> Markdown version of [/jobs/ext/1788596-sr-analyst-cyber-threat-intelligence](https://www.wearedevelopers.com/jobs/ext/1788596-sr-analyst-cyber-threat-intelligence). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Analyst, Cyber Threat Intelligence - **Company:** Wyndham Hotels & Resorts, Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $110,000.0 - $135,000.0 - **Contract:** Franchise - **Skills:** Artificial Intelligence, Cyber Security, Computer Telephony Integration, Intrusion Detection and Prevention, Network Security, Log Analysis, Open Source Intelligence, Phishing, Red Team (Cyber Security), Mitre Att&ck, Malware, Cyber Threat Analysis, Information Technology, Cybercrime - **Published:** July 8, 2026 - **Apply:** https://careers.wyndhamhotels.com/talentcommunity/apply/1406563100/?locale=en_US ## About the Role The individual selected for this role must have experience performing technical analysis of malware, phishing infrastructure, and attacker tooling to extract indicators, TTPs, and other potential attribution signals. This position will involve being deeply informed of commodity cybercrime threats, retail and hospitality specific fraud types, emerging vulnerabilities, and intimate knowledge of various malware families and threat actor tradecraft tooling., * 3+ years of hands-on experience in cyber threat intelligence, threat hunting, intrusion analysis or incident response at an organization facing sophisticated cybercrime adversaries. * Are not afraid to bring new ideas to the table and challenge the status quo. * A passion for cybersecurity, someone who enjoys reading industry news or listening to podcasts. * A strong engineering background, you have built computers, managed networks and maybe even coded a few tools yourself, you don't need to hand requirements to someone else to get something built. * A strong foundation in network security, vulnerability exploitation concepts, and technical threat analysis. * Experience with Threat Intelligence Platforms (TIPs) and a working knowledge of technologies for intelligence integration, including their use within a modern Security Operations Center architecture. * Experience with leveraging the MITRE ATT&CK, MITRE D3FEND, CTI-CMM, Cyber Kill Chain, and other relevant security frameworks and applying them to processes and procedures. * Demonstrate organized, focused research habits, know how to leverage various internet tools to find what you need to know, including leveraging AI-assistance. * Are comfortable performing malware analysis, infrastructure analysis, OSINT, and log analysis to develop and validate your own findings. * Ability to break down complex and technical ideas for a non-technical audience. * Formal technical writing skills and personal experience producing finished deliverables for senior leadership which resulted in action. * Comfortable speaking in front of large audiences and leading calls. * Ability to multi-task and manage time is a must. * Have an existing network in the threat intelligence community and a track record of productive bidirectional sharing., * Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related field preferred but not required. * Certifications (SANS, COMPTIA, ISC2 etc) preferred, not required. ## Description As a member of the Cybersecurity Team, you will be responsible for supporting the cyber threat intelligence program mission, architecture and operation. Successful execution of this program results in the delivery of crucial guidance to a variety of Wyndham teams across various disciplines. The key tenant of this position revolves around research on threat actors and campaigns targeting hotel chains, travel industry partner technologies, and the broader hospitality and retail sectors. The output of that research will be in the production of timely, actionable analysis and recommendations while remaining sensitive to changing business requirements from stakeholders., * Perform regular threat intelligence research into cybercrime and nation state threat actor tradecraft and produce threat intelligence products and profiles based on defined intelligence Requirements for selected stakeholders. Some of these products will be expected to be automated with human-review. * You will support the planning and maintenance of tooling and automated pipelines to collect, enrich, correlate, and operationalize all-source intelligence into our detection and reporting stack. * You will be expected to assist in the triage and review of security events by analyzing malicious artifacts gathered from forensic workflows using static and dynamic analysis techniques. You will also apply your knowledge of in-the-wild threats and TTPs to provide intelligence context for Security Operations and Detection Engineering personnel during triage and incident response operations. * Work alongside peers involved in Detection Engineering and Incident Response to translate intelligence into applicable detection rules, hunting hypotheses, red team and detection validation scenarios and inform incident context. * Build and maintain external intelligence-sharing relationships with peer organizations, RH-ISAC, and other select partners. Attend conferences, vendor Technical or Customer Advisory Boards and other industry events virtually or in-person. ## Related Videos - [Getting under the skin: The Social Engineering techniques](https://www.wearedevelopers.com/videos/38-getting-under-the-skin-the-social-engineering-techniques) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)