Consultant specializing in Cyber Threat Intelligence within cybersecurity services. Focusing on continuous improvement and operational management collaboration with SOC and CSIRT.
Responsibilities
The role is part of a continuous improvement effort, working closely with the build, SOC and CSIRT teams.
Manage day-to-day CTI operations.
Ensure the operational follow-up of CTI: feed monitoring, integrations, and data quality.
Work closely with the build team on redesigning and automating CTI processes (IOC ingestion, OpenCTI, Splunk/TheHive interconnections).
Handle and triage CTI alerts; verify IOC relevance and their impact on the environment.
Contribute to the creation and updating of CTI reports.
Gather and analyze information from internal sources (SOC, CSIRT, VOC) and external sources (OSINT, partners, commercial feeds, CERT-FR, ANSSI).
Contribute to IOC qualification and enrichment (reliability, context, MITRE ATT&CK mapping).
Monitor APT and cybercriminal campaigns affecting critical sectors.
Produce tactical and operational CTI reports (IOCs, TTPs, campaigns).
Maintain an actionable, documented and automated CTI pipeline.
Disseminate IOCs and reports to relevant entities (SOC, CSIRT, CISO, business units).
Participate in threat hunting activities in SIEM/EDR environments (primarily Splunk).
Correlate IOCs/TTPs with SOC logs and alerts.
Propose new detection rules (YARA, Sigma, etc.) in collaboration with detection teams.
Provide contextualized intelligence during major incidents.
Contribute to monitoring and post-incident knowledge retention.
Help define and maintain the threat repository/taxonomy (actors, TTPs, MITRE ATT&CK, Diamond Model).
Document processes, best practices and lessons learned.
Recommend improvements to CTI tooling (TIP integration, optimization of Splunk / TheHive / OpenCTI).
Requirements
Proven experience in operational CTI run management (IOCs, alerts, automation, integrations).
Knowledge of the OpenCTI ecosystem, Splunk and/or TheHive.
Scripting/automation skills (Python, APIs) are a plus.
Strong interpersonal skills and the ability to collaborate with build and operational security teams.
Analytical mindset, rigor and technical curiosity.
Benefits
Join a young, growing company specializing in cybersecurity.
A personalized CSR and professional development path.
Clinical Consultant role in dialysis industry enhancing revenue through customer relationships and collaboration. Requires strong clinical background and strategic planning capabilities.
Clinical Consultant focusing on clinical education and customer relationships in the dialysis industry. Responsible for assessing facilities and training nursing staff for improved outcomes.
Power Apps Consultant developing applications on Power Platform for Data & Analytics projects. Collaborating with stakeholders to create effective technical solutions in São Paulo, Brazil.
Consultor Comercial I responsible for financial and administrative governance at Suzano. Ensuring compliance and managing processes for the commercial sector.
RF Consultant focal point for Mobile Access deployment in private networks. Responsible for XML file creation, eNodeB integration, and collaboration with project teams.
ORM Consultant at SIDN Digital Thinking managing online reputation strategies for large brands. Responsibilities include strategic coordination, analysis of user sentiment, and corporate communications support.
Senior IT Service Desk Consultant for Wolf Consulting handling Tier 2/Tier 3 requests. Working in a hybrid environment supporting IT operations for small and mid - size businesses.
HubSpot Consultant shaping CRM initiatives and strategies for B2B clients. Partnering to drive retention and growth while optimizing HubSpot solutions from Hamburg.
Lead Software Engineer designing, developing and delivering enterprise - level applications at Pariveda Solutions. Work collaboratively with clients on real business challenges in an agile, people - first way.