
Senior Threat Intelligence Analyst
Posted Aug 15

Posted Aug 15
This is a fully remote position, open to applicants in United Kingdom.
• Perform proactive research on threat actors, malware families, campaigns, and developing TTPs.
• Investigate and present both operational and strategic intelligence, encompassing attribution, motivation, capability, and geopolitical context.
• Lead both short-term and long-term threat tracking initiatives while identifying intelligence gaps.
• Assess and disseminate tools, methodologies, and best practices for comprehending adversary TTPs.
• Conduct analysis of network traffic and infrastructure utilizing global datasets.
• Analyze PCAP, NetFlow, passive DNS, open ports, certificates, and other datasets to trace malicious infrastructure.
• Identify and refine IOCs and threat actor TTPs, converting them into automated tracking mechanisms.
• Respond to customer inquiries with tailored, written technical threat intelligence reports.
• Ensure that intelligence products comply with analytical standards and contain actionable conclusions.
• Conduct peer reviews of colleagues’ reports.
• Collaborate on analytical tools, data analytics systems, research methodologies, and automation of analysis.
• Assist threat detection and data acquisition teams with signature development and telemetry collection priorities.
• Represent Team Cymru by participating in working groups, industry events, and community collaborations.
• Over 5 years of experience as a threat intelligence analyst, network forensics analyst, or IT security analyst.
• A Bachelor's degree in Computer Science, Computer Engineering, Cybersecurity, or a related field is preferred.
• Exceptional oral and written communication abilities.
• Capacity to produce customer-facing intelligence reports under tight deadlines.
• Experience with structured analysis techniques, estimative language, and confidence levels is preferred.
• Demonstrated success in leading complex analytical projects or investigations.
• Ability to manage multiple concurrent work streams effectively.
• Strong analytical, deductive reasoning, and critical thinking abilities.
• Competence in working efficiently within a distributed, remote team environment.
• Experience tracking APT, nation-state, or cybercriminal actors.
• Excellent skills in network infrastructure and traffic analysis: PCAP, NetFlow, PDNS, open ports, and certificates.
• In-depth understanding of IP networking and internet services: DNS, HTTP/HTTPS, TLS, VPNs, and BGP.
• Knowledge of operating system concepts, IOCs, and host and network-level detection architectures.
• Proficient in SQL and adept at querying and analyzing large, disparate datasets.
• Strong familiarity with common OSINT platforms and research methodologies.
• Willingness to travel occasionally within the UK and internationally.
• Proficiency in programming or scripting, preferably in Python, is highly desirable.
• Familiarity with AI systems, Linux servers, malware analysis, YARA, Zeek, Suricata, sandbox reporting, reverse engineering tools, and internet infrastructure operations is highly desirable.
• A collaborative, mission-driven culture.
• Opportunity to engage in global cybersecurity and threat intelligence initiatives.
• Participation in exclusive conferences, industry events, working groups, and community collaborations.
• Remote working options available.
• Occasional travel within the UK and internationally for customer workshops, industry events, and team meetings.
Leidos
Palo Alto Networks
Presidio
Presidio
Get handpicked remote jobs straight to your inbox weekly.