Principal Threat Intelligence Consultant

1 day, 10 hours ago
Full-time
Senior
Cybersecurity
GuidePoint Security

GuidePoint Security

GuidePoint Security is a trusted cybersecurity consulting firm that provides expertise, solutions, and services to help organizations make informed decisions and minimize risks. Their elite team of experts offers holistic perspectives on cybersecurity,...

Internet Software & Services
251-1K
Founded 2011

Description

  • Serve as a technical resource to deliver threat intelligence results for clients across multiple sectors.
  • Help clients mature their threat intelligence programs through workshops and documentation.
  • Research emerging threats and provide malware analysis support.
  • Deliver threat briefs to customers and senior leadership.
  • Assist the DFIR team on investigations as needed and provide actionable intelligence.
  • Mentor junior analysts and provide leadership within the GRIT team.
  • Author client deliverables tailored to technical and managerial audiences, including findings, recommendations, business impact, and remediation strategies.
  • Use automation, orchestration, and scripting to reduce manual work and improve efficiency.
  • Contribute to the integration of open-source and commercial tools to improve GRIT processes and procedures.
  • Build and maintain strong client relationships through support, information, and guidance.

Requirements

  • 5+ years of experience performing threat intelligence analysis.
  • 7+ combined years of IT and information security experience.
  • Prior experience in a consulting services role (preferred).
  • Experience implementing or improving operational processes or procedures in the intelligence analysis lifecycle (preferred).
  • Proficiency hunting APT data using open-source or commercial cyber threat tools or repositories such as VirusTotal, Passive Total, Threat Miner, or Maltego.
  • Core capabilities in network traffic analysis, host forensics, malware handling/triage, and log review.
  • Experience with security solutions including EDR, SIEM, NDR, FW, NGAV, Velociraptor, and OSQuery.
  • Strong ability to correlate data and research using repositories such as VirusTotal, Domaintools, and Threatminer.
  • Intermediate ability to present technical information and analysis to audiences of up to 50 people on a quarterly basis.
  • Experience with programming languages including PowerShell, Python, BASH, Go, or similar.
  • Experience with enterprise cloud technologies such as Amazon Web Services, G Suite, Office 365, and Azure.
  • Relevant certifications such as GCIA, GCIH, GDAT, GCFE, or GFCA (preferred).
  • Awareness of attacker techniques, advanced threat groups, and intelligence integration into investigations.
  • Ability to apply formal intelligence analysis methods and make confidence-based attribution assessments while identifying analytic bias.

Benefits

  • Remote workforce primarily, U.S.-based only.
  • Group medical insurance options with significant employer premium contributions.
  • Group dental insurance with employer-paid employee coverage and partial family coverage.
  • 12 corporate holidays plus a Flexible Time Off (FTO) program.
  • Healthy mobile phone and home internet allowance.
  • Eligibility for retirement plan participation after 2 months at open enrollment.
  • Pet benefit option.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

vCISO (Mexico)

DYOPATH 251-1K Internet Software & Services

DYOPATH is hiring a remote Security Consultant (vCISO) in Mexico to serve as a strategic and hands-on cybersecurity advisor for enterprise clients, helping shape security programs and strengthen client security posture.

Cybersecurity
1 day, 10 hours ago

Sr. Staff Technology Controls Architecture & Assurance Lead

Archer 251-1K Construction & Engineering

Archer is seeking a Senior Staff Technology Controls & Assurance Lead to own governance, risk, compliance, and security assurance work supporting its electric aircraft, defense programs, and FAA certification efforts.

Confluence JIRA Power BI Python SIEM Splunk SQL Tableau
1 day, 10 hours ago

Associate Principal Red Team Consultant

UltraViolet Cyber 501-1000 Computer and Network Security

UltraViolet Cyber is hiring a remote Associate Principal Red Team Consultant to lead client-facing offensive security engagements that simulate advanced adversaries across enterprise, cloud, and social engineering attack surfaces.

Active Directory AWS Azure C# DNS GCP Go Metasploit Penetration Testing PowerShell Python SIEM
2 days, 10 hours ago

Cybersecurity Executive

PartnerOne 51-250 Media

Partner One is seeking a cybersecurity executive to lead a global business serving enterprise, government, defense, and critical infrastructure customers, with responsibility for growth, operational performance, product direction, and long-term value creation.

Cybersecurity
3 days, 9 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers