration and automation, AWS, Azure, GCP, and AI use cases in CTI.
  • Experience collaborating with ISACs, InfraGard, CISA, law enforcement, or intelligence community partners.

Culture & Benefits

  • Collaborative and inclusive environment focused on mentorship, diverse perspectives, and continuous growth.
  • Remote-friendly and flexible work culture.
  • Exposure to diverse threat landscapes across live entertainment, e-commerce, and cloud infrastructure.
  • Opportunity to shape the maturity and impact of a global threat intelligence function.
  • 401(k) retirement program with employer match.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →