At a Glance
- Tasks: Track state-sponsored cyber threats and mentor peers in intrusion analysis.
- Company: Join a diverse team at Recorded Future, a leader in threat intelligence.
- Benefits: Enjoy competitive pay, inclusive culture, and opportunities for professional growth.
- Other info: Collaborate globally and contribute to cutting-edge cybersecurity initiatives.
- Why this job: Make a real impact by combating cyber threats and sharing your expertise.
- Qualifications: 5+ years in Information Security with strong analytical and technical skills.
The predicted salary is between 36000 - 60000 £ per year.
Overview
Senior Threat Intelligence Analyst (Russia APT Focus) – Insikt Group, Recorded Future. This role involves tracking state-sponsored APT campaigns, mentoring peers in intrusion analysis, representing Insikt Group externally, and supporting Recorded Future’s Analyst-on-Demand service. The focus is on state-sponsored cyber threats originating from Russia.
What You’ll Do
- Conduct proactive research on state-sponsored APT activity by synthesizing multiple technical datasets to develop novel insights and high-quality reporting
- Establish and refine methods to track APT campaigns using network, intrusion, and malware analysis
- Hunt for threat actor infrastructure and activity across diverse technical data sources, leveraging banner data, service metadata, and related technical artifacts
- Identify, prioritize, and deploy detection mechanisms for command-and-control infrastructure, malware families, and threat groups of interest
- Continuously evaluate and improve threat intelligence workflows, identifying opportunities to enhance automation, efficiency, and analytic precision
- Stay up to date on evolving APT tradecraft by regularly reviewing technical publications, blogs, and intelligence from trusted sharing communities
- Mentor colleagues on intrusion analysis tradecraft and threat intelligence best practices, fostering a culture of knowledge sharing and continuous development
- Collaborate with geopolitical and regional analysis teams to support cross-functional research
- Propose and evaluate new data sources and analytical methods to enhance or automate the intelligence cycle
- Represent Insikt Group externally as a subject matter expert through customer briefings, media engagements, or public research dissemination
- Collaborate with engineering and data science teams to ensure effective integration of relevant data and analytics into the Recorded Future platform
- Support customer intelligence needs through Recorded Future’s Analyst-on-Demand service
Required Qualifications
- BA/BS or equivalent experience in Computer Science, Computer Engineering, Information Security, Security Studies, Intelligence, or a related field
- Preferably 5+ years of experience in Information Security and/or Threat Intelligence
- Demonstrated experience conducting technical threat analysis and research
- In-depth knowledge of TCP/IP and other networking protocols and datasets relevant to intrusion and network infrastructure analysis
- Demonstrated capability in identifying and tracking infrastructure through methods such as banner analysis and metadata correlation
- Experience with static and dynamic malware analysis, including family attribution and variant clustering
- Proficiency in scripting (Python preferred, or Go, C, C++, Java) and fluency with common CTI research tools such as Maltego, Jupyter Notebook, the Elastic Stack, and similar tools
- Proven experience applying structured analytical techniques and intelligence methodologies to assess state-sponsored threat activity, including the intelligence cycle, intelligence writing best practices, and frameworks such as the Diamond Model
- Familiarity with threat modeling and adversary tracking frameworks such as MITRE ATT&CK, the Cyber Kill Chain, and related models to support campaign clustering, detection development, and strategic reporting
- Detailed understanding of existing APT groups’ past activities, TTPs, motivations, and targeting patterns
- Experience with open-source intelligence-gathering tools and techniques
- Experience working directly with customers, with strong written and verbal communication skills to clearly convey complex technical and non-technical concepts
- Strong interpersonal and teamwork skills, including working with globally distributed team members
Preferred Qualifications
- MA/MS or equivalent experience in Computer Science, Computer Engineering, Information Security, or a related field
- Experience writing network and endpoint detection signatures
- Experience with Windows, iOS, Android, macOS, or malware analysis
- Proficiency in a high-priority foreign language, with preference for Arabic, Chinese, Farsi, Korean, Portuguese, Russian, or Spanish
Why Join Recorded Future
Recorded Future employees (or “Futurists”) represent over 40 nationalities and embody core values of high standards, inclusion, and ethics. The company’s dedication to empowering clients with intelligence has earned a 4.8-star Gartner rating and serves more than 45 of the Fortune 100 companies.
Legal Notice and Compliance
Recorded Future is an equal opportunity and affirmative action employer. We welcome candidates from all backgrounds and do not discriminate based on race, religion, color, national origin, gender including pregnancy, sexual orientation, gender identity, age, marital status, veteran status, disability or any other characteristic protected by law. We also prohibit discrimination related to compensation inquiries. For accommodation requests, please email careers@recordedfuture.com.
Additional Information
Senior Threat Intelligence Analyst (Rest of World APT Focus) – The Record: A cybersecurity news publication that explores the untold stories in this field.
Senior Threat Intelligence Analyst (Russia APT Focus) employer: Recorded Future
At Recorded Future, we pride ourselves on fostering a dynamic and inclusive work environment where innovation thrives. As a Senior Threat Intelligence Analyst, you will not only engage in cutting-edge research on state-sponsored cyber threats but also have the opportunity to mentor peers and collaborate with diverse teams across the globe. With a strong commitment to employee growth and a culture that values high standards and ethics, joining us means being part of a forward-thinking company that empowers its employees to make a meaningful impact in the cybersecurity landscape.
StudySmarter Expert Advice🤫
We think this is how you could land Senior Threat Intelligence Analyst (Russia APT Focus)
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Recorded Future, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Recorded Future
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Recorded Future. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Senior Threat Intelligence Analyst (Russia APT Focus)
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Recorded Future insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Recorded Future that you’re committed to staying ahead in the game.
How to prepare for a job interview at Recorded Future
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Recorded Future to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Recorded Future.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.