Principal Threat Intelligence Analyst
Strategic and Persistent Threats, Insikt Group, Recorded Future
This Role:
As an analyst for Insikt Group’s Strategic and Persistent Threats (SPT) team, you will contribute to APT campaign tracking initiatives, support our Analyst on Demand service, mentor your colleagues on all things intrusion analysis, and represent Insikt Group’s research externally. This role supports proactive research and monitoring efforts into threat actor infrastructure, tools, and TTPs, as well as client-driven finished intelligence reports and requirements. Your research will be largely focused on state-sponsored threats emanating from China.
What You’ll Do:
Synthesize multiple technical datasets to derive novel insights and reporting related to state-sponsored APT activity tied to China;
Establish methods of tracking APT campaigns using a combination of network, intrusion, and malware analysis skills;
Support the fulfillment of client priority intelligence requirements via Recorded Future’s Analyst on Demand service;
Mentor your colleagues on intrusion analysis and threat intelligence best practices;
Identify new datasets to ingest and propose new analytics that can be developed to improve and/or automate portions of the intelligence cycle;
Serve as a subject matter expert on Chinese state-sponsored threat activity;
Work with the Advanced Reversing, Malware, Operations, and Reconnaissance team to identify, prioritize, and deploy various detection mechanisms for command & control infrastructure, malware families, and threat actor groups of interest;
Stay on top of developments within the APT threat landscape and track key developments by following publications, blogs, and mailing lists;
Represent the SPT team’s research (emphasis on China state-sponsored research) externally to journalists and media (anonymously or otherwise) in collaboration with Recorded Future’s public relations team;
Work with engineering and data science teams to ensure relevant data and analytics are correctly designed, developed, and deployed in the Recorded Future platform.
What You’ll Bring (Required):
BA/BS or equivalent experience in Computer Science, Computer Engineering, Information Security, Security Studies, Intelligence, or a related field
6+ years of experience in Information Security and/or Threat Intelligence
Demonstrable experience conducting technical threat analysis and research
Demonstrable experience with structured analytical techniques, the intelligence cycle, and intelligence writing techniques and methodologies
Proven expertise in clustering and tracking multiple state-sponsored activity groups using techniques such as the Diamond Model of Intrusion Analysis
Scripting capabilities in Python (preferred), Go, C, C++, or Java
Familiarity with platforms & software such as Maltego, Jupyter Notebook, the ELK Stack, and Excel, among other common cyber threat intelligence research platforms
In-depth knowledge of TCP/IP and other networking protocols and datasets relevant to intrusion and network infrastructure analysis
Experience developing intelligence requirements
Experience working directly with clients
Experience with open-source intelligence-gathering tools and techniques
Excellent written and verbal communication; ability to convey complex technical and non-technical concepts
Excellent interpersonal and teamwork skills; ability to work with globally distributed team members
Highly Desirable Skills/Experience (not required):
MA/MS or equivalent experience in Computer Science, Computer Engineering, Information Security, or a related field
Experience writing network and endpoint detection signatures
Experience with Windows, iOS, Android, MacOS or malware analysis
Proficiency in a high-priority foreign language: preference for Chinese, Russian, Farsi, or Korean.
$50,000 — $100,000/year
To apply for this job, please visit the application page
