Cyber Threat Intelligence Analyst
Job Description
Warwick
What
I.T. & Communications
Type
Contract
Salary
Annual
Cyber Threat Intelligence Analyst Utilities Predominantly remote: 1 day per month onsite in Warwick 6 months Day rate contract
In short: We require a CTI expert to join a strong threat intelligence team for a critical national infrastructure energy client. In this role you will be exposed to OT (Operational Technology) but having experience of this is NOT a prime requisite - more of a nice-to-have. Ultimately, we need a solid Cyber Threat Intelligence SME.
In full:
The role will work directly across all areas of Cyber Defend to produce bespoke and technical intelligence across Tactical, Strategic, and Operational intelligence. This role will work with key stakeholders from around the business in vital operational areas such as critical national infrastructure (CNI) and Operational Technology (OT).
Provides actionable technical intelligence to our detection engineers, threat hunters and security operations to improve security controls based from threat intelligence.
Monitor, research and evaluate cyber threats and trends that may impact business objectives and provide corresponding guidance and recommendations to inform risk assessments and business decisions relating to security posture, operations, investments and partners.
Develop, implement and maintain a framework for monitoring and analysis, centred on clear intelligence requirements and key indicators or warnings. Engage with senior business stakeholders to define and agree intelligence requirements and understanding of assessments and recommendations.
Provide direction and outlook by horizon scanning for future trends and threats in the cyber domain. Simultaneously work closely with Cyber Defend and the SOC to ensure that timely technical intelligence is distributed to allow effective cyber defence mitigations to be implemented in a timely fashion.
Engage with high profile intelligence partners in Gov't and industry to set requirements, ensure collection against intelligence requirements and corroborate assessments. Represent and speak at intelligence sharing and analysis platforms that cut across Gov't and multiple sectors.
Generate confidence in intelligence products by managing disagreement and questions relating to intelligence sources and assessments. Manage conflict and orchestrate consensus in high pressure and politically sensitive environments, which ensuring operational security of assessments and sources at all times.
Key accountabilities:
Conduct in-depth analysis of cyber threat groups, threat actor tools, motivation and Tactics Techniques and Procedures (TTPs) to allow for reverse engineering of threat tools/exploits for the purpose of configuring and testing scripted countermeasures/controls in the network.
A strong understanding of threats posed to OT and Industrial Control Systems (ICS) and programmable logic controller (PLC) systems.
Articulating complex concepts to various stakeholders across the business to include knowledge of TTPs that involve cloud technology.
Consuming new threat reports, extracting relevant and actionable intelligence including TTPs and behavioural indicators.
Working closely with our detection engineers and threat hunters to build bespoke detections to detect novel TTPs based on intelligence.
Develop comprehensive threat intelligence reports detailing your findings, risk assessments, and recommended mitigation strategies.
Monitor and gather threat intelligence from open sources, dark web forums, industry feeds, and other relevant data sources.
