Cyber Threat Intelligence Specialist

3 weeks, 6 days ago
Full-time
Senior
Cybersecurity
Mews

Mews

Mews offers a cloud-native hospitality management system designed to automate operations, enhance revenue, and deliver exceptional guest experiences for modern hoteliers.

Consumer Services
251-1K
Founded 2012
$232M raised

Description

  • Design and implement Mews' CTI service end-to-end, including intelligence requirements, lifecycle management, collection, enrichment, dissemination, and continuous improvement.
  • Track threat actors, campaigns, and TTPs relevant to SaaS platforms and the hospitality and payments ecosystem.
  • Convert raw intelligence into actionable outputs for detection engineering, threat hunting, and incident response.
  • Act as a trusted intelligence partner during security incidents by providing attacker context, likely objectives, and forward-looking risk assessments.
  • Identify opportunities to automate and enrich intelligence workflows, including AI-assisted techniques where they improve speed or coverage.
  • Design AI-assisted workflows that can be adopted by the wider team, such as enrichment pipelines, TTP classification, and validated threat landscape summaries.
  • Work closely with Security Engineering, Platform Engineering, Legal, and Product teams.
  • Help shape how intelligence is surfaced to customers as a trust capability as the program matures.

Requirements

  • Hands-on CTI experience in SaaS, cloud, or technology-centric environments.
  • Track record of building or significantly evolving a CTI program.
  • Experience tracking threat actors, campaigns, and TTPs relevant to online platforms and identity-centric attacks such as credential phishing, account takeover, and API abuse.
  • Demonstrated ability to translate intelligence into operational outcomes such as detection rules, hunting hypotheses, IR support, and control improvements.
  • Experience with intelligence lifecycle management from requirements to feedback.
  • Ability to define priority intelligence requirements (PIRs) aligned to business context and risk.
  • AI Fluency Level 3, or equivalent hands-on experience redesigning workflows with AI.
  • Working knowledge of Russian for threat actor tracking and underground ecosystem monitoring (nice to have).
  • Experience with MISP, threat intelligence platforms, or integrating IOC/TTP feeds into Splunk or similar SIEM (nice to have).
  • Familiarity with RH-ISAC (nice to have).

Benefits

  • Salary range of €57,000–€90,000 in Spain, 1,191,500–2,000,000 Kč in Czechia, or £62,500–£105,800 in the UK.
  • Unlimited paid holiday.
  • Company share program.
  • Paid parental leave: 6 months fully paid for primary caregivers and 2 months for secondary caregivers after one year of service.
  • Annual learning budget of €300, with more for high performers.
  • Monthly EDGE time for Explore, Develop, Grow, and Elevate.
  • Work-from-anywhere policy with flexibility to work abroad for a few weeks each year.
  • Flexible hybrid working options.
  • Home office setup budget and monthly work-from-home allowance.
  • Claude tokens to help automate workflows and build smarter ways of working.
  • Additional local benefits such as healthcare, retirement plans, team events, and socials.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Security Operations Analyst - Weekend 4x10 Shift

Huntress 251-1K Professional Services

Huntress is seeking a remote US Security Operations Center Analyst to investigate, respond to, and remediate cyber intrusions while supporting customers and improving SOC detection capabilities.

Active Directory AWS Azure Bash Cybersecurity JavaScript Linux macOS PHP PowerShell Python Ruby TCP/IP
4 hours, 29 minutes ago

Security Intern

Crest Industries 51-250 Electrical Equipment

Crest Operations is seeking a Security Intern to support its Enterprise Security & Risk team with cybersecurity operations across manufacturing, cloud, business, and enterprise technology environments.

Active Directory Azure Cybersecurity Power BI SIEM
5 hours, 29 minutes ago

Information Security Analyst

EnableComp 251-1K Insurance

The Security Analyst at EnableComp supports the healthcare revenue cycle company’s security program by maintaining compliance controls, coordinating assessments, and helping protect systems, networks, and information.

Azure Cybersecurity HIPAA
5 hours, 44 minutes ago

Vulnerability Manager

BeyondTrust 1K-5K Professional Services

BeyondTrust is hiring a fully remote, North America–based Vulnerability Manager to operate its product vulnerability management program, with a primary focus on FedRAMP 20x compliance and onboarding vulnerability management for new SaaS products.

AWS Azure CI/CD Cybersecurity GCP Kubernetes Python
1 day, 4 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers