Associate Principal Cyber Threat Intelligence Analyst

5 hours, 27 minutes ago
Full-time
Mid Level
Cybersecurity
Dragos

Dragos

Dragos is an industrial cybersecurity company focused on safeguarding civilization by securing industrial assets across vertical industries. Their integrated software platform provides critical visibility into ICS and OT networks, enabling clients in p...

Professional Services
251-1K
Founded 2016
$438M raised

Description

  • Directly support the client’s ICS/OT cyber threat intelligence needs in high-stakes national security contexts.
  • Lead ICS/OT cyber threat intelligence research, analysis, and threat hunting using proprietary and commercial resources.
  • Perform both freeform and hypothesis-driven hunts by analyzing network traffic and industrial protocols for anomalous behavior.
  • Establish baseline OT asset and network behaviors across Singapore’s critical infrastructure using Dragos Platform, Synapse, and related tools.
  • Contextualize ICS/OT threats and risks, and provide guidance on best practices and mitigations.
  • Translate hunt results into MITRE ATT&CK for ICS mappings and confidence-based assessments for non-technical stakeholders.
  • Support the client during incident response engagements and exercises.
  • Develop industry-focused technical and strategic ICS/OT CTI content.
  • Provide feedback to internal Dragos teams to improve intelligence impact across the organization.

Requirements

  • Must be a Singapore citizen and have an active Security Clearance.
  • Minimum 4 years of cyber threat intelligence experience using multiple data sources such as NetFlow, open-source intelligence, SIEMs, and malware repositories.
  • Hands-on threat hunting experience, including packet capture analysis and industrial protocol inspection.
  • Strong expertise in both freeform and hypothesis-driven threat hunting methodologies.
  • Experience in a customer-facing role with the ability to manage stakeholders independently and effectively.
  • Strong technical and strategic writing skills for CTI products, confidence-based assessments, and threat modeling frameworks such as Diamond Model of Intrusion Analysis.
  • Proficiency with data aggregation, hunting, and analysis tools such as Synapse.
  • Experience leveraging AI/LLM resources in CTI workflows.
  • Deep knowledge of ICS/OT threats across industrial verticals, including adversary TTPs, PLCs, HMIs, RTUs, and network protocols and topologies (preferred).
  • Ability to independently scope, develop, and deliver CTI analysis using frameworks such as MITRE ATT&CK for ICS, D3FEND, and ICS Cyber Kill Chain (preferred).

Benefits

  • Salary of 180,000 SGD.
  • Competitive equity package.
  • Comprehensive benefits plan.
  • Remote-first work environment.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Security Operations Analyst II

Alphasense 51-250 Industrial Conglomerates

AlphaSense is hiring a Security Operations Analyst II to join its fully remote Security Operations team in Canada and help triage alerts, investigate incidents, and improve detection coverage.

AWS DNS GCP SIEM TCP/IP TLS
1 day, 5 hours ago

CyberSecurity Specialist

Avertium 251-1K IT Services

Avertium is hiring a Cyber Security Specialist to support 24x7 SOC monitoring and incident response for mid-market and enterprise clients.

Cybersecurity DNS Encryption HIPAA HTTP SIEM TCP/IP
1 day, 5 hours ago

Security Operations Engineer

Mesh 51-200 financial services

Mesh is hiring a Security Ops Engineer to design, operate, and respond to security controls across its infrastructure and systems as it builds payments infrastructure for the next era of the global economy.

AWS Azure Datadog Docker GCP Kubernetes Network Security Python SIEM Splunk
2 days, 4 hours ago

Security analyst

Gravity Payments 51-250 Diversified Financial Services

Gravity Payments is seeking a Security Analyst to protect and improve security operations across cloud, endpoint, identity, SaaS, and corporate environments.

AWS JIRA Linux macOS Network Security Penetration Testing PowerShell Python Shell Scripting SIEM
2 days, 4 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers