Principal Dark Web Collection Analyst

2 weeks, 6 days ago
Full-time
Senior
Data Science and Analytics
Recorded Future

Recorded Future

Recorded Future is the leading threat intelligence platform, empowering organizations to identify and mitigate threats across various domains with real-time, unbiased, and actionable intelligence.

Professional Services
251-1K
Founded 2009
$58M raised

Description

  • Serve as the company-wide subject matter expert on dark web and underground community dynamics.
  • Own strategic collection decisions on which forums, markets, and channels to pursue and where not to invest.
  • Identify, evaluate, and gain access to criminal forums, darknet marketplaces, Telegram channels, and adjacent covert infrastructure within legal and policy boundaries.
  • Develop and maintain collection strategies, personas, and source documentation to sustain access.
  • Partner with engineering to translate research tradecraft into automated collection pipelines.
  • Monitor sources for operational changes such as takedowns, migrations, and rebrands, and adapt collection accordingly.
  • Produce finished intelligence products including actor profiles, source assessments, and analytical summaries.
  • Collaborate with product, PMM, sales, customer success, and research teams as the go-to expert on underground community intelligence.
  • Represent Recorded Future externally through customer-facing blogs, webinars, and public research.

Requirements

  • 5+ years of hands-on dark web threat research with demonstrable collection outcomes across forums, marketplaces, or covert channels.
  • Deep, current expertise in major criminal forums and darknet markets, including access models and community evolution.
  • Proven ability to operate within closed or invite-only communities while maintaining OPSEC and legal compliance.
  • Russian language proficiency at a professional working level.
  • Strong analytical writing skills for concise intelligence products aimed at technical and executive audiences.
  • Comfort operating externally through presentations, webinars, and public-facing writing.
  • Additional language skills relevant to underground communities such as Ukrainian, Romanian, Chinese, Portuguese, or Arabic (preferred).
  • Background in cybercrime research, threat actor tracking, or law enforcement intelligence (preferred).
  • Prior experience at a threat intelligence vendor, CSIRT, law enforcement, or intelligence agency (preferred).
  • Basic Python scripting ability for data parsing and format conversion (preferred).

Benefits

  • Base salary range of $152,000 to $228,500.
  • Eligibility for incentive compensation.
  • Equity eligibility.
  • Medical, dental, and vision insurance.
  • Life insurance.
  • 401(k) retirement plan.
  • Remote work (#LI-Remote).
  • Accommodation support during the application process.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Threat Researcher

GreyNoise 51-250 Internet Software & Services

GreyNoise Intelligence is hiring a Threat Researcher to investigate emerging cyber threats and produce actionable intelligence that helps security practitioners detect, disrupt, and impose costs on adversaries.

Embedded Systems SQL
1 day, 9 hours ago

Associate Principal Cyber Threat Intelligence Analyst

Dragos 251-1K Professional Services

Dragos is hiring an OT Cyber Threat Intelligence Analyst to support a Singapore government security team with threat hunting, intelligence analysis, and incident response for critical infrastructure environments.

LLM SIEM
2 days, 10 hours ago

Security Operations Analyst II

Alphasense 51-250 Industrial Conglomerates

AlphaSense is hiring a Security Operations Analyst II to join its fully remote Security Operations team in Canada and help triage alerts, investigate incidents, and improve detection coverage.

AWS DNS GCP SIEM TCP/IP TLS
3 days, 11 hours ago

CyberSecurity Specialist

Avertium 251-1K IT Services

Avertium is hiring a Cyber Security Specialist to support 24x7 SOC monitoring and incident response for mid-market and enterprise clients.

Cybersecurity DNS Encryption HIPAA HTTP SIEM TCP/IP
3 days, 11 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers