Sr. Cyberthreat Analyst (OSINT)

HRTX

Philippines

On-site

PHP 1,000,000 - 1,800,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

HRTX is seeking a Sr. Cyberthreat Analyst (OSINT) to lead threat research using open and dark sources, write TTP instances, and develop detections for defense. You will analyze malware with sandbox tools and map activity to MITRE ATT&CK and Diamond Model, while collaborating with a global team to strengthen client defenses.

The role emphasizes timely, accurate reporting and adherence to information security policies, with responsibilities across publication and review processes.

Qualifications

  • Experience writing reports on technical subject matter clearly and concisely.
  • Ability to create malware detections (YARA, Sigma, Snort) with minimal false positives.
  • Disciplined time management and ability to work with a global team.
  • Open-source intelligence experience and large data set handling.
  • Familiarity with MITRE ATT&CK and Diamond Model mappings.

Responsibilities

  • Research new adversary TTPs using OSINT, dark web, and vendor sources.
  • Document TTP instances to help customers understand infection chains.
  • Write at least 2 TTP instances daily and ensure accuracy.
  • Analyze malware with sandboxes and static tools for insights.
  • Create malware or vulnerability detections for threat hunting and defense.

Skills

Report writing
Malware detections
Time management
Global collaboration
Feedback integration

Education

BS in computer science / information systems / cyber intelligence

Tools

Sandbox environments
Threat intel platforms

Job description

About the job Sr. Cyberthreat Analyst (OSINT)

Specific Duties and Responsibilities:

  • Threat Lead Identification: Research new adversary tactics, techniques, and procedures (TTPs) using open sources (public information such as security vendor reporting, social media, code repositories); closed sources (dark web and underground forums); and proprietary sources.
  • Subject Matter: Threat leads should focus on team priority intelligence requirements (PIRs). Examples of such subject matter include malware developments, offensive security tools, vulnerability exploits, cloud security, and mobile security.
  • Key Detail Identification: During research, identify and take note of infection chains, host and network IoCs, malware samples, threat actors, and MITRE ATT&CK tactics and techniques.
  • Author Notes: Write TTP Instances detailing identified threat leads. TTP Instances include a combination of information from open-source reporting and your own analysis (i.e. code review, static malware analysis). TTP Instances are written and formatted to help our customers understand infection chains while also helping them prepare and validate their defenses.
  • Cadence: Write at least 2 TTP Instance notes daily
  • Quality: Authored TTP Instances should include minimal grammatical or syntax errors. Plagiarism is not acceptable.
  • Malware Analysis: Using sandbox environments and static analysis tools, analyze malware samples associated with threat leads.
  • Use Cases: Malware analysis is used to provide additional insight into an event, validate open-source reporting, uncover additional IoCs, and assist peers and customers in detection engineering.
  • Detection Engineering: Create malware or vulnerability detections (e.g. YARA, Sigma, Snort, Nuclei) that can be used for threat hunting, detection, and classification.
  • Cadence: Create at least 2 malware or vulnerability detections per month
  • Delivery: These detections may be uploaded to the Client Platform on their own, or accompanied by a TTP Instance.
  • Content Review: Review TTP Instances and Malware Detections created by your peers, checking for subject matter accuracy, correct IoC identification (no false positives), MITRE ATT&CK mapping, Diamond Model mapping, and proper grammar and formatting.
  • Content Publication: Upload reviewed TTP Instances to the Client Platform while ensuring proper entity and Diamond Model tagging.
  • Information Security: Adhere to and implement our organization's quality and information security policies and carry out its processes and procedures accordingly.
  • Protect client-supplied and generated-for-client information from unauthorized access, disclosure, modification, destruction, or interference (see also Table of Offenses)
  • Carry out tasks as assigned and aligned with particular processes or activities related to information security.
  • Report any potential or committed non-conformity, observation and/or security event or risks to immediate superior.

Qualification

Required Skills

  • Demonstrable experience writing reports on technical subject matter (e.g. malware, vulnerability exploits, offensive security tools) in a clear, concise, and logical format
  • Demonstrable ability to create malware detections (e.g. YARA, Sigma, Snort) with no false positives
  • Disciplined time management
  • Flexibility when working with a global team in varying timezones Self-starting, self-motivated, and thrive in a collaborative environment Ability to receive and apply constructive feedback from peers and leadership

Minimum Qualifications

  • B.S. equivalent in computer science, information systems, or cyber intelligence Four (4) years of professional experience in the Cybersecurity or Threat Intelligence industry
  • Technical proficiency in Cyber Threat Intelligence and Threat Intelligence platforms
  • Experience working with open-source intelligence (OSINT) and/or large data sets
  • Experience working with sandboxes, virtual machines, or other malware analysis tools
  • Familiarity with the MITRE ATT&CK Framework, including the ability map reported activity to ATT&CK tactics and techniques
  • Familiarity with interpreting and mapping cyberattacks to the Diamond Model of Intrusion Analysis
  • Adeptness in cybersecurity and data protection

Preferred Qualifications

  • Experience creating vulnerability detections (e.g. Nuclei)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Junior Cyber Threat Analyst
Junior Cyber Threat Analyst

Infinit-O • Philippines

On-site
PHP 300,000 - 540,000
Cyber Threat Analyst
Cyber Threat Analyst

HRTX • Philippines

On-site
PHP 600,000 - 900,000
Jr. Cyber Threat Analyst
Jr. Cyber Threat Analyst

HRTX • Philippines

On-site
PHP 420,000 - 780,000
Vulnerability Analyst
Vulnerability Analyst

HRTX • Philippines

On-site
PHP 446,000 - 1,004,000
Jr. Technical Writer (Cyber Threat Intelligence)
Jr. Technical Writer (Cyber Threat Intelligence)

Infinit-O • Metro Manila

On-site
PHP 300,000 - 420,000
Threat Intelligence Analyst
Threat Intelligence Analyst

HRTX • Philippines

On-site
PHP 350,000 - 700,000
Technical Writer
Technical Writer

Create Synergies Inc. • Pasay

On-site
PHP 400,000 - 800,000
Technical Writer
Technical Writer

Our Clients • Pasay

On-site
PHP 480,000 - 720,000
Jr. Threat Intelligence Analyst
Jr. Threat Intelligence Analyst

HRTX • Philippines

On-site
PHP 500,000 - 800,000
Jr. Technical Writer (Cyber Threat Intelligence) | Hybrid Setup | Pasay
Jr. Technical Writer (Cyber Threat Intelligence) | Hybrid Setup | Pasay

Infinit-O • Philippines

On-site
PHP 300,000 - 540,000