Cyber Threat Intelligence Analyst at AIG specializing in cyber threat research and intelligence production. Collaborating with an interdisciplinary team to enhance cybersecurity situational awareness and reporting.
Responsibilities
Collect, process, catalog, and document information using sources and tools available
Conduct deep-dive investigations into threat actors, TTPs, malware, phishing campaigns, and IOCs using OSINT, dark web, commercial feeds, and internal telemetry
Develop independently and support production of recurring intelligence reporting and briefings for various stakeholders within the organization
Produce concise written analysis and visual presentation of findings under deadlines, including both tactical and strategic assessments
Respond to requests for ad-hoc reporting and research topics from management as required
Maintain a knowledge base of threats to the organization’s business lines, regions, and technology stack
Work with various intelligence collection and reporting tools and frameworks to produce reports
Quickly understand and deliver on stakeholder requirements to produce intelligence that is relevant, timely, accurate, actionable, and appropriate for the audience
Mentor junior analysts to strengthen analytic tradecraft standards across the team and champion a culture of curiosity, critical thinking, and adversary awareness
Deal professionally with offensive, profane, and obscene materials encountered during the course of investigations and research
Requirements
Bachelor’s degree in cybersecurity, computer science, intelligence studies, or related discipline
2+ years of experience in cybersecurity, with at least 1+ years focused on cyber threat intelligence
Experience with using intelligence analysis methodologies and the threat intelligence lifecycle to distill raw information into actionable intelligence
Good understanding of global geopolitical dynamics and the ability to apply that knowledge to an information security context
Proven ability to understand and explain the behaviors of different types of sophisticated cyber adversaries including organized cybercriminal groups and state-sponsored groups
Strong knowledge of common threat actor tools, infrastructure, and malware families
Proven ability to translate complex information sets into specific recommendations and map adversary behavior to MITRE ATT&CK to develop intelligence-focused detection and mitigation strategies
Outstanding written and oral communication skills for both technical and executive audiences
Ability to prepare and present research findings in both virtual and in-person settings
Ability to work both independently and with a team of like-minded professionals to achieve reporting objectives and the ability to organize, track, and prioritize work
Ability to maintain or develop professional contacts in the cybersecurity community and in client industries including finance and government
Experience with conducting operations in closed/vetted online forums and marketplaces in both the surface and dark web spaces
Experience working in and defining intelligence requirements for private sector organizations, especially in a regulated industry (e.g., finance, insurance, healthcare, critical infrastructure)
Hands-on experience with intelligence platforms and tools (e.g., ThreatConnect, CrowdStrike, Mandiant, Anomali, Recorded Future, Silobreaker, Maltego)
Strong understanding of threat analysis and enterprise level mitigation strategies, including experience with SIEMs (e.g., Splunk, Sentinel, Falcon LogScale), EDR/XDR, and threat detection pipelines
Working knowledge of how malicious code operates and how technical vulnerabilities are exploited
Knowledge of operating systems, VPN technologies, Internet abuse issues, networking technologies, and other elements of enterprise networks and technology stacks
Knowledge of databases, query design, and how to analyze data thus obtained
Ability to safely triage and analyze malicious content using technologies like virtual machines, sandboxes, and browsing techniques to maintain strict operational security
Hands-on reverse engineering or malware analysis experience is a plus
Intern supporting IT Security team at OneDigital with hands - on experience and mentoring. Engaging in real - world assignments and responsibilities within IT Security.
Senior Cyber Security Analyst protecting customers from cyber threats while enhancing cyber security services at technology firm. Focused on both security operations and technical delivery.
Cybersecurity Analyst assisting in the review and implementation of cybersecurity initiatives across a large environment at Kemper. Responding to cyber threats and improving processes and technologies.
Senior Information Security Analyst managing Information Security Management System at BMLL Technology. Supporting compliance with ISO 27001 and enhancing security measures.
Graduate Cyber Security Analyst at McKesson participating in a 24 - month Cyber Academy program. Monitor security alerts and contribute to incident response efforts while gaining mentorship.
Threat Intelligence Analyst role analyzing cyber threats and providing strategic recommendations. Working with cybersecurity teams at PwC Canada to safeguard client data and systems.
Contract Security Analyst specializing in security operations and incident response for cloud security at Embark. Focus on alert handling, detection engineering, and data loss prevention.
Cyber Security Analyst providing security operations support for USAF Cloud One project. Engaging in incident response and cybersecurity compliance activities within a hybrid environment.
Cybersecurity Analyst responsible for monitoring, analyzing, and responding to security incidents in SOC. Developing detection rules and conducting threat - hunting campaigns within a hybrid work setup.
Information Security Analyst working with Optasia to enforce security controls and protect data. Collaborating on technical projects and auditing systems in a hybrid work environment.