Principal Threat Intelligence Analyst

Engineering · Boston, United States

Job description

With 1,000 intelligence professionals, over $300M in sales, and serving over 1,800 clients worldwide, Recorded Future is the world’s most advanced, and largest, intelligence company!

Principal Threat Intelligence Analyst

Strategic and Persistent Threats, Insikt Group, Recorded Future

As an analyst for Insikt Group’s Strategic and Persistent Threats (SPT) team, you will contribute to APT campaign tracking initiatives, support our Analyst on Demand service, mentor your colleagues on all things intrusion analysis, and represent Insikt Group’s research externally. This role supports proactive research and monitoring efforts into threat actor infrastructure, tools, and TTPs, as well as client-driven finished intelligence reports and requirements. Your research will be largely focused on state-sponsored threats emanating from China.

What You’ll Do: 

  • Synthesize multiple technical datasets to derive novel insights and reporting related to state-sponsored APT activity tied to China;
  • Establish methods of tracking APT campaigns using a combination of network, intrusion, and malware analysis skills;
  • Support the fulfillment of client priority intelligence requirements via Recorded Future’s Analyst on Demand service;
  • Mentor your colleagues on intrusion analysis and threat intelligence best practices;
  • Identify new datasets to ingest and propose new analytics that can be developed to improve and/or automate portions of the intelligence cycle;
  • Serve as a subject matter expert on Chinese state-sponsored threat activity;
  • Work with the Advanced Reversing, Malware, Operations, and Reconnaissance team to identify, prioritize, and deploy various detection mechanisms for command & control infrastructure, malware families, and threat actor groups of interest;
  • Stay on top of developments within the APT threat landscape and track key developments by following publications, blogs, and mailing lists;
  • Represent the SPT team’s research (emphasis on China state-sponsored research) externally to journalists and media (anonymously or otherwise) in collaboration with Recorded Future’s public relations team;
  • Work with engineering and data science teams to ensure relevant data and analytics are correctly designed, developed, and deployed in the Recorded Future platform.

What You’ll Bring (Required):

  • BA/BS or equivalent experience in Computer Science, Computer Engineering, Information Security, Security Studies, Intelligence, or a related field
  • 6+ years of experience in Information Security and/or Threat Intelligence
  • Demonstrable experience conducting technical threat analysis and research
  • Demonstrable experience with structured analytical techniques, the intelligence cycle, and intelligence writing techniques and methodologies
  • Proven expertise in clustering and tracking multiple state-sponsored activity groups using techniques such as the Diamond Model of Intrusion Analysis
  • Scripting capabilities in Python (preferred), Go, C, C++, or Java
  • Familiarity with platforms & software such as Maltego, Jupyter Notebook, the ELK Stack, and Excel, among other common cyber threat intelligence research platforms
  • In-depth knowledge of TCP/IP and other networking protocols and datasets relevant to intrusion and network infrastructure analysis
  • Experience developing intelligence requirements
  • Experience working directly with clients
  • Experience with open-source intelligence-gathering tools and techniques
  • Excellent written and verbal communication; ability to convey complex technical and non-technical concepts
  • Excellent interpersonal and teamwork skills; ability to work with globally distributed team members

Highly Desirable Skills/Experience (not required):

  • MA/MS or equivalent experience in Computer Science, Computer Engineering, Information Security, or a related field
  • Experience writing network and endpoint detection signatures
  • Experience with Windows, iOS, Android, MacOS or malware analysis
  • Proficiency in a high-priority foreign language: preference for Chinese, Russian, Farsi, or Korean.

Why should you join Recorded Future?
Recorded Future employees (or “Futurists”), represent over 40 nationalities and embody our core values of having high standards, practicing inclusion, and acting ethically. Our dedication to empowering clients with intelligence to disrupt adversaries has earned us a 4.8-star user rating from Gartner and more than 45 of the Fortune 100 companies as clients.

We are committed to maintaining an environment that attracts and retains talent from a diverse range of experiences, backgrounds and lifestyles.  By ensuring all feel included and respected for being unique and bringing their whole selves to work, Recorded Future is made a better place every day.

If you need any accommodation or special assistance to navigate our website or to complete your application, please send an e-mail with your request to our recruiting team at careers@recordedfuture.com 

Recorded Future is an equal opportunity and affirmative action employer and we encourage candidates from all backgrounds to apply. Recorded Future does not discriminate based on race, religion, color, national origin, gender including pregnancy, sexual orientation, gender identity, age, marital status, veteran status, disability or any other characteristic protected by law.

Recorded Future will not discharge, discipline or in any other manner discriminate against any employee or applicant for employment because such employee or applicant has inquired about, discussed, or disclosed the compensation of the employee or applicant or another employee or applicant.

Notice to Agency and Search Firm Representatives:
Recorded Future will not accept unsolicited resumes from any source other than directly from a candidate. Any unsolicited resumes sent to Recorded Future, including those sent to our employees or through our website, will become the property of Recorded Future. Recorded Future will not be liable for any fees related to unsolicited resumes.

Agencies must have a valid written agreement in place with Recorded Future's recruitment team and must receive written authorization before submitting resumes. Submissions made without such agreements and authorization will not be accepted and no fees will be paid.