Threat Intelligence Analyst
Monitor external threat landscape relevant to identity verification and fraud. Analyze fraud patterns in production traffic, source forged samples, produce threat intelligence reports, and maintain knowledge base of threat actors and TTPs. Requires 2-4 years experience with OSINT methodology and SQL.
Responsibilities
- Monitor fraud ecosystems and dark web marketplaces for emerging forgery techniques, document fraud trends, and biometric attack methods.
- Analyze fraud patterns in production traffic to identify emerging attack types, frequency trends, and detection coverage gaps.
- Source forged sample artifacts for red team repository.
- Produce threat intelligence reports and alerts for various teams, maintaining a knowledge base of threat actors, tools, and TTPs.
- Translate intelligence into prioritized test scenarios and capability gaps for red team backlog.
Requirements
- 2-4 years of experience with Open Web Intelligence methodology and tooling - source identification, verification, and pivoting across the open and deep web.
- 2-4 years of experience working with SQL - ability to query and analyze fraud patterns in real customer traffic.
- Strong analytical writing skills for briefs, reports, and intelligence summaries for mixed audiences.
- Technical literacy to read and understand technical write-ups of attack methods without needing to implement them.
- Research discipline and critical thinking with structured methodology, source citation, and source credibility assessment.
Nice to have
- Experience in dark web research including access practices and navigation of marketplaces and forums.
- Familiarity with fraud/forgery tools and the broader fraud ecosystem.
- Background in intelligence, cybersecurity research, or financial crime.