Senior Threat Researcher

Recenso

Abu Dhabi

On-site

AED 150,000 - 200,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

A cybersecurity firm is seeking a Senior Threat Researcher specialized in dark web monitoring and intelligence analysis. The role involves collecting data from underground sources to enhance threat intelligence outputs. Ideal candidates will have 7–10 years of experience in cybersecurity, with a focus on dark web research, along with strong collaboration skills with CTI and AI teams. This position demands expertise in tooling, scripting, and the ability to communicate complex findings clearly.

Qualifications

  • 7–10 years in cybersecurity/cyber threat intelligence.
  • 5+ years focused on dark web research or underground monitoring.
  • Demonstrated experience infiltrating and monitoring dark web communities.
  • Strong record of correlating dark web findings with threat intelligence and incident response cases.

Responsibilities

  • Monitor and collect intelligence from underground forums and darknet markets.
  • Extract and validate IOCs and provide early warnings on leaks.
  • Produce periodic dark web monitoring reports and client-specific alerts.

Skills

Underground Monitoring & Collection
Threat Data Harvesting
Collaboration with CTI & AI Teams
Technical Expertise
Research & Intelligence
Tooling & Automation
Soft Skills

Education

GCTI, GIAC Cyber Threat Intelligence, OSINT-specific certifications

Tools

Flashpoint
KELA
DarkOwl
CyberSixgill
Python
Scrapy
Maltego
Kibana
Power BI

Job description

The Senior Threat Researcher will specialize in monitoring, collecting, and analysing intelligence from underground forums, darknet markets, encrypted messaging platforms, and closed communities. This role complements the Threat Intelligence researchers by providing raw and contextual underground data that feeds into adversary profiling, enrichment pipelines, and client deliverables. The researcher will also help shape automation strategies for dark web monitoring within the CTI platform, working closely with analysts, AI/ML engineers, and incident responders.

Requirements
  • Underground Monitoring & Collection
    • Identify and infiltrate dark web marketplaces, forums, and closed channels (Telegram, IRC, Discord, etc.).
    • Track threat actors’ chatter related to exploits, malware, credentials, and attack tools.
    • Conduct HUMINT-style engagement when permissible and safe.
  • Threat Data Harvesting
    • Extract and validate IOCs (hashes, domains, wallet addresses, C2 servers).
    • Correlate underground findings with OSINT, malware telemetry, and CTI feeds.
    • Provide early warning on data leaks, ransomware negotiations, and credential dumps.
  • Collaboration with CTI & AI Teams
    • Feed structured underground intelligence into the CTI platform for enrichment and scoring.
    • Partner with ML engineers to train NLP models for dark web text mining.
    • Work with TI analysts to transform raw chatter into tactical and strategic intelligence.
  • Reporting & Dissemination
    • Produce periodic dark web monitoring reports and client‑specific alerts.
    • Contribute to threat actor profiles, campaign tracking, and risk advisories.
    • Provide insights to incident response and red team exercises.
Desired Skills
  • Technical Expertise
    • Deep knowledge of Tor, I2P, Freenet, and underground marketplaces.
    • Familiarity with cryptocurrency ecosystems (Bitcoin, Monero, mixers, blockchain tracing).
    • Proficiency in harvesting IOCs and mapping to frameworks like MITRE ATT&CK.
    • Understanding of STIX/TAXII, MISP, and TI platform ingestion formats.
  • Research & Intelligence
    • Strong OSINT/HUMINT tradecraft, ability to pivot from dark web to surface intel.
    • Experience monitoring ransomware leak sites, carding forums, and exploit brokers.
    • Analytical ability to contextualize underground activity in geopolitical/cybercrime terms.
  • Tooling & Automation
    • Hands‑on with dark web monitoring tools (Flashpoint, KELA, DarkOwl, CyberSixgill, custom scrapers).
    • Scripting for data extraction (Python, Scrapy, APIs).
    • Familiarity with data visualization tools (Maltego, Kibana, Power BI).
  • Soft Skills
    • Ability to communicate highly technical underground findings in executive‑friendly language.
    • Discretion, OPSEC awareness, and strong ethical boundaries.
    • Collaborative mindset with TI analysts, IR, and platform engineers.
Experience Required
  • 7–10 years in cybersecurity/cyber threat intelligence, with 5+ years focused on dark web research or underground monitoring.
  • Demonstrated experience infiltrating and monitoring dark web communities.
  • Strong record of correlating dark web findings with threat intelligence and incident response cases.
  • Hands‑on exposure to CTI platforms (MISP, Anomali, ThreatConnect, Recorded Future, etc.).
  • Familiarity with malware ecosystems, data leaks, and exploit sales.
  • Certifications desirable: GCTI, GIAC Cyber Threat Intelligence, OSINT‑specific certifications (Bellingcat, SANS OSINT), blockchain tracing certifications.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Threat Researcher
Senior Threat Researcher

EstateSight AI • Abu Dhabi

On-site
Senior Threat Intelligence Analyst
Senior Threat Intelligence Analyst

Recenso • Abu Dhabi

On-site
AED 300,000 - 400,000
Senior Threat Intelligence Analyst
Senior Threat Intelligence Analyst

EstateSight AI • Abu Dhabi

On-site
AED 330,000 - 441,000
Competitive salary
Professional development opportunities
Threat Intelligence Analyst
Threat Intelligence Analyst

spiderSilk • Dubai

Hybrid
AED 220,000 - 360,000
Dark Web Threat Intelligence Analyst
Dark Web Threat Intelligence Analyst

spiderSilk • Dubai

Hybrid
AED 220,000 - 360,000
Senior Dark Web Threat Intelligence Analyst
Senior Dark Web Threat Intelligence Analyst

EstateSight AI • Abu Dhabi

On-site
Counter-Threat Intelligence Engineer
Counter-Threat Intelligence Engineer

Remotedxb • Dubai

On-site
AED 360,000 - 750,000
Threat Hunting Specialist (UAEN)
Threat Hunting Specialist (UAEN)

Confidential • Abu Dhabi Emirate

On-site
AED 260,000 - 420,000
Systems Engineer
Systems Engineer

Remotedxb • Dubai

On-site
AED 150,000 - 210,000
Senior Threat Intelligence & CTI Platform Lead
Senior Threat Intelligence & CTI Platform Lead

Recenso • Abu Dhabi

On-site
AED 300,000 - 400,000