Threat Intelligence & Threat Hunting Specialist - 12 Months Contract
Hays · Riyadh, Saudi Arabia
Apply & track with Apply EdgeWe are looking for a Cyber Threat Intelligence & Threat Hunting Specialist to establish and operate the Cyber Threat Intelligence (CTI) function while conducting proactive threat hunting activities across the organization's technology environment.The successful candidate will be responsible for collecting, analyzing, and operationalizing threat intelligence, identifying emerging cyber threats, performing intelligence-driven threat hunting, and enhancing detection capabilities across security monitoring platforms. The role will work closely with SOC, MSSP, IT Security, and Infrastructure teams to strengthen the organization's cyber defense posture and ensure alignment with financial sector security requirements and threat landscapes.Key ResponsibilitiesCyber Threat Intelligence (CTI)Develop, implement, and operate the Cyber Threat Intelligence (CTI) program.Collect, evaluate, and analyze threat intelligence from multiple sources, including:Commercial and open-source threat intelligence feedsFinancial sector ISACs and intelligence-sharing communitiesVendor security advisoriesDark web and underground monitoring sourcesProduce actionable intelligence related to:Cyber fraud campaignsPhishing attacksMalware infectionsRansomware threatsAdvanced Persistent Threats (APTs)Monitor the external threat landscape and assess its potential impact on the organization.Maintain threat actor profiles, indicators of compromise (IOCs), and adversary tracking repositories.Threat HuntingConduct proactive threat hunting activities across endpoint, network, and identity environments.Analyze:EDR telemetrySIEM log dataNetwork security logsIdentity and access management logsIdentify and investigate:Suspicious user activitiesUnauthorized access attemptsHidden persistence mechanismsLateral movement techniquesPrivilege escalation activitiesIndicators of compromiseDevelop and continuously improve threat hunting methodologies, hypotheses, and playbooks.Detection Engineering & Security MonitoringCollaborate with SOC and MSSP teams to enhance monitoring capabilities.Develop and improve SIEM detection use cases.Tune and validate security alerts and detection rules.Identify gaps in detection coverage and recommend improvements.Support the development and enhancement of EDR and SIEM detection content.Reporting & Intelligence ProductsProduce Monthly Threat Intelligence Reports covering:Emerging cyber threatsFinancial sector threat trendsActive threat campaignsNewly disclosed vulnerabilitiesThreat actor activitiesRecommended mitigation actionsPresent intelligence findings to cybersecurity leadership and stakeholders.Create executive and technical threat briefings when required.Incident Response SupportSupport cyber incident investigations through intelligence analysis.Provide context on threat actors, TTPs, indicators, and attack patterns.Assist SOC teams during containment and remediation activities.Correlate threat intelligence with security events and incidents.Required QualificationsEducationBachelor's Degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field.Experience4-8 years of experience in Cyber Threat Intelligence, Threat Hunting, SOC Operations, Incident Response, or Cybersecurity Operations.Experience within banking, financial services, fintech, or other regulated industries is highly preferred.Demonstrated experience conducting intelligence-driven threat hunting investigations.Required Technical SkillsCandidates should have hands-on experience with:Cyber Threat Intelligence (CTI)Threat Hunting MethodologiesSIEM Platforms (Microsoft Sentinel, Splunk, QRadar, ArcSight, etc.)Endpoint Detection & Response (EDR) SolutionsMITRE ATT&CK FrameworkIndicator of Compromise (IOC) AnalysisThreat Actor ProfilingMalware and Phishing AnalysisSecurity Incident InvestigationDetection EngineeringLog Analysis and CorrelationSecurity Operations Center (SOC) Processes