> Markdown version of [/jobs/ext/2287610-cyber-threat-intelligence-specialist](https://www.wearedevelopers.com/jobs/ext/2287610-cyber-threat-intelligence-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Threat Intelligence Specialist - **Company:** Mews - **Location:** Spain (Remote available) - **Salary:** €57,000.0 - €90,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Confluence, Software as a Service, Cloud Computing, Cyber Security, Computer Telephony Integration, Payment Systems, Intrusion Detection and Prevention, Phishing, Security Information and Event Management, Web Platforms, Large Language Models, Cyber Threat Analysis, Cybercrime, Splunk - **Published:** August 29, 2026 - **Apply:** https://www.jobleads.com/es/job/e8de819e0010e9b0ba079d73cc9160009 ## About the Role * Hands-on CTI experience in SaaS, cloud, or technology-centric environments, with a track record of building or significantly evolving a CTI program rather than just operating within one * Experience tracking threat actors, campaigns, and TTPs relevant to online platforms and identity-centric attacks (credential phishing, account takeover, API abuse) * Demonstrated ability to translate intelligence into operational outcomes: detection rules, hunting hypotheses, IR support, control improvements * Intelligence lifecycle management from requirements to feedback, with the ability to define priority intelligence requirements (PIRs) aligned to business context and risk * AI Fluency Level 3, or equivalent hands-on experience redesigning workflows with AI and building approaches others can follow, * Working knowledge of Russian for threat actor tracking and underground ecosystem monitoring * Experience with MISP, threat intelligence platforms, or integrating IOC/TTP feeds into Splunk or similar SIEM * Familiarity with RH-ISAC (the Retail and Hospitality Information Sharing and Analysis Centre) ## Description Let's get into the specifics. It's impossible to capture every nuance of a role - especially at a rapidly growing company like Mews - but if we had to distil it into a job description (which we do because this is a job description), it would be this: Building a threat intelligence capability from scratch is genuinely rare: most security roles inherit someone else's tooling, someone else's playbooks, someone else's definition of what "good" looks like. This one doesn't. As Mews' first Cyber Threat Intelligence Specialist, you will design and operationalise the CTI function within our Security Operations team, setting the intelligence requirements, the collection and analysis approach, and the feedback loops that will shape how the whole team detects and responds to threats. The hospitality industry is a specific and underserved target for credential phishing, account takeover, and ransomware, and Mews processes data for thousands of properties globally. There is real risk here, and real opportunity to reduce it. You will join a Security Operations team that operates as a product security function, not a traditional IT security shop. Your work feeds directly into detection engineering, threat hunting, and incident response, and as the program matures you will help shape how intelligence can be surfaced to Mews customers as a trust capability. You will work closely with Security Engineering, Platform Engineering, Legal, and Product teams, and you will report to Roger Ribas, the Director of Security Operations. What you would do * Design and implement Mews' CTI service end-to-end: intelligence requirements, lifecycle management, collection, enrichment, dissemination, and continuous improvement * Track threat actors, campaigns, and TTPs (tactics, techniques, and procedures) relevant to SaaS platforms and the hospitality and payments ecosystem * Convert raw intelligence into actionable outcomes for detection engineers, threat hunters, and incident responders, with a strong bias toward intelligence that changes decisions rather than just informs them * Act as a trusted intelligence partner during security incidents, providing attacker context, likely objectives, and forward-looking risk assessments * Identify opportunities to automate and enrich intelligence workflows, including applying AI-assisted techniques where they meaningfully improve speed or coverage * AI Fluency Level 3: In this role, that means you have gone beyond using AI tools for your own productivity. You have redesigned how threat intelligence work gets done: building AI-assisted workflows that others on the team can adopt (for example, automated enrichment pipelines, AI-assisted TTP classification, or LLM-supported threat landscape summaries that are rigorously checked and validated before distribution). You actively interrogate what AI gives you, apply your own judgment to catch errors, and document your approaches so they can be replicated and improved * For more information on AI fluency at Mews, please refer to "AI Fluency at Mews: A Comprehensive Guide for Candidates" on Confluence ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [42 x 2 Canvases Later: Two Years, Two Minds, Many Lessons](https://www.wearedevelopers.com/videos/1458-42-x-2-canvases-later-two-years-two-minds-many-lessons) - [Getting under the skin: The Social Engineering techniques](https://www.wearedevelopers.com/videos/38-getting-under-the-skin-the-social-engineering-techniques) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)