Cyber Threat Intelligence (CTI) Analyst

1 month, 2 weeks ago
Full-time
Senior
Cybersecurity
AI2CYBER

AI2CYBER

AI2CYBER is a leading cybersecurity company that leverages AI technology to provide dynamic threat mitigation solutions. With a deep understanding of the constantly evolving security landscape, we proactively stay ahead of emerging challenges and equip...

Internet Software & Services
Founded 2014

Description

  • Analyze threat actor activity, campaigns, malware families, and evolving adversary TTPs.
  • Produce actionable intelligence reports for SOC teams, incident response, and leadership.
  • Conduct threat landscape assessments and sector-specific risk analysis.
  • Track and profile APT groups, financially motivated actors, and emerging threats.
  • Extract, correlate, and enrich IOCs such as domains, IPs, hashes, and infrastructure patterns.
  • Map adversary techniques to MITRE ATT&CK and analyze malware behavior, sandbox outputs, PCAPs, logs, and telemetry.
  • Support detection rule development using Sigma, YARA, Splunk, and EDR queries.
  • Work with STIX/TAXII feeds and threat intelligence platforms to support ingestion, normalization, and correlation.
  • Contribute to intelligence scoring models and validate intelligence with internal telemetry and honeypot data.
  • Support SOC investigations, incident response, purple-team exercises, and present findings to technical and executive stakeholders.

Requirements

  • This position is available only for Greek residents.
  • Strong understanding of adversary TTPs, the Kill Chain, MITRE ATT&CK, and IOC lifecycle/enrichment techniques.
  • Experience with threat intelligence platforms, malware analysis reports, log analysis tools such as Splunk or ELK, and OSINT collection techniques.
  • Knowledge of STIX/TAXII, YARA or Sigma rule creation, network protocols, and traffic analysis.
  • Experience with Windows and Linux security telemetry.
  • Scripting capability, with Python preferred, for data processing and automation.
  • Preferred experience tracking specific threat actors such as APT28, Lazarus, or FIN7.
  • Preferred familiarity with exploit development trends and CVE weaponization timelines.
  • Preferred experience with honeypots, telemetry-driven intelligence, ransomware ecosystems, and initial access brokers.
  • Nice-to-have certifications include GIAC GCTI, GCIA, GCED, OSCP, OSCE, CISSP, or SANS CTI-related certifications.

Benefits

  • Highly competitive salary reviewed upward on a regular basis.
  • Work from home with a performance-focused, remote-friendly setup.
  • Participation in state-of-the-art projects, tech challenges, and large-scale initiatives.
  • Personal and professional development opportunities with industry experts.
  • Continuous learning with access to board resources.
  • Structured onboarding plan and training for a smooth induction.
  • Equipment support to ensure you have the tools needed to work effectively.
  • No dress code for maximum comfort.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Technology Operations Support Analyst

Facet 251-1K Capital Markets

Facet is hiring an IT/Security Operations Analyst to support internal users, manage access and endpoint operations, and help secure the company’s systems in a fast-growing fintech environment.

Cybersecurity JIRA macOS Salesforce
16 hours, 54 minutes ago

Security Analyst, Bug Bounty

Stripe 5K-10K Diversified Financial Services

Stripe is hiring a Security Analyst for its Vulnerability Management team to triage bug bounty reports, coordinate remediation, and improve the effectiveness of its vulnerability response process.

AWS Burp Suite GCP Python Ruby
1 day, 15 hours ago

Associate, Vulnerability Assessment

Coalfire 251-1K Internet Software & Services

Coalfire is hiring a Vulnerability Assessment Associate to identify, analyze, and report security vulnerabilities across systems, networks, and applications while supporting remediation and risk reduction efforts for clients.

AWS Azure Bash Cybersecurity GCP HIPAA PowerShell Python SOC
1 day, 16 hours ago

Information Security Analyst

Media.Monks 5K-10K Media

Monks is hiring an Information Security Analyst to protect customer and company data and support the organization’s security and compliance posture across a global business.

AWS Azure Cybersecurity Encryption GCP Linux macOS OpenID Connect SAML
1 day, 16 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers