Cyber Threat Intelligence Research Intern
RemoteUnited States
Job Summary
Monitor dark web forums, marketplaces, and Telegram channels for credential leaks and track threat actor infrastructure using OSINT tools like Maltego and SpiderFoot. Build and maintain Python scripts to automate data collection, clean stealer logs, and extract indicators of compromise from open sources. Contribute to threat intelligence strategy by creating concise reports, dashboards, and alerts for SOC and incident response teams while mapping findings to MITRE ATT&CK frameworks. Maintain structured repositories of TTPs and threat actor profiles to support ongoing investigations and knowledge sharing across the security organization.
Required Qualifications
- Strong interest in cybersecurity, threat intelligence, and attacker behavior
- Good understanding of OSINT concepts and tools
- Good understanding of Dark web vs deep web, Tor, and common underground ecosystems
- Hands-on experience with Python for writing small scripts for data collection and parsing (web scraping, API calls, regex, etc.)
- Hands-on experience with Python for basic data handling (JSON, CSV, simple data analysis)
- Familiarity with Basic networking concepts (IP, DNS, ports, HTTP/S)
- Familiarity with Common attack types (phishing, credential stuffing, ransomware, data breaches)
- Ability to read & interpret breach data (usernames, passwords, hashes, stealer logs) with a strong sense of confidentiality and ethics
- Strong written communication skills to convert technical findings into clear summaries
Desired Qualifications
- Experience in building repeatable threat intel processes and automations
- Mentorship from security engineers / analysts and a chance to influence how our Threat Intel function evolves
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.