Security Threat Intelligence Analyst

WPP

São Paulo

Presencial

BRL 120 000 - 150 000

Tempo integral

14 dias+

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Vantagens oferecidas por esta oferta de emprego

Passionate, inspired people
Challenging and stimulating work
Hybrid work model

Resumo da oferta

WPP is seeking a Threat Intelligence Engineer to enhance their cyber threat intelligence platforms. The role focuses on engineering and maintaining systems for threat data ingestion and integration with security tools. Candidates should have experience with APIs, data transformation, and threat intelligence concepts, along with relevant certifications.

The position promotes a hybrid work model, blending office collaboration with remote flexibility. Join WPP to be part of a culture that values respect and equal opportunities for all employees.

Qualificações

  • Experience engineering or operating enterprise threat intelligence platforms.
  • Hands-on experience integrating CTI with SIEM, SOAR, or EDR/XDR.
  • Fluent in written and spoken English.

Responsabilidades

  • Engineer and maintain threat intelligence platforms.
  • Design ingestion pipelines for intelligence feeds.
  • Integrate threat intelligence into security tooling.

Conhecimentos

Engineering threat intelligence platforms
Integrating CTI with SIEM/SOAR/EDR/XDR
APIs and data transformation
Understanding of threat intelligence concepts
Experience in incident response support

Formação académica

Relevant certifications (GCTI, GCIA, GCED)

Ferramentas

Google Threat Intelligence
Recorded Future

Descrição da oferta de emprego

The Threat Intelligence Engineer is responsible for engineering, operating, and continuously improving WPP’s cyber threat intelligence platforms, integrations, and enrichment pipelines. This role focuses on how threat intelligence is ingested, processed, correlated, and operationalised at scale across security operations. The position is an engineering‑led individual contributor role with no people management responsibilities.

What you’ll be doing:
  • Engineer and maintain threat intelligence platforms and data sources.
  • Design ingestion pipelines for external, internal, and open‑source intelligence feeds.
  • Maintain centralised repositories for indicators, threat actor artefacts, and metadata.
  • Integrate threat intelligence into SIEM, SOAR, EDR/XDR, email, identity, and cloud tooling.
  • Build enrichment pipelines linking incidents to threat actors, campaigns, and TTPs.
  • Partner with Automation Engineering to ensure intelligence is automation‑first.
  • Provide engineered intelligence support to Incident Response during active incidents.
  • Enable Detection Engineering and Threat Hunting with structured intelligence outputs.
  • Support Vulnerability Management with intelligence on actively exploited vulnerabilities.
  • Build automation hooks between CTI platforms and SOAR workflows.
  • Enable safe, explainable intelligence use for agentic and automated decision support.
  • Improve intelligence delivery speed, accuracy, and signal‑to‑noise ratio.
  • Define and maintain engineering standards for CTI integrations.
  • Monitor feed efficacy and deprecate low‑value intelligence sources.
  • Support audits, assurance, and documentation activities related to CTI.
What you’ll need:
  • Experience engineering or operating enterprise threat intelligence platforms.
  • Hands‑on experience integrating CTI with SIEM, SOAR, or EDR/XDR.
  • Strong capability in APIs, data transformation, enrichment logic, and automation.
  • Solid understanding of threat intelligence concepts and operationalisation.
  • Experience with Google Threat Intelligence, Recorded Future, or similar platforms.
  • Familiarity with MITRE ATT&CK and threat‑led detection models.
  • Experience supporting incident response or detection engineering teams.
  • Relevant certifications (GCTI, GCIA, GCED, cloud security certifications).
  • Fluent in written and spoken English.
Benefits:
  • Passionate, inspired people – a culture that encourages extraordinary work.
  • Scale and opportunity – influence projects at an industry‑unparalleled scale.
  • Challenging and stimulating work – unique work and collaboration with creative problem solvers.
  • Hybrid work model – teams in the office around four days a week; accommodations and flexibility can be discussed during the interview.

WPP is an equal opportunity employer and considers applicants for all positions without discrimination or regard to particular characteristics. We are committed to fostering a culture of respect in which everyone feels they belong and has the same opportunities to progress in their careers.

Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Cyber Threat Intelligence Manager
Cyber Threat Intelligence Manager

Jobtailor • São Paulo

Presencial
BRL 300 000 - 520 000
Risk Specialist
Risk Specialist

WPP • São Paulo

Presencial
BRL 80 000 - 120 000
Cultural diversity and respect
Challenging and stimulating work
Insider Risk Security Engineer
Insider Risk Security Engineer

CloudWalk, Inc. • São Paulo

Presencial
BRL 300 000 - 420 000
Cyber Security Analyst - Americas
Cyber Security Analyst - Americas

Intuition Machines • Brasil

Teletrabalho
Fully remote position
Flexible working hours
Modern development workflows
Mid-Level Information Security Analyst – Cyber Threat Intelligence
Mid-Level Information Security Analyst – Cyber Threat Intelligence

Jobtailor • Porto Alegre

Presencial
BRL 180 000 - 280 000
Information Security Analyst (Mid-level) – Focus on Cyber Threat Intelligence
Information Security Analyst (Mid-level) – Focus on Cyber Threat Intelligence

Jobtailor • Porto Alegre

Presencial
BRL 60 000 - 120 000
Technology Risk & Controls Senior Specialist
Technology Risk & Controls Senior Specialist

WPP • São Paulo

Híbrido
BRL 180 000 - 300 000
Brazil Cybersecurity, Threat Intelligence & Fraud Protection Cyber Threat Intelligence Analyst – LATAM
Brazil Cybersecurity, Threat Intelligence & Fraud Protection Cyber Threat Intelligence Analyst – LATAM

Group-IB • Brasil

Presencial
BRL 120 000 - 180 000
Flexible schedule
Certification support
International team exposure
Technical Security Governance Lead - Identity
Technical Security Governance Lead - Identity

WPP • São Paulo

Híbrido
Security Engineer - Incident Response
Security Engineer - Incident Response

CloudWalk, Inc. • São Paulo

Presencial
BRL 180 000 - 240 000