About this role
Job Summary
We are seeking a highly motivated and analytical Threat Intelligence Analyst with 3-5 years of experience in Cyber Threat Intelligence (CTI), Threat Hunting, and Security Operations. The ideal candidate will be responsible for identifying, analyzing, and reporting emerging cyber threats, threat actors, attack techniques, vulnerabilities, and campaigns that could impact the organization. This role requires close collaboration with Security Operations Center (SOC), Incident Response, Vulnerability Management, and Engineering teams to transform threat intelligence into actionable insights that strengthen the organization's security posture.
The successful candidate should possess hands-on experience with threat intelligence platforms, SIEM technologies, threat hunting methodologies, MITRE ATT&CK framework, and open-source intelligence (OSINT) techniques. The role demands strong analytical skills, technical expertise, and the ability to communicate complex cybersecurity threats to both technical and non-technical stakeholders.
Key Responsibilities
1.Monitor, research, and analyze cyber threats, threat actors, malware campaigns, and emerging attack trends affecting the organization.
2.Collect, correlate, and evaluate intelligence from multiple sources including OSINT, commercial intelligence feeds, dark web monitoring platforms, and internal security telemetry.
- Conduct proactive threat hunting activities across endpoints, networks, cloud environments, and security platforms.
- Identify and validate Indicators of Compromise (IOCs), Indicators of Attack (IOAs), and Tactics, Techniques, and Procedures (TTPs).
- Leverage the MITRE ATT&CK framework to map adversary behaviors and improve detection capabilities.
Produce actionable intelligence reports, executive summaries, threat advisories, and situational awareness briefings.
6.Support incident response investigations by providing threat intelligence context, attack attribution, and remediation recommendations.
- Analyze malware samples and threat actor methodologies to understand attack patterns and potential business impact.
- Develop and maintain detection use cases, threat hunting queries, Sigma rules, and correlation rules.
Monitor dark web forums, underground marketplaces, and external threat sources for risks targeting organizational assets.
- Collaborate with SOC analysts, security engineers, vulnerability management teams, and business stakeholders to improve cyber defense strategies.
- Utilize threat intelligence platforms such as MISP, ThreatConnect, Recorded Future, Anomali, or similar technologies for intelligence management and enrichment.
- Stay current with cybersecurity trends, threat landscapes, vulnerabilities, and industry best practices.
Required Skills & Qualifications
- Strong understanding of cyber threat intelligence lifecycle and intelligence-driven security operations.
- Experience with SIEM solutions such as Microsoft Sentinel, Splunk, QRadar, or ArcSight.
- Proficiency in Microsoft Defender XDR, Defender for Endpoint, and cloud security monitoring tools.
- Knowledge of MITRE ATT&CK, Cyber Kill Chain, Diamond Model, and NIST Cybersecurity Framework.
- Hands-on experience with OSINT investigations and threat intelligence platforms.
- Familiarity with malware analysis concepts, network traffic analysis, endpoint investigations, and log correlation.
- Experience with STIX/TAXII, IOC management, and threat intelligence sharing mechanisms.
- Working knowledge of Python, PowerShell, KQL, YARA, or Sigma rules.
Tired of cold applications?
Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.
Know someone who'd be great for this?