Threat Intelligence Analyst
Role details
Job location
Tech stack
Job description
The Threat Intelligence Analyst will work in our Cyber Fusion Centre, which is responsible for the protection, detection and response capabilities used to safeguard our business from cyber threats. You will act as the subject matter expert for cyber threats, scrutinizing the digital landscape to detect emerging threats and vulnerabilities. You will be responsible for gathering, analysing and disseminating intelligence from multiple sources regarding potential and actual cyber threats that can be used to inform and support our cyber decision-making processes. The role is essential in anticipating and countering cyber-attacks before they can inflict damage on our business. You will work closely with both our Red and Blue Teams to continuously improve our detection and response capabilities, identifying vulnerabilities and control gaps to ensure we can pre-empt emerging threats and plan improvements to our cyber defences. You will play a pivotal role in defending our business from cyber threats. By continuously monitoring, analysing and actioning intelligence, you will be on the front line of protecting our business assets and interests from harm. The role is based in either York (UK) or Lisbon (Portugal) and is a permanent position. Travel to other team locations will be required as necessary., * Manage the end-to-end intelligence lifecycle, including the development and maintenance of a clear and comprehensive set of intelligence requirements to support our overall business objectives.
-
Collect data on potential threats from various sources, including open source (OSINT), human intelligence (HUMINT), technical intelligence, proprietary intelligence feeds, and dark web monitoring.
-
Develop and continuously maintain a pipeline of new intelligence sources to integrate with our Fusion Centre that support our overall intelligence requirements.
-
Research, analyse and evaluate the patterns, trends and anomalies needed to assess the potential impact of threats to our business.
-
Use specialised tools and techniques to gather relevant security information and intelligence, and keep up-to-date with the latest threat vectors.
-
Prepare detailed reports and briefings for various stakeholders outlining the nature of threats, their potential impact and recommended mitigation approach.
-
Support live incident response by analysing the threat, determining it's origin and motivation and suggesting rapid response actions that can be used to contain the threat and potential impact.
-
Work with external entities such as government agencies and industry groups to share threat
-
intelligence, and enhance the collective understanding and response to cyber threats.
-
Stay ahead of cyber threats by tracking their evolution, predicting future attack trends and providing insight to support the development of our overall cyber strategy.
-
Conduct training sessions and awareness initiatives to educate our business community about threat detection and response techniques.
-
Use threat intelligence to develop and maintain our attack models used in the Fusion Centre.
-
Generate strategic, ad-hoc (tactical) and operational intelligence products as required.
-
Evaluate and grade intelligence sources to ensure we are only acting on reliable data.
Requirements
- Ideally 2yrs+ experience in a threat intelligence role, preferably with a MSSP, Government agency or similar financial services organisation.
- Knowledge of the intelligence lifecycle.
- Comprehensive knowledge of common hacking techniques and the latest cyber threats.
- Good working knowledge of using cyber threat intelligence and attack modelling frameworks.
- Excellent research and analytical skills with the ability to work under own initiative.
- Highly inquisitive and analytical, with ability to clearly separate facts from opinions.
- Good presentation and report writing skills.
- BSc or MSc in Cybersecurity is desirable.
- Industry recognised qualifications such as GCTI and CCTIM and GPEN are desirable.