Senior Intelligence Analyst, Advanced Intelligence Access
Mandiant is a recognized leader in cyber security expertise and has earned the trust of security professionals and company executives around the world. Our unique combination of renowned frontline experience, nation-state grade threat intelligence, machine intelligence, and the industry's best security validation ensures that Mandiant knows more about today's advanced threats than anyone.
- Understand the customers' Cyber Threat Intelligence (CTI) requirements. Identify their needs and opportunities for deployment of CTI within their operations to have the greatest defensive impact.
- Evaluate tools and best practices for tracking advanced threats, Tools, Techniques, and Procedures (TTPs) of attacker’s motivations, and industry and attacker trends.
- Perform analysis of customer data, taking their bespoke sources to identify threat activity, or to build and automate investigative workflows.
- Write intelligence reporting against customer requirements, appropriate for their intelligence analysts or executive leaders.
- Support the integration of CTI into customer's security processes and technologies, including Security Information and Event Management (SIEM) and Threat Intelligence Platform (TIP) systems.
Minimum qualifications:
- Bachelor's degree or equivalent practical experience.
- 7 years of experience working in a government or military environment, leveraging and developing CTI for network, host and log analysis, to enable the detection and response to cyber threats.
- Experience in leveraging CTI to describe, track and develop new intelligence on advanced persistent threats.
- Experience in conducting or supporting incident response and investigations within enterprise environments.
Preferred qualifications:
- Experience in SOC operations, threat hunting, detection engineering and SOC workflow optimization.
- Experience in network Intrusion Detection System (IDS) monitoring, Endpoint Detection and Response (EDR) solutions, SIEM and Security Orchestration, Automation, and Response (SOAR) integration, and managing and contributing CTI into a threat intelligence platform.
- Understanding of core cyber security concepts, common enterprise IT infrastructure components, operating system internals and networking.