Senior Threat Researcher

EstateSight AI

Abu Dhabi

On-site

AED 279,000 - 334,800

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

A cybersecurity firm in Abu Dhabi is seeking a professional with 7-10 years of experience in cyber threat intelligence focusing on dark web monitoring. The ideal candidate will identify and infiltrate dark web forums, analyze threats, and collaborate with AI teams. This role requires strong analytical skills and the ability to produce insightful reports. Familiarity with dark web tools and scripting for data extraction is essential. Certifications in cyber threat intelligence are desirable.

Qualifications

  • 7–10 years in cybersecurity/cyber threat intelligence, with 5+ years focused on dark web research.
  • Hands-on experience infiltrating and monitoring dark web communities.
  • Strong record in correlating dark web findings with threat intelligence.

Responsibilities

  • Identify and infiltrate dark web marketplaces and forums.
  • Extract and validate indicators of compromise (IOCs).
  • Produce dark web monitoring reports and client-specific alerts.

Skills

Underground monitoring and collection
Threat data harvesting
Collaboration with CTI & AI teams
Technical expertise in dark web
Research & intelligence skills
Tooling & automation
Soft skills for communication

Tools

Python
Maltego
Kibana
Power BI

Job description

Requirements

Underground Monitoring & Collection

  • Identify and infiltrate dark web marketplaces, forums, and closed channels (Telegram, IRC, Discord, etc.).
  • Track threat actors’ chatter related to exploits, malware, credentials, and attack tools.
  • Conduct HUMINT-style engagement when permissible and safe.

Threat Data Harvesting

  • Extract and validate IOCs (hashes, domains, wallet addresses, C2 servers).
  • Correlate underground findings with OSINT, malware telemetry, and CTI feeds.
  • Provide early warning on data leaks, ransomware negotiations, and credential dumps.

Collaboration with CTI & AI Teams

  • Feed structured underground intelligence into the CTI platform for enrichment and scoring.
  • Partner with ML engineers to train NLP models for dark web text mining.
  • Work with TI analysts to transform raw chatter into tactical and strategic intelligence.

Reporting & Dissemination

  • Produce periodic dark web monitoring reports and client-specific alerts.
  • Contribute to threat actor profiles, campaign tracking, and risk advisories.
  • Provide insights to incident response and red team exercises.
Desired Skills

Technical Expertise

  • Deep knowledge of Tor, I2P, Freenet, and underground marketplaces.
  • Familiarity with cryptocurrency ecosystems (Bitcoin, Monero, mixers, blockchain tracing).
  • Proficiency in harvesting IOCs and mapping to frameworks like MITRE ATT&CK.
  • Understanding of STIX/TAXII, MISP, and TI platform ingestion formats.

Research & Intelligence

  • Strong OSINT/HUMINT tradecraft, ability to pivot from dark web to surface intel.
  • Experience monitoring ransomware leak sites, carding forums, and exploit brokers.
  • Analytical ability to contextualize underground activity in geopolitical/cybercrime terms.

Tooling & Automation

  • Hands-on with dark web monitoring tools (Flashpoint, KELA, DarkOwl, CyberSixgill, custom scrapers).
  • Scripting for data extraction (Python, Scrapy, APIs).
  • Familiarity with data visualization tools (Maltego, Kibana, Power BI).

Soft Skills

  • Ability to communicate highly technical underground findings in executive-friendly language.
  • Discretion, OPSEC awareness, and strong ethical boundaries.
  • Collaborative mindset with TI analysts, IR, and platform engineers.
Experience Required
  • 7–10 years in cybersecurity/cyber threat intelligence, with 5+ years focused on dark web research or underground monitoring.
  • Demonstrated experience infiltrating and monitoring dark web communities.
  • Strong record of correlating dark web findings with threat intelligence and incident response cases.
  • Hands-on exposure to CTI platforms (MISP, Anomali, ThreatConnect, Recorded Future, etc.).
  • Familiarity with malware ecosystems, data leaks, and exploit sales.
  • Certifications desirable: GCTI, GIAC Cyber Threat Intelligence, OSINT-specific certifications (Bellingcat, SANS OSINT), blockchain tracing certifications.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Threat Researcher
Senior Threat Researcher

Recenso • Abu Dhabi

On-site
AED 150,000 - 200,000
Threat Intelligence Analyst
Threat Intelligence Analyst

spiderSilk • Dubai

Hybrid
AED 220,000 - 360,000
Senior Threat Intelligence Analyst
Senior Threat Intelligence Analyst

EstateSight AI • Abu Dhabi

On-site
AED 330,000 - 441,000
Competitive salary
Professional development opportunities
Senior Threat Intelligence Analyst
Senior Threat Intelligence Analyst

Recenso • Abu Dhabi

On-site
AED 300,000 - 400,000
Senior Dark Web Threat Intelligence Researcher
Senior Dark Web Threat Intelligence Researcher

Recenso • Abu Dhabi

On-site
AED 150,000 - 200,000
Senior Dark Web Threat Intelligence Analyst
Senior Dark Web Threat Intelligence Analyst

EstateSight AI • Abu Dhabi

On-site
Dark Web Threat Intelligence Analyst
Dark Web Threat Intelligence Analyst

spiderSilk • Dubai

Hybrid
AED 220,000 - 360,000
Counter-Threat Intelligence Engineer
Counter-Threat Intelligence Engineer

Remotedxb • Dubai

On-site
AED 360,000 - 750,000
Systems Engineer
Systems Engineer

Remotedxb • Dubai

On-site
AED 150,000 - 210,000
Threat Hunting Specialist (UAEN)
Threat Hunting Specialist (UAEN)

Confidential • Abu Dhabi Emirate

On-site
AED 260,000 - 420,000