Principal Dark Web Collection Analyst

1 month, 2 weeks ago
Full-time
Senior
Data Science and Analytics
Recorded Future

Recorded Future

Recorded Future is the leading threat intelligence platform, empowering organizations to identify and mitigate threats across various domains with real-time, unbiased, and actionable intelligence.

Professional Services
251-1K
Founded 2009
$58M raised

Description

  • Serve as the company-wide subject matter expert on dark web and underground community dynamics.
  • Own strategic collection decisions on which forums, markets, and channels to pursue and where not to invest.
  • Identify, evaluate, and gain access to criminal forums, darknet marketplaces, Telegram channels, and adjacent covert infrastructure within legal and policy boundaries.
  • Develop and maintain collection strategies, personas, and source documentation to sustain access.
  • Partner with engineering to translate research tradecraft into automated collection pipelines.
  • Monitor sources for operational changes such as takedowns, migrations, and rebrands, and adapt collection accordingly.
  • Produce finished intelligence products including actor profiles, source assessments, and analytical summaries.
  • Collaborate with product, PMM, sales, customer success, and research teams as the go-to expert on underground community intelligence.
  • Represent Recorded Future externally through customer-facing blogs, webinars, and public research.

Requirements

  • 5+ years of hands-on dark web threat research with demonstrable collection outcomes across forums, marketplaces, or covert channels.
  • Deep, current expertise in major criminal forums and darknet markets, including access models and community evolution.
  • Proven ability to operate within closed or invite-only communities while maintaining OPSEC and legal compliance.
  • Russian language proficiency at a professional working level.
  • Strong analytical writing skills for concise intelligence products aimed at technical and executive audiences.
  • Comfort operating externally through presentations, webinars, and public-facing writing.
  • Additional language skills relevant to underground communities such as Ukrainian, Romanian, Chinese, Portuguese, or Arabic (preferred).
  • Background in cybercrime research, threat actor tracking, or law enforcement intelligence (preferred).
  • Prior experience at a threat intelligence vendor, CSIRT, law enforcement, or intelligence agency (preferred).
  • Basic Python scripting ability for data parsing and format conversion (preferred).

Benefits

  • Base salary range of $152,000 to $228,500.
  • Eligibility for incentive compensation.
  • Equity eligibility.
  • Medical, dental, and vision insurance.
  • Life insurance.
  • 401(k) retirement plan.
  • Remote work (#LI-Remote).
  • Accommodation support during the application process.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Middle Information Security Access Specialist

GR8 Tech 251-1K IT Services

GR8_TECH is hiring an IAM and access management professional to secure and automate employee access across its global B2B iGaming technology organization.

Active Directory AWS Azure
5 hours, 48 minutes ago

Investigations Analyst

Turing 251-1K Internet Software & Services

Turing is hiring an Investigations Analyst to support its security investigations function by handling fraud and insider-threat cases from initial signal through resolution, protecting the company and its customers.

Python SIEM SQL
6 hours, 3 minutes ago

Investigations Analyst

Turing 251-1K Internet Software & Services

Turing is hiring an Investigations Analyst to support its security investigations function by resolving fraud and insider-threat cases and protecting the company and its customers.

Python SIEM SQL
6 hours, 3 minutes ago

Cyber Threat Intelligence Analyst

Toyota Tsusho Systems 51-250 IT Services

Toyota Tsusho Systems US, Inc., a Toyota group technology and mobility company, is hiring a CTI Analyst to conduct cyber threat intelligence operations, malware and TTP research, and supporting engineering that strengthens global security defenses.

Cybersecurity
1 day, 6 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers