Get more replies from employers
Send a job-specific resume in minutes.
Infinit-O is seeking a Cyber Threat Analyst to monitor, analyze, and report on malware developments, threat actors, and TTPs. You will research techniques, map activities to MITRE ATT&CK, and produce actionable detections and insights for customers.
The role emphasizes high-quality, well-documented TTP instances, sandboxed analysis, and collaboration with senior peers to validate findings and strengthen defenses.
TTP MNL reports on technical subject matter such as malware developments, offensive security tools, vulnerability exploits, cloud security, and mobile security. Cyber Threat Analysts are expected to familiarize themselves with these topics continuously, identifying threat leads from a variety of sources. Cyber Threat Analysts are also expected to analyze malware and create effective detections, which their senior peers will review and validate. Cyber Threat Analysts must be able to communicate this subject matter effectively to various audiences, both verbally and in writing.
Specific Duties and Responsibilities:
Threat Lead Identification: Research new adversary tactics, techniques, andprocedures (TTPs) using open sources (public information such as security vendorreporting, social media, code repositories); closed sources (dark web andunderground forums); and proprietary sources.
Subject Matter: Threat leads should focus on team priority intelligence
requirements (PIRs). Examples of such subject matter include malware
developments, offensive security tools, vulnerability exploits, cloud security, andmobile security.
Key Detail Identification: During research, identify and take note of infectionchains, host and network IoCs, malware samples, threat actors, and MITRE ATT&CKtactics and techniques
Author Insikt Notes: Write TTP Instances detailing identified threat leads. TTPInstances include a combination of information from open-source reporting andyour own analysis (i.e. code review, static malware analysis). TTP Instances arewritten and formatted to help our customers understand infection chains while alsohelping them prepare and validate their defenses.
Cadence: Write at least 2 TTP Instance notes daily
Quality: Authored TTP Instances should include minimal grammatical or syntaxerrors. Plagiarism is not acceptable.
Malware Analysis: Using sandbox environments and static analysis tools, analyzemalware samples associated with threat leads.
Use Cases: Malware analysis is used to provide additional insight into an event, validate open-source reporting, uncover additional IoCs, and assist peers and customers in detection engineering
Detection Engineering: Create malware or vulnerability detections (e.g. YARA, Sigma, Snort, Nuclei) that can be used for threat hunting, detection, and classification.
Cadence: Create at least 1 malware or vulnerability detection per month
Delivery: In most cases, these detections will be delivered alongside a TTP Instance.
Information Security: Adhere to and implement Infinit-O's quality and informationsecurity policies and carry out its processes and procedures accordingly.Protect client-supplied and generated-for-client information from unauthorizedaccess, disclosure, modification, destruction, or interference (see also Table ofOffenses)
Carry out tasks as assigned and aligned with particular processes or activitiesrelated to information security.
Report any potential or committed non-conformity, observation and/or securityevent or risks to immediate superior.
Qualification