Apply Edge Start your job search

Analyst - Cyber Threat Intelligence

LanceSoft Middle East · Dubai, United Arab Emirates

Apply & track with Apply Edge
Job Title: Analyst - Cyber Threat IntelligenceLocation: DubaiDuration: 1 Year ext.SummaryThe Analyst – Cyber Threat Intelligence will support the Digital Defence Center (DDC) by researching, analyzing, and reporting on emerging cyber threats to protect the organization’s people, systems, and assets. The role will focus on threat hunting, cyber incident response, digital forensics, offensive security assessments, and threat intelligence across complex on-premises and multi-cloud environments.Key ResponsibilitiesConduct proactive threat hunting across on-premises and cloud environments using digital forensics techniques, security tools, and custom scripts.Perform offensive security assessments using tools and techniques such as Metasploit, exploit development, OSINT, and enterprise network attack simulations.Analyze cyber breaches and attacker behavior across all stages of an attack and map findings to the MITRE ATT&CK framework and Cyber Kill Chain.Conduct incident response and digital forensic investigations during active security breaches.Analyze system, security, and application logs to identify indicators of compromise, attacker activity, and security weaknesses.Research emerging cyber threats, threat actors, vulnerabilities, and attack techniques using Threat Intelligence Platforms.Support threat intelligence, threat hunting, incident response, penetration testing, red teaming, and purple team activities.Develop and use custom forensic tools, scripts, and automation to support investigations and threat hunting.Work with large datasets using SQL/KQL, Python, Splunk, and related security analytics technologies.Utilize and analyze data from EDR solutions to identify and investigate suspicious activities.Report findings and provide actionable intelligence that contributes to measurable improvements in the organization’s overall security posture.Collaborate with cybersecurity and technology teams during major cyber incidents and security investigations.Required QualificationsBachelor’s degree in Computer Science, Engineering, Business, or a related discipline.5–7 years of overall experience, with 3–5 years of relevant cybersecurity experience.Around 3+ years of technical experience in Digital Forensics and Incident Response (DFIR), Security Operations, Threat Hunting, Threat Intelligence, Cyber Incident Response, Penetration Testing, or Red Teaming.Strong experience with Cyber Kill Chain and attacker techniques across the complete attack lifecycle.Hands-on expertise with Threat Intelligence Platforms, including Recorded Future, Flashpoint, Blueliv, Anomali, ThreatIQ, or similar platforms.Demonstrable experience with digital forensics tools, techniques, custom tools, and scripting.Strong capability in analyzing and interpreting system, security, and application logs.Experience with offensive security tools and techniques, including Metasploit, exploit development, OSINT, and enterprise network attack simulation.Advanced understanding of operating system internals and security mechanisms.Strong knowledge of digital forensics, threat intelligence, incident response, and threat hunting.Experience working with large datasets using SQL/KQL, Python, Splunk, or similar technologies.Working knowledge of Endpoint Detection and Response (EDR) solutions.Ability to conduct forensic investigations and incident response within complex on-premises and multi-cloud environments.Preferred CertificationsGIAC Certified Intrusion Analyst (GCIA)GIAC Certified Incident Handler (GCIH)GIAC Certified Forensic Examiner (GFCE)GIAC Certified Forensic Analyst (GCFA)