Threat Intelligence Analyst
VultrFull Time
Mid-level (3 to 4 years), Senior (5 to 8 years)
Candidates should possess a BA/BS or equivalent experience in Computer Science, Computer Engineering, Information Security, Security Studies, Intelligence, or a related field, with a preference for 5+ years of experience in Information Security and/or Threat Intelligence. Demonstrated experience in technical threat analysis, research, and in-depth knowledge of TCP/IP and networking protocols are required. Proficiency in scripting (Python preferred) and familiarity with CTI research tools like Maltego, Jupyter Notebook, and Elastic Stack are necessary. Proven experience applying structured analytical techniques, intelligence methodologies, and threat modeling frameworks such as MITRE ATT&CK and the Cyber Kill Chain is essential. A detailed understanding of existing APT groups' past activities, TTPs, motivations, and targeting patterns, along with experience in open-source intelligence-gathering tools, is also required.
The Senior Threat Intelligence Analyst will lead efforts to track state-sponsored APT campaigns, mentor peers in intrusion analysis, and represent Insikt Group externally. Responsibilities include conducting proactive research on APT activity, synthesizing technical datasets, and producing high-impact intelligence reports focused on Russian state-sponsored cyber threats. This role involves establishing methods to track APT campaigns, hunting for threat actor infrastructure, and deploying detection mechanisms for command-and-control infrastructure. The analyst will continuously evaluate and improve threat intelligence workflows, stay updated on evolving APT tradecraft, and collaborate with geopolitical and regional analysis teams. They will also propose and evaluate new data sources and analytical methods, support customer intelligence needs through Analyst-on-Demand, and collaborate with engineering and data science teams for platform integration.
Provides machine-readable threat intelligence solutions
Recorded Future provides threat intelligence in the cybersecurity industry by gathering and analyzing information about potential threats to organizations. Their intelligence is delivered in a machine-readable format, making it easy for clients like threat analysts and security teams to integrate with their existing systems. Unlike competitors, Recorded Future focuses on partnerships with Value Added Resellers (VARs) to enhance their offerings and provide comprehensive support. The company's goal is to help organizations lower the risk of cyber attacks through effective threat intelligence.