ironquill.tech/board

$ cat jobs/cyber-threat-analyst-hrtx-inc-2fc76269ad20.json

Cyber Threat Analyst

hrtx inc·APAC·Philippines·mid
Apply on himalayas → Get AI match score →
Cyber Threat Analysts are expected to familiarize themselves with these topics continuously, identifying threat leads from a variety of sources. Cyber Threat Analysts are also expected to analyze malware and create effective detections, which their senior peers will review and validate. Cyber Threat Analysts must be able to communicate this subject matter effectively to various audiences, both verbally and in writing. Specific Duties and Responsibilities: Threat Lead Identification: Research new adversary tactics, techniques, and procedures (TTPs) using open sources (public information such as security vendor reporting, social media, code repositories); closed sources (dark web and underground forums); and proprietary sources. Subject Matter: Threat leads should focus on team priority intelligence requirements (PIRs). Examples of such subject matter include malware developments, offensive security tools, vulnerability exploits, cloud security, and mobile security. Key Detail Identification: During research, identify and take note of infection chains, host and network IoCs, malware samples, threat actors, and MITRE ATT&CK tactics and techniques Author Insikt Notes: Write TTP Instances detailing identified threat leads. TTP Instances include a combination of information from open-source reporting and your own analysis (i.e. code review, static malware analysis). TTP Instances are written and formatted to help our customers understand infection chains while also helping them prepare and validate their defenses. Cadence: Write at least 2 TTP Instance notes daily Quality: Authored TTP Instances should include minimal grammatical or syntax errors. Plagiarism is not acceptable. Malware Analysis: Using sandbox environments and static analysis tools, analyze malware samples associated with threat leads. Use Cases: Malware analysis is used to provide additional insight into an event, validate open-source reporting, uncover additional IoCs, and assist peers and customers in de