Senior Manager, Cyber Threat Intelligence
Senior Manager, Cyber Threat Intelligence
aia digital- Posted 2 hours ago
- Be among the first 10 applicants
Job Description
Responsibilities
- Develop, document, and maintain cyber threat hunting framework.
- Hunt and identify for threat actor groups, techniques, tools and procedures (TTPs)
- Perform threat hunting through analysis of anomalous log data to detect and mitigate cyber threat activities.
- Actively develop threat hunting hypothesis, translating hunt activities into an iterative process, and automating the process of hunting for cyber threats. This includes building Agentic AI capabilities as part of automation.
- Review alerts generated by security monitoring tools and provided recommendations to enhance alerts for more efficient monitoring.
- Provide forensic analysis of network packet captures, DNS, proxies, malware, host-based security, and application logs, as well as logs from various data sources.
- Provide expert investigative support during large scale and complex security incidents.
- Analysis of security incidents to enhance security monitoring and alert catalogue.
- Investigate and validate suspicious events by using open-source and proprietary intelligence sources.
- Document and communicate findings to an array of audiences which includes both technical and executive teams.
- Continuously improving processes and use cases on security monitoring tools.
- Keep up to date with information security news, adversary techniques and threat landscape.
- Support day-to-day operations, ensuring efficient delivery of Cyber Threat Intel services.
Requirements
- Must have a minimum of 5 years of experience in a technical security role in one of the following areas: Cyber Threat Intelligence, Cyber Threat Hunting, Purple Teaming.
- Acquired relevant certifications: GCTI, CCIP, CIA.
- Experience with researching and incorporating Cyber Threat Intelligence findings into threat hunting workflow.
- Knowledge and experience working with MITRE ATTACK framework, Cyber Kill Chain Model or Diamond Model.
- Proficiency in using threat intelligence platforms and OSINT tools.
- Knowledge of malware and threat actor's behavior, and how common protocol and applications work at network level.
- Experience with incident response process, including detecting advanced adversaries, log analysis and malware triage.
- Good understanding in network protocols and system vulnerabilities.
- Knowledge and experience in developing detection signatures (YARA, SNORT)
- Highly capable in producing Threat Advisories and Intelligence Reports for Senior Management in a timely manner.
Communication Requirements
- Excellent verbal and written communication skills, fluent in English.
- Strong interpersonal skills.
- Self-learner with demonstrated ability of understanding and keeping up to date with latest technology.
- Attention to detail and ability to report on key activities and status Analytical capabilities.
- Knowledge of analysis of competing hypothesis (ACH), logical fallacies and cognitive biases to provide solutions to a problem is a plus.
- Familiarity with enterprise controls, related tools and their limitations.
- A team player, with ability to work independently in certain situations.
More Info
Key Skills
Agentic AI capabilities
Purple Teaming
Cyber Threat Intelligence
Malware triage
YARA
Application logs
Cyber Kill Chain Model
OSINT tools
System vulnerabilities
DNS proxies
MITRE ATTACK framework
Network packet captures
Diamond Model
Threat intelligence platforms
Threat Advisories and Intelligence Reports


