Jobs

Senior Emerging Threat Intelligence Analyst


Job details
  • Recorded Future
  • London
  • 4 months ago

With 1,000 intelligence professionals, over $300M in sales, and serving over 1,800 clients worldwide, Recorded Future is the world’s most advanced, and largest, intelligence company!

We are seeking a uniquely talented individual who combines the technical acumen of a Cyber Threat Hunter with the expressive skills of a Technical Writer to work as anEmerging Threat Intelligence Analyst. This individual will be a critical component of Recorded Future’s Insikt Group, and will be a point person for cross-team collaboration both throughout Insikt Group as well as with Recorded Future’s Attack Surface Intelligence Quick Reaction Team (QRT). This individual will aid in the identification, assessment, and communication of new and emergent threats in the cybersecurity landscape, specifically vulnerability intelligence and detection.

Responsibilities

Vulnerability Analysis:You are tasked with the prompt identification, thorough analysis, and comprehensive assessment of emerging cybersecurity threats, specifically recently disclosed or exploited vulnerabilities. Your technical prowess will be crucial in ensuring our preparedness for potential risks and understanding the implications of prompt and thorough analysis of high-impact vulnerabilities. Threat Analysis: You are tasked with the production and review of intelligence summaries accessible to all Recorded Future clients. These summaries will detail a variety of cyber threat events, including recent cyber attacks and adjustments in known threat groups’ tactics, techniques, and procedures (TTPs).Technical Authorship:Utilizing your skill in making complex concepts accessible, you will convert intricate technical insights into engaging and easily understandable blog posts, client disclosures, and Insikt Notes. Each publication should comprehensively address the nature of the threat, its potential impact, suggested mitigation strategies, and a succinct summary for quick referencing.Detection Engineering:Design and develop Nuclei templates for vulnerability scanning, ensuring these templates are tailored to detect new and emerging vulnerabilities efficiently. Develop custom lab environments and proof-of-concept code based on specific vulnerability signatures and behaviors. Maintain an up-to-date repository of these templates, and continually refine them to improve detection accuracy and performance. This involves creating test cases, simulating attack scenarios, and verifying that the templates correctly identify vulnerabilities without producing false positives.Research Collaboration:You will partner with teams within Insikt Group to augment our collective understanding of emergent threats and vulnerabilities. This collaborative exploration will subsequently inform and enhance our proactive protective measures.Cross-team Collaboration: You will be responsible for working on projects across multiple research teams within Insikt Group and QRT with weekly content production and tight deadlines. Detailed Documentation:Your role involves meticulous record-keeping, noting intricate details of identified vulnerabilities, methodologies of discovery, and potential implications. This comprehensive record aids in understanding the nature of threats and planning appropriate responses.Continual Professional Development:Stay abreast of the latest advancements in cybersecurity trends, threat tactics, and research methodologies, ensuring our collective knowledge remains current and comprehensive.

Qualifications

A degree in Cybersecurity, Computer Science, Information Technology, or a related discipline. A minimum of 3 years of substantial experience in cybersecurity, with a focus on threat detection, penetration testing, or vulnerability assessment. A solid grasp of fundamental cybersecurity principles, attack trajectories, and techniques for vulnerability analysis. Demonstrable experience researching and analyzing new cyber threats across either a) multiple industries or b) multiple timeframes (e.g., both weekly and quarterly) Demonstrable experience deploying known vulnerable infrastructure within a lab environment for analysis. Demonstrable experience creating and authoring Nuclei templates for vulnerability identification and validation. Practical experience using common threat intelligence analysis models such as MITRE ATT&CK, D3FEND, the Diamond Model, and the Cyber Kill Chain Practical experience with network and web application penetration testing tools such as, Burp Suite, NMap, Fiddler, and Wireshark Familiarity with and use of common cyber threat intelligence tools such as DomainTools, VirusTotal, SHODAN, etc. Demonstrable experience in technical writing, showcasing an ability to translate complex technical concepts into engaging, reader-friendly content. Demonstrably strong writing ability, to be assessed via a writing sample A meticulous attention to detail, underscoring a commitment to accuracy and thoroughness in all aspects of work. Capable of functioning effectively within a team as well as independently.

Preferred but not required:

Relevant industry certifications such as OSCP, OSWA, GWAPT, Pentest+, or equivalent. Familiarity with scripting and programming languages such as YAML, Python, Golang, Javascript, C, etc.  Prior experience within a quick reaction or incident response team environment. Practical experience with malware detections, including YARA, Sigma, and Snort

Why should you join Recorded Future?
Recorded Future employees (or “Futurists”), represent over 40 nationalities and embody our core values of having high standards, practicing inclusion, and acting ethically. Our dedication to empowering clients with intelligence to disrupt adversaries has earned us a 4.8-star user rating from Gartner and more than 45 of the Fortune 100 companies as clients.

Sign up for our newsletter

The latest news, articles, and resources, sent to your inbox weekly.

Similar Jobs

Senior Threat Researcher -Unit 42 (Clearance Required) -

Job DescriptionYour CareerAs a Unit 42 National Security Team (NATSEC) team member, you will work closely with a globally distributed team of vulnerability researchers, reverse engineers, and threat intelligence analysts. You will be embedded in a customer environment, where you will track advanced persistent threats in support of sensitive customer...

Palo Alto Networks London

Strategic Cyber Threat Intelligence Analyst

Job Posting Title:Strategic Cyber Threat Intelligence Analyst, Vice PresidentState Street is seeking a strategic cyber threat intelligence analyst to conduct all-source cyber intelligence analysis and production within the global Cyber Threat Intelligence (CTI) team. The ideal candidate will exhibit an innovative mindset and proven capacity for identifying, analyzing, and reporting...

State Street London

Threat Intelligence Specialist

Your newpanyA reputable telmunications client is looking for a Threat Intelligence Specialist to join the wider team. You must have hands-on experience of working in this field at least a minimum of 4–5 years+ in post. You will be working with the wider team - e nsuring delivery of the...

hays-gcj-v4-pd-online Basingstoke

Senior Analyst, Cyber Defence

The Senior Analyst, Cyber Defence will support the cybersecurity response program by consistently delivering timely, actionable, and relevant threat intelligence to enable the improvement of McDonald’s security posture. The Senior Analyst, Cyber Defence is responsible for collecting, analysing, and disseminating cyber threat intelligence. These capabilities will include the timely collection...

McDonald's London

Senior Cybersecurity Analyst

Be You - Our people create our best Plexus.Ingrained in our culture of inclusion is the philosophy that each individual offers diverse perspectives, backgrounds and experiences that create great outcomes when we are united as a team.We embrace the differences of all our colleagues, celebrate diversity and welcome applications from...

Plexus Livingston

Senior Security Analyst (WFH) - Financial Org

RoleDo you want to be a Security Analyst working solely with a banking sector client?Do you envision yourself:As a Senior Security Analyst dedicated to empowering the banking sector by wielding cybersecurity prowess?You’ll have the opportunity to:Immerse yourself in the exclusive realm of banking cybersecurity, focusing solely on safeguarding financial domains....

Hamilton Barnes London