3 дня назад
CTI Analyst III (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
CTI Analyst III (Cybersecurity): Producing actionable tactical and operational cyber threat intelligence for healthcare-sector defense, incident response, risk management, and decision-making with an accent on threat analysis, intelligence production, and regulatory compliance. Focus on analyzing dark web and open-source intelligence, applying MITRE ATT&CK and Cyber Kill Chain frameworks, mentoring analysts, and improving CTI workflows.
Location: US - National
Company
is an IT services firm focused exclusively on helping healthcare providers use technology and achieve digital transformation.
What you will do
- Collect, analyze, contextualize, and disseminate actionable tactical and operational cyber threat intelligence.
- Produce threat assessments and intelligence reports covering healthcare-sector threats and regulated environments.
- Acquire and manage intelligence from open-source, commercial, dark web, and industry-sharing sources.
- Collaborate with security operations, incident response, risk management, external partners, and information-sharing groups.
- Provide technical leadership and mentorship to junior CTI analysts.
- Improve CTI tools, workflows, methodologies, documentation, quality assurance, and operational impact.
Requirements
- Advanced knowledge of the cyber threat intelligence lifecycle, structured analysis, and intelligence dissemination.
- At least 8 years of experience in cyber threat intelligence, information security, incident response, threat analysis, or a related field; equivalent paths include a bachelor's degree with 8 years, a master's degree with 6 years, or 11 years without a degree.
- Proficiency with threat intelligence platforms, SIEM tools, NETFLOW, PCAP, malware analysis, and OSINT techniques.
- Strong understanding of intrusion detection and prevention, incident response, attack methodologies, and security operations.
- Experience with the Cyber Kill Chain, MITRE ATT&CK, and Analysis of Competing Hypotheses frameworks.
- Ability to work in the US nationally and participate in a 24-hour on-call rotation for critical technical incidents.
Nice to have
- Healthcare-sector experience and knowledge of sector-specific threats.
- Certifications such as CISSP, GCTI, GIAC, GCIH, CEH, GCFA, CompTIA+, or equivalent.
- Experience with scripting, automation, data visualization, external intelligence partners, and ISACs.
Culture & Benefits
- Opportunity to support healthcare providers and regulated environments.
- Work involves collaboration across multidisciplinary technical and operational teams.
- Requires independent work, discretion with sensitive information, and management of multiple priorities.
- Participation in a rotating 24-hour on-call schedule for emergency response.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →