Cyber Threat Intelligence Analyst
Salary: $180,000 per year
About the role
Dragos Global Threat Intelligence defends the infrastructure that powers civilization—from clean water and reliable power to food processing and oil & gas production. We're seeking an OT Cyber Threat Intelligence Analyst to embed with a Singapore government security team as a trusted, autonomous expert. You'll lead threat hunts, deliver tailored intelligence across multiple formats, and represent Dragos inside cleared environments—making independent judgment calls that directly shape government strategy while collaborating across Dragos delivery teams to amplify intelligence impact.
Responsibilities:
Directly support the client with ICS/OT cyber threat intelligence needs, including high-stakes moments involving national security priorities, while establishing credibility to drive priorities rather than simply respond to tasking
Drive ICS/OT CTI research, analysis, and threat hunting using proprietary and commercial resources, performing both freeform and hypothesis-driven hunts by analyzing network traffic and industrial protocols to surface anomalous behavior
Support the client in establishing baseline OT asset and network behaviors across Singapore's critical infrastructure using Dragos Platform, Synapse, and complementary tools to validate and prioritize leads
Contextualize ICS/OT threats and risks relevant to the client's objectives, provide guidance on best practices and mitigations, and develop deep expertise in threats specific to the client's OT environment
Translate technical hunt results into MITRE ATT&CK for ICS mappings and confidence-based assessments that non-technical stakeholders can act on
Support the client during incident response engagements and exercises
Develop industry-focused technical and strategic ICS/OT CTI content and provide feedback to internal Dragos teams to maximize intelligence impact across the organization
Qualifications:
Must be a Singapore citizen and have an active Security Clearance
Minimum 4 years of cyber threat intelligence experience using multiple data sources (eg, NetFlow, open-source intelligence, SIEMs, malware repositories) to develop analysis products
Hands-on threat hunting experience, including packet capture analysis and industrial protocol inspection
Strong hands-on expertise with both freeform and hypothesis-driven threat hunting methodologies
Experience serving in a customer-facing role with demonstrated ability to manage stakeholders independently and effectively
Strong technical and strategic writing skills for developing CTI analysis products, including confidence-based assessments and threat modeling frameworks (such as Diamond Model of Intrusion Analysis)
Proficiency with data aggregation, hunting, and analysis tools (e.g., Synapse) and experience leveraging AI/LLM resources in CTI workflows
Preferred Qualifications:
Deep knowledge of ICS/OT threats across industrial verticals, including adversary TTPs, historical attacks, relevant technologies (PLCs, HMIs, RTUs), and network protocols and topologies
The ability to independently scope, develop, and deliver CTI analysis using industry frameworks (MITRE ATT&CK for ICS, D3FEND, ICS Cyber Kill Chain)