Cyber Threat Intelligence (CTI) Analyst

1 hour, 39 minutes ago
Full-time
Senior
Cybersecurity
AI2CYBER

AI2CYBER

AI2CYBER is a leading cybersecurity company that leverages AI technology to provide dynamic threat mitigation solutions. With a deep understanding of the constantly evolving security landscape, we proactively stay ahead of emerging challenges and equip...

Internet Software & Services
Founded 2014

Description

  • Analyze threat actor activity, campaigns, malware families, and evolving adversary TTPs.
  • Produce actionable intelligence reports for SOC teams, incident response, and leadership.
  • Conduct threat landscape assessments and sector-specific risk analysis.
  • Track and profile APT groups, financially motivated actors, and emerging threats.
  • Extract, correlate, and enrich IOCs such as domains, IPs, hashes, and infrastructure patterns.
  • Map adversary techniques to MITRE ATT&CK and analyze malware behavior, sandbox outputs, PCAPs, logs, and telemetry.
  • Support detection rule development using Sigma, YARA, Splunk, and EDR queries.
  • Work with STIX/TAXII feeds and threat intelligence platforms to support ingestion, normalization, and correlation.
  • Contribute to intelligence scoring models and validate intelligence with internal telemetry and honeypot data.
  • Support SOC investigations, incident response, purple-team exercises, and present findings to technical and executive stakeholders.

Requirements

  • This position is available only for Greek residents.
  • Strong understanding of adversary TTPs, the Kill Chain, MITRE ATT&CK, and IOC lifecycle/enrichment techniques.
  • Experience with threat intelligence platforms, malware analysis reports, log analysis tools such as Splunk or ELK, and OSINT collection techniques.
  • Knowledge of STIX/TAXII, YARA or Sigma rule creation, network protocols, and traffic analysis.
  • Experience with Windows and Linux security telemetry.
  • Scripting capability, with Python preferred, for data processing and automation.
  • Preferred experience tracking specific threat actors such as APT28, Lazarus, or FIN7.
  • Preferred familiarity with exploit development trends and CVE weaponization timelines.
  • Preferred experience with honeypots, telemetry-driven intelligence, ransomware ecosystems, and initial access brokers.
  • Nice-to-have certifications include GIAC GCTI, GCIA, GCED, OSCP, OSCE, CISSP, or SANS CTI-related certifications.

Benefits

  • Highly competitive salary reviewed upward on a regular basis.
  • Work from home with a performance-focused, remote-friendly setup.
  • Participation in state-of-the-art projects, tech challenges, and large-scale initiatives.
  • Personal and professional development opportunities with industry experts.
  • Continuous learning with access to board resources.
  • Structured onboarding plan and training for a smooth induction.
  • Equipment support to ensure you have the tools needed to work effectively.
  • No dress code for maximum comfort.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

L1 Analyst

Appgate 251-1K Professional Services

GFC Operations is hiring an L1 Analyst to serve as the first line of defense, investigating and mitigating cybersecurity events for clients in a highly analytical, curiosity-driven operations environment.

Cybersecurity HTML Linux
30 minutes ago

Maryland State Board Of Elections: CyberSecurity Internship

Security Intern for the University of Maryland’s Information Security team, supporting risk assessments, vulnerability management, and application security work under the supervision of the CISO.

Cybersecurity
2 hours, 10 minutes ago

Insider Threat Analyst

SpaceX 10K-50K Aerospace & Defense

SpaceX is hiring an Insider Threat Analyst to investigate anomalous activity and help protect its personnel, assets, intellectual property, and operations across a fast-paced advanced technology environment.

Splunk
2 hours, 23 minutes ago

US PSOC Manager

Nebius 51-250 Internet Software & Services

Nebius is seeking a global SOC and Command & Control governance leader to define and oversee the operating framework, doctrine, training, and quality standards for security operations across its worldwide sites.

SOC
4 hours, 54 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers