Cyber Threat Intelligence Analyst, Associate
On-siteSingapore, Singapore
Job Summary
Conduct proactive threat research and investigative analysis to identify adversary campaigns, capabilities, infrastructure, targeting, and tactics, techniques, and procedures (TTPs) using internal collection, OSINT, and commercial intelligence sources. Triage cyber threat intelligence alerts and incoming intelligence, assessing relevance, credibility, severity, and potential impact, and escalate actionable findings as appropriate. Author clear, concise, and actionable threat intelligence reports, including tactical and technical reporting, threat assessments, investigative summaries, and intelligence briefings tailored to operational and non-technical audiences. Enrich, validate, and characterize threat indicators and technical artifacts using open-source, commercial, and internal security tooling, and curate high-confidence indicators of compromise (IOCs) for operational use. Apply analytic frameworks such as MITRE ATT&CK and the Diamond Model to characterize adversary activity, infrastructure, capabilities, and relationships. Partner with threat hunting, security monitoring, incident response, detection engineering, and other cybersecurity teams to translate threat intelligence into detection opportunities, investigative leads, mitigations, and control validation activities. Where applicable, use scripting and data analysis techniques, including Python, to support investigations, enrichment, data processing, and analytic workflows.
Required Qualifications
- Min 4 years of experience in cyber threat intelligence, cybersecurity investigations, threat hunting, security operations, incident response, or a related cybersecurity discipline
- Experience researching cyber threat actors, malware, campaigns, vulnerabilities, and adversary TTPs using internal, open-source, and/or commercial intelligence sources
- Familiarity with intelligence analysis frameworks and methodologies such as MITRE ATT&CK, the Diamond Model, intelligence lifecycle, and structured analytic techniques
- Experience conducting alert triage and investigative analysis, including evaluating intelligence for relevance, credibility, and potential organizational impact
- Strong report writing and analytic communication skills, with the ability to clearly articulate evidence, assessments, confidence levels, implications, and recommended actions
- Understanding of intelligence requirements and collection management concepts, including identifying information gaps and aligning collection activity to priority intelligence needs
- Familiarity with SIEM, endpoint, network, threat intelligence platform, or other security tooling and the ability to interpret relevant security telemetry in support of investigations
- Experience enriching and analyzing indicators such as domains, IP addresses, URLs, file hashes, malware artifacts, and related technical infrastructure
- Working knowledge of scripting or data analysis, preferably Python, for automation, enrichment, or investigative workflows
- Strong analytical and critical-thinking skills, including the ability to synthesize information from multiple sources, distinguish fact from assessment, and develop evidence-based analytic judgments
- Ability to work collaboratively across cybersecurity teams and communicate effectively with both technical and non-technical stakeholders
- Ability to manage multiple investigative and intelligence priorities while maintaining attention to detail and producing timely, high-quality analysis
Desired Qualifications
- GIAC Cyber Threat Intelligence (GCTI), CISSP, CASP+ or similar cybersecurity certifications
- Experience with threat intelligence platforms, commercial intelligence providers, OSINT tooling, malware analysis platforms, or large-scale security data analysis
- Familiarity with intelligence requirements management, source evaluation, structured analytic techniques, or intelligence production standards
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.