Senior Threat Intelligence Analyst
Posted 1hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Senior threat intelligence analyst researching cyber threats for Team Cymru, an internet threat intelligence company. Analyzing malicious infrastructure, producing intelligence reports, and guiding detection and analytics tooling.
Responsibilities:
- Conduct proactive research into threat actors, malware families, campaigns, and evolving TTPs
- Investigate and present operational and strategic intelligence, including attribution, motivation, capability, and geopolitical context
- Lead short- and long-term threat tracking projects and identify intelligence gaps
- Evaluate and share tools, methodologies, and best practices for understanding adversary TTPs
- Perform network traffic and infrastructure analysis using global datasets
- Analyze PCAP, NetFlow, passive DNS, open ports, certificates, and other datasets to map malicious infrastructure
- Identify and refine IOCs and threat actor TTPs and translate them into automated tracking mechanisms
- Triage and respond to customer requests with tailored written technical threat intelligence reports
- Ensure intelligence products meet analytic standards and contain actionable conclusions
- Conduct peer reviews of colleagues' reporting
- Collaborate on analytical tools, data analytics systems, research methodologies, and analysis automation
- Support threat detection and data acquisition teams with signature development and telemetry collection priorities
- Participate in working groups, industry events, and community collaboration as a Team Cymru representative
Requirements:
- 5+ years of experience as a threat intelligence analyst, network forensics analyst, or IT security analyst
- Bachelor's degree in Computer Science, Computer Engineering, Cybersecurity, or equivalent is preferred
- Exceptional oral and written communication skills
- Ability to produce customer-facing intelligence reports under time pressure
- Experience using structured analysis techniques, estimative language, and confidence levels is preferred
- Proven track record leading complex analytical projects or investigations
- Ability to manage multiple concurrent work streams
- Strong analytical, deductive reasoning, and critical thinking skills
- Ability to work effectively within a distributed, remote team environment
- Experience tracking APT, nation-state, or cybercriminal actors
- Outstanding network infrastructure and traffic analysis skills: PCAP, NetFlow, PDNS, open ports, and certificates
- Deep working knowledge of IP networking and internet services: DNS, HTTP/HTTPS, TLS, VPNs, and BGP
- Knowledge of operating system concepts, IOCs, and host- and network-level detection architectures
- Working proficiency in SQL and querying and analyzing large disparate datasets
- Strong familiarity with common OSINT platforms and research techniques
- Occasional travel within the UK and internationally is required
- Programming or scripting proficiency, preferably Python, is highly desirable
- Familiarity with AI systems, Linux servers, malware analysis, YARA, Zeek, Suricata, sandbox reporting, reverse engineering tools, and internet infrastructure operations is highly desirable
Benefits:
- Collaborative, mission-driven culture
- Opportunity to work on global cybersecurity and threat intelligence
- Participation in exclusive conferences, industry events, working groups, and community collaboration
- Remote work
- Occasional travel within the UK and internationally for customer workshops, industry events, and team meetings


















