
Senior Cyber Threat Response Advisor
Posted 7 hours ago

Posted 7 hours ago
This is a fully remote position, open to applicants in United States.
• Conduct analysis of critical-infrastructure sectors to identify organizations that require the highest level of protection.
• Uncover vulnerabilities and exposures from the initial signal to actionable notifications for defenders.
• Integrate OSINT, external attack surface discovery, and direct threat actor intelligence.
• Leverage AI to develop tools and workflows that enhance remediation processes at scale, ensuring human quality control.
• Contribute effective strategies into TRM tools and workflows.
• Map out C2 infrastructure, malware families, TTPs, and threat actors.
• Analyze large sets of indicators and exposures, clustering infrastructure effectively.
• Generate exposure notifications, as well as actor and campaign profiles, IOC packages, and infrastructure attributions.
• Provide advice across multiple active threats and assist fellow analysts through analytical execution.
• Collaborate with critical infrastructure organizations, government partners, ISACs, engineers, and internal teams.
• Engage in weekly team meetings and daily asynchronous standups.
• Record findings in Notion and TRM investigative tools.
• Adjust work hours during active disruption periods to address urgent partner needs.
• Minimum of 5 years of experience in cyber threat intelligence, incident response, or a closely related analytical discipline.
• Proven experience as the primary contact for an external organization during live incidents or remediation efforts.
• Capability to conduct complex analyses independently leading to actionable results.
• Experience providing definitive answers under time-sensitive RFI conditions.
• Proficiency in applied AI, including the creation of AI-assisted workflows and validation of outputs.
• Practical skills in OSINT, external attack surface discovery, or direct threat-actor intelligence collection.
• Experience in producing comprehensive intelligence outputs such as actor profiles, campaign reports, attribution assessments, exposure notifications, or infrastructure mapping.
• Strong OSINT capabilities, with the ability to resolve identities, aliases, infrastructure, and behaviors across disparate sources.
• Exceptional judgment concerning analytical confidence and evidentiary strength.
• Superior written and verbal communication skills.
• Comfort in a fast-paced and ambiguous work environment.
• Willingness to travel up to 50% within the United States.
• Must reside in the United States.
• U.S. citizenship is required.
• Familiarity with critical-infrastructure sectors, government partners, ISACs, or sector coordinating bodies is advantageous.
• Proficiency in a language commonly used by cyber actors is a plus.
• A public presence through conference presentations, published research, or participation in exclusive sharing circles is a plus.
• Eligibility for equity plan participation.
• Remote work in a distributed-first environment.
• Async-first workflow using Slack and Notion.
• High degree of autonomy with minimal bureaucracy.
• Collaboration within a global team.
• Flexible working hours during active disruption periods.
• Competitive benefits package, wellness initiatives, and time off from work, varying by country and local employment regulations.
Power Digital Marketing
Ciena
Johnson & Johnson
BlueCross BlueShield of Tennessee
Get handpicked remote jobs straight to your inbox weekly.