Cyber Threat Intelligence and Incident Response Specialist
Analyze intelligence from open and closed sources to identify relevant cyber threats, maintain an ongoing view of cyber risk, and support real-time and retrospective incident investigations. The role focuses primarily on cyber threat intelligence, with practical incident response responsibilities.
Обязанности
- Identify relevant threats, including threat actor groups, techniques, tools, and targets.
- Build and maintain an intelligence picture of cyber risks by combining technical, business, and geopolitical information.
- Investigate cyber incidents in real time and retrospectively, including log analysis, indicator-of-compromise identification, and attack reconstruction.
- Coordinate cyber incident response with internal teams and external providers, including escalation management.
- Develop and improve incident response playbooks, scenarios, exercises, and procedures.
- Produce high-quality intelligence and investigation reports with actionable recommendations.
- Coordinate with external intelligence organizations.
- Guide infrastructure, architecture, penetration testing, marketing, and awareness stakeholders on cyber threat intelligence matters.
- Participate in organizational incident response and cyber threat intelligence exercises.
Требования
- Experience analyzing cyber threat intelligence from open and closed sources.
- Understanding of cyber incidents, attack techniques, threat actors, and defensive systems.
- Ability to analyze logs, identify indicators of compromise, reconstruct attack activity, and interpret investigation reports.
- Ability to operate and work with SIEM, SOAR, threat intelligence platforms, and forensic tools.
- Strong written and verbal communication skills for producing intelligence and investigation reports and presenting findings to management.
Будет плюсом
- Knowledge of threat actor groups, attack methods, and defensive systems.
- Experience participating in organizational incident response and cyber threat intelligence exercises.
- Ability to work outside standard hours during critical incidents.