
Senior Cyber Threat Intelligence, CTI Analyst
Posted Aug 27

Posted Aug 27
This is a fully remote position, open to applicants in United Kingdom.
• Perform hands-on analysis of cyber threat intelligence, concentrating on threat actors, campaigns, tactics, techniques, procedures, infrastructure, malware, phishing activities, ransomware, and cybercrime ecosystems aimed at live entertainment, ticketing, and e-commerce.
• Generate tactical, operational, and strategic intelligence outputs, which include threat assessments, intelligence reports, executive briefings, RFIs, threat actor profiles, and actionable recommendations.
• Take ownership of and assist in the intelligence lifecycle, encompassing requirements gathering, data collection, analysis, enrichment, dissemination, and feedback.
• Convert raw threat data, OSINT, vendor intelligence, dark web research, internal telemetry, and partner reporting into actionable intelligence.
• Conduct technical investigations on malicious infrastructure, tools, and tradecraft, involving infrastructure pivoting, malware and phishing kit triage, and campaign attribution analysis.
• Identify detection opportunities and collaborate with Detection Engineering to develop YARA, Sigma, or SIEM query content.
• Support threat hunting, detection engineering, incident response, vulnerability management, fraud prevention, and broader cyber defense teams.
• Create and enhance Priority Intelligence Requirements, collection priorities, analytical workflows, and reporting protocols.
• Analyze threat actor behavior and correlate activities with the MITRE ATT&CK framework.
• Present briefings to technical, business, and senior leadership stakeholders regarding threats, trends, business impacts, and recommended actions.
• Mentor and guide fellow analysts through influence, tradecraft coaching, intelligence writing, and analytical review.
• Assist in the maturation of CTI processes, tools, reporting standards, and intelligence outputs.
• Aid in the development and automation of threat analysis workflows and tools; utilize platforms such as MISP, ThreatConnect, EclecticIQ, or Anomali.
• Occasionally participate in on-call rotations and aid incident response efforts.
• Over 5 years of hands-on experience in cyber threat intelligence within a dedicated CTI, cyber intelligence, or threat intelligence role.
• Proven experience in conducting threat actor analysis, adversary tracking, campaign analysis, IOC/TTP analysis, and intelligence production, including the use of MITRE ATT&CK or similar frameworks.
• Comprehensive understanding of the intelligence lifecycle, including requirements, collection, analysis, dissemination, and stakeholder feedback.
• Demonstrated ability to create clear, actionable intelligence reports, assessments, briefings, and RFIs for both technical and non-technical audiences.
• Experience in supporting threat hunting, incident response, detection engineering, vulnerability management, or security operations through intelligence outputs.
• Experience in mentoring, guiding, or influencing other analysts as a senior individual contributor or functional lead.
• Strong knowledge of system, network, and application security, specifically Windows and Linux internals.
• Experience analyzing threats using SIEM, EDR, and TIP platforms; familiarity with OSINT, dark web sources, ISACs, Recorded Future, Mandiant, Flashpoint, Anomali, ThreatConnect, and VirusTotal.
• Hands-on experience investigating adversary infrastructure utilizing passive DNS, WHOIS, TLS certificate, and internet-scan data.
• Experience triaging malware, phishing kits, or attacker tooling using sandbox or detonation environments and extracting IOCs, C2 infrastructure, and behavioral indicators.
• Proficiency in at least one query language (KQL, SPL, CQL, SQL), capability to read and understand code, and working knowledge of scripting languages such as Python or Bash.
• Excellent written and verbal communication skills, with the ability to translate complex threat activity into business-relevant risk.
• Cyber threat intelligence experience within live entertainment, ticketing, e-commerce, payments, or another high-volume consumer transaction sector.
• Experience in building or enhancing CTI processes such as Priority Intelligence Requirements, collection plans, reporting standards, RFI workflows, or intelligence dissemination models.
• Familiarity with ransomware, cybercrime, fraud-related threat intelligence, third-party exposure, or credential exposure analysis.
• Experience conducting research on the dark web, underground forums, or cybercrime ecosystems, including persona management and operational security tradecraft.
• Experience with static or dynamic malware analysis and reverse engineering using tools like Ghidra, IDA, or x64dbg, or with network flow analysis and host forensics.
• Experience in authoring detection content such as YARA, Sigma, or Suricata rules, or SIEM correlation searches.
• Experience tracking offensive tooling and C2 frameworks such as Cobalt Strike, Sliver, or Mythic.
• Familiarity with STIX/TAXII, threat intelligence enrichment pipelines, or TIP administration and automation.
• Knowledge of AWS, Azure, or GCP and securing cloud environments.
• Exposure to AI use cases within cyber threat intelligence.
• Experience collaborating with external intelligence-sharing groups such as ISACs, InfraGard, CISA, law enforcement, or intelligence community partners.
• Security certifications such as GCTI, GCFA, GREM, OSCP, or CISSP.
• Strong experience with question-driven analysis and structured analytic techniques.
• Ability to analyze and correlate TTPs to an enterprise environment.
• Ability to analyze and step through code to identify potential IOCs or detection opportunities.
• Ability to identify anomalies and trends across vast, unstructured datasets.
• Ability to investigate adversary infrastructure and pivot from a single indicator to broader campaign infrastructure.
• Comfortable performing initial triage of malware samples, phishing kits, and attacker tooling in sandbox or detonation environments.
• Working knowledge of common C2 frameworks, commodity malware families, and phishing ecosystems.
• Sound operational security practices for OSINT, dark web, and underground forum research.
• Ability to script enrichment and automation against threat intelligence and security tool APIs.
• Proven experience in tracking advanced threat actors and financially motivated cybercrime groups.
• Strong command of the intelligence lifecycle and the MITRE ATT&CK framework, including MITRE Navigator.
• Skilled intelligence writer capable of authoring and peer reviewing products for both technical and executive audiences.
• Experience in developing Priority Intelligence Requirements and collection priorities within a large organization.
• Ability to deliver briefings to technical, business, and senior leadership stakeholders.
• Capacity to mentor and guide fellow analysts.
• Ability to operate effectively within high-stakes, time-sensitive investigations.
• Capacity to translate complex threat activity into business-relevant risk and decision support.
• A collaborative and inclusive environment that emphasizes mentorship, diverse perspectives, and ongoing growth.
• A remote-friendly and flexible work culture.
• Exposure to a broad spectrum of threat landscapes across live entertainment, e-commerce, and cloud infrastructure.
• An opportunity to directly influence the maturity and effectiveness of Live Nation’s global threat intelligence function.
• 401(K) retirement plan with employer matching.
Tenet Healthcare
Early Childhood Educators
Get handpicked remote jobs straight to your inbox weekly.