Hybrid Cyber Threat Intelligence Consultant

Posted 2 months ago

Apply now

About the role

  • Consultant specializing in Cyber Threat Intelligence within cybersecurity services. Focusing on continuous improvement and operational management collaboration with SOC and CSIRT.

Responsibilities

  • The role is part of a continuous improvement effort, working closely with the build, SOC and CSIRT teams.
  • Manage day-to-day CTI operations.
  • Ensure the operational follow-up of CTI: feed monitoring, integrations, and data quality.
  • Work closely with the build team on redesigning and automating CTI processes (IOC ingestion, OpenCTI, Splunk/TheHive interconnections).
  • Handle and triage CTI alerts; verify IOC relevance and their impact on the environment.
  • Contribute to the creation and updating of CTI reports.
  • Gather and analyze information from internal sources (SOC, CSIRT, VOC) and external sources (OSINT, partners, commercial feeds, CERT-FR, ANSSI).
  • Contribute to IOC qualification and enrichment (reliability, context, MITRE ATT&CK mapping).
  • Monitor APT and cybercriminal campaigns affecting critical sectors.
  • Produce tactical and operational CTI reports (IOCs, TTPs, campaigns).
  • Maintain an actionable, documented and automated CTI pipeline.
  • Disseminate IOCs and reports to relevant entities (SOC, CSIRT, CISO, business units).
  • Participate in threat hunting activities in SIEM/EDR environments (primarily Splunk).
  • Correlate IOCs/TTPs with SOC logs and alerts.
  • Propose new detection rules (YARA, Sigma, etc.) in collaboration with detection teams.
  • Provide contextualized intelligence during major incidents.
  • Contribute to monitoring and post-incident knowledge retention.
  • Help define and maintain the threat repository/taxonomy (actors, TTPs, MITRE ATT&CK, Diamond Model).
  • Document processes, best practices and lessons learned.
  • Recommend improvements to CTI tooling (TIP integration, optimization of Splunk / TheHive / OpenCTI).

Requirements

  • Proven experience in operational CTI run management (IOCs, alerts, automation, integrations).
  • Knowledge of the OpenCTI ecosystem, Splunk and/or TheHive.
  • Scripting/automation skills (Python, APIs) are a plus.
  • Strong interpersonal skills and the ability to collaborate with build and operational security teams.
  • Analytical mindset, rigor and technical curiosity.

Benefits

  • Join a young, growing company specializing in cybersecurity.
  • A personalized CSR and professional development path.
  • Remote work possible.

Job title

Cyber Threat Intelligence Consultant

Job type

Experience level

Mid levelSenior

Salary

Not specified

Degree requirement

No Education Requirement

Tech skills

Location requirements

Report this job

See something inaccurate? Let us know and we'll update the listing.

Report job