Senior Cyber Threat Intelligence, CTI Analyst

Posted Aug 27

This is a fully remote position, open to applicants in United Kingdom.

📋 Description

• Perform hands-on analysis of cyber threat intelligence, concentrating on threat actors, campaigns, tactics, techniques, procedures, infrastructure, malware, phishing activities, ransomware, and cybercrime ecosystems aimed at live entertainment, ticketing, and e-commerce.

• Generate tactical, operational, and strategic intelligence outputs, which include threat assessments, intelligence reports, executive briefings, RFIs, threat actor profiles, and actionable recommendations.

• Take ownership of and assist in the intelligence lifecycle, encompassing requirements gathering, data collection, analysis, enrichment, dissemination, and feedback.

• Convert raw threat data, OSINT, vendor intelligence, dark web research, internal telemetry, and partner reporting into actionable intelligence.

• Conduct technical investigations on malicious infrastructure, tools, and tradecraft, involving infrastructure pivoting, malware and phishing kit triage, and campaign attribution analysis.

• Identify detection opportunities and collaborate with Detection Engineering to develop YARA, Sigma, or SIEM query content.

• Support threat hunting, detection engineering, incident response, vulnerability management, fraud prevention, and broader cyber defense teams.

• Create and enhance Priority Intelligence Requirements, collection priorities, analytical workflows, and reporting protocols.

• Analyze threat actor behavior and correlate activities with the MITRE ATT&CK framework.

• Present briefings to technical, business, and senior leadership stakeholders regarding threats, trends, business impacts, and recommended actions.

• Mentor and guide fellow analysts through influence, tradecraft coaching, intelligence writing, and analytical review.

• Assist in the maturation of CTI processes, tools, reporting standards, and intelligence outputs.

• Aid in the development and automation of threat analysis workflows and tools; utilize platforms such as MISP, ThreatConnect, EclecticIQ, or Anomali.

• Occasionally participate in on-call rotations and aid incident response efforts.


⛳️ Requirements

• Over 5 years of hands-on experience in cyber threat intelligence within a dedicated CTI, cyber intelligence, or threat intelligence role.

• Proven experience in conducting threat actor analysis, adversary tracking, campaign analysis, IOC/TTP analysis, and intelligence production, including the use of MITRE ATT&CK or similar frameworks.

• Comprehensive understanding of the intelligence lifecycle, including requirements, collection, analysis, dissemination, and stakeholder feedback.

• Demonstrated ability to create clear, actionable intelligence reports, assessments, briefings, and RFIs for both technical and non-technical audiences.

• Experience in supporting threat hunting, incident response, detection engineering, vulnerability management, or security operations through intelligence outputs.

• Experience in mentoring, guiding, or influencing other analysts as a senior individual contributor or functional lead.

• Strong knowledge of system, network, and application security, specifically Windows and Linux internals.

• Experience analyzing threats using SIEM, EDR, and TIP platforms; familiarity with OSINT, dark web sources, ISACs, Recorded Future, Mandiant, Flashpoint, Anomali, ThreatConnect, and VirusTotal.

• Hands-on experience investigating adversary infrastructure utilizing passive DNS, WHOIS, TLS certificate, and internet-scan data.

• Experience triaging malware, phishing kits, or attacker tooling using sandbox or detonation environments and extracting IOCs, C2 infrastructure, and behavioral indicators.

• Proficiency in at least one query language (KQL, SPL, CQL, SQL), capability to read and understand code, and working knowledge of scripting languages such as Python or Bash.

• Excellent written and verbal communication skills, with the ability to translate complex threat activity into business-relevant risk.

• Cyber threat intelligence experience within live entertainment, ticketing, e-commerce, payments, or another high-volume consumer transaction sector.

• Experience in building or enhancing CTI processes such as Priority Intelligence Requirements, collection plans, reporting standards, RFI workflows, or intelligence dissemination models.

• Familiarity with ransomware, cybercrime, fraud-related threat intelligence, third-party exposure, or credential exposure analysis.

• Experience conducting research on the dark web, underground forums, or cybercrime ecosystems, including persona management and operational security tradecraft.

• Experience with static or dynamic malware analysis and reverse engineering using tools like Ghidra, IDA, or x64dbg, or with network flow analysis and host forensics.

• Experience in authoring detection content such as YARA, Sigma, or Suricata rules, or SIEM correlation searches.

• Experience tracking offensive tooling and C2 frameworks such as Cobalt Strike, Sliver, or Mythic.

• Familiarity with STIX/TAXII, threat intelligence enrichment pipelines, or TIP administration and automation.

• Knowledge of AWS, Azure, or GCP and securing cloud environments.

• Exposure to AI use cases within cyber threat intelligence.

• Experience collaborating with external intelligence-sharing groups such as ISACs, InfraGard, CISA, law enforcement, or intelligence community partners.

• Security certifications such as GCTI, GCFA, GREM, OSCP, or CISSP.

• Strong experience with question-driven analysis and structured analytic techniques.

• Ability to analyze and correlate TTPs to an enterprise environment.

• Ability to analyze and step through code to identify potential IOCs or detection opportunities.

• Ability to identify anomalies and trends across vast, unstructured datasets.

• Ability to investigate adversary infrastructure and pivot from a single indicator to broader campaign infrastructure.

• Comfortable performing initial triage of malware samples, phishing kits, and attacker tooling in sandbox or detonation environments.

• Working knowledge of common C2 frameworks, commodity malware families, and phishing ecosystems.

• Sound operational security practices for OSINT, dark web, and underground forum research.

• Ability to script enrichment and automation against threat intelligence and security tool APIs.

• Proven experience in tracking advanced threat actors and financially motivated cybercrime groups.

• Strong command of the intelligence lifecycle and the MITRE ATT&CK framework, including MITRE Navigator.

• Skilled intelligence writer capable of authoring and peer reviewing products for both technical and executive audiences.

• Experience in developing Priority Intelligence Requirements and collection priorities within a large organization.

• Ability to deliver briefings to technical, business, and senior leadership stakeholders.

• Capacity to mentor and guide fellow analysts.

• Ability to operate effectively within high-stakes, time-sensitive investigations.

• Capacity to translate complex threat activity into business-relevant risk and decision support.


🏝️ Benefits

• A collaborative and inclusive environment that emphasizes mentorship, diverse perspectives, and ongoing growth.

• A remote-friendly and flexible work culture.

• Exposure to a broad spectrum of threat landscapes across live entertainment, e-commerce, and cloud infrastructure.

• An opportunity to directly influence the maturity and effectiveness of Live Nation’s global threat intelligence function.

• 401(K) retirement plan with employer matching.

People also viewed

Tenet Healthcare1 day ago

UKG Pro WFM Scheduling & Clinical Scheduling Extensions Analyst

US flagUnited States OnlyFull-timeAnalyst$73.6k – $105k/year
ApplyView job
Sophos1 day ago

Threat Analyst 2

GB flagUnited Kingdom OnlyFull-timeAnalyst
ApplyView job
Early Childhood Educators1 day ago

Professional Practice Analyst

CA flagCanada OnlyFull-timeAnalystC$77k – C$81.5k/year
ApplyView job
Coinbase1 day ago

Complaints Analyst III

LU flagLuxembourg OnlyFull-timeAnalyst€82k/year
ApplyView job
Stack Overflow1 day ago

Document Control Analyst, Delivery Program

US flagColorado OnlyFull-timeAnalyst$72k – $79k/year
ApplyView job
Prime Therapeutics1 day ago

Health Informatics Analyst

US flagUnited States OnlyFull-timeAnalyst$74k – $118k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers