Principal Cyber Defense Threat Intelligence Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Location: Hybrid, with in-office work at least three days per week on Tuesday, Wednesday, and Thursday. Open to corporate offices in Chicago/Oakbrook Terrace, Illinois; Philadelphia, Pennsylvania; Newark, Delaware; Baltimore, Maryland; or Washington, DC. Candidates must be able to commute within the service area. Monthly or as-needed travel to Golden, Colorado is required. No relocation is available.
Salary: $136,800–$188,100 per year, plus an annual bonus of up to 20% for eligible positions.
Company
is a Fortune 200 energy company supporting six utilities, more than 20,000 colleagues, and over 10.7 million customers.
What you will do
- Identify, collect, monitor, analyze, and synthesize threat intelligence from internal, partner, and open sources.
- Produce actionable intelligence reports and verbal briefings for the joint security operations center and IT and operational technology teams.
- Develop threat hunting and detection campaigns with partner organizations and apply detection methodologies across the corporate environment.
- Collaborate with incident response, monitoring, forensics, systems engineering, physical security, and OT security teams.
- Support the identification, containment, and eradication of threats targeting enterprise, operational technology, and critical infrastructure assets.
- Recommend short- and long-term security control improvements and direct the tuning of signatures, rules, alerts, parsers, and custom scripts.
Requirements
- Bachelor’s degree in computer science, information systems, or a related technical field, or equivalent military or government experience, with typically 5–8 years of diverse experience in IT, cybersecurity, real-time systems, or a related area.
- Must be willing to obtain and maintain a U.S. government TS/SCI security clearance.
- Experience in operational technology defense, threat hunting, adversary TTPs, MITRE ATT&CK, OSINT collection, and deception techniques.
- Proficiency with SIEM, IDS/IPS, threat intelligence platforms, and SOAR solutions, plus experience in incident handling, vulnerability management, malware analysis, and intelligence gathering.
- Strong knowledge of operating systems, network and host cybersecurity solutions, vulnerabilities, exploits, and kill chain methodology.
- Strong written and verbal communication skills and experience collaborating with internal and external trusted entities.
Nice to have
- GIAC Certified Intrusion Analyst, GIAC Certified Incident Handler, GIAC Cyber Threat Intelligence, GIAC Network Forensic Analyst, or OSCP certification.
- Graduate degree in cybersecurity, intelligence and analysis, or a related field.
- At least three years of experience supporting the energy sector.
- Experience investigating targeted intrusions across complex network segments in a SOC, SIRT, or CSIRT environment.
- Existing U.S. government security clearance and experience handling sensitive classified data.
Culture & Benefits
- Medical, dental, and vision insurance, plus life and disability insurance.
- 401(k) match and annual company contribution.
- Paid vacation, sick time, holidays, maternity leave, bonding or primary caregiver leave, and parental leave.
- Tuition reimbursement, fitness reimbursement, adoption and surrogacy assistance, and wellbeing resources.
- Employee Assistance Program and referral bonus program.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →