Research Analyst - Cyber Threat Intelligence (m/f/x) - Remote anywhere in Spain
- Full-time
- Team: Research
- Department: Intelligence
Company Description
Founded in 2020, QuoIntelligence is Europe´s fastest growing startup in the field of Cyber Threat Intelligence. Headquartered in Germany, and incorporated in the United States, Italy and Spain, we are committed to informing decision makers of current and prospected cyber and geopolitical threats by providing Finished Intelligence, tailor-made for their organization.
Our Intelligence Operations Team analyzes the current and future cyber threat landscape to disseminate timely and accurate tactical/operational/strategic intelligence to external customers and industry peers.
The team is remote and distributed across Germany, Italy, Spain, and the US.
Job Description
- Detect, investigate, track, and report on regionally focused malicious cyber activities. Stay on top of developments within the APT threat landscape and track key developments by following publications, blogs, and mailing lists.
- Contribute to the development of reports and research in English based on research discoveries and based on developed SME areas. These high-impact data-driven research projects would answer pressing questions related to threat detection, analysis, and mitigation.
- Carry out in-depth investigations into alerts, anomalies, intrusions, malware, etc. reported by the monitoring team or by our clients.
- Identify new datasets to ingest and propose new analytics which can be developed to improve and/or automate portions of the intelligence cycle.
- Work with the IntelOps team to identify, prioritize, and deploy various detection mechanisms for malware families and threat actor groups of interest.
- Use current understanding of industry practices and processes to develop high-impact research questions and hypotheses.
- Use both quantitative and qualitative methods of analysis to best answer high-priority research questions around threats.
- Use both internal and external data to find the best and most comprehensive answer to threat research questions. This may include using already developed external data pipelines or developing new collection methods according to research needs.
Qualifications
Essential requirements:
- Bachelor’s degree in Computer Science, Computer Engineering, Information Security, Security Studies, Intelligence, or a related field. Alternatively, 4 additional years of experience in a similar role.
- 3 years of experience in Information Security, particularly Threat Intelligence, Incident Response, Security Operations, Vulnerability Management. Demonstrable experience conducting technical threat analysis and research.
- Demonstrable research and analytic competencies. Prior experience in research or analysis is preferred, particularly as it relates to malicious cyber activity. Experience with structured analytical techniques, the intelligence cycle, and intelligence writing techniques and methodologies.
- Knowledge of vulnerabilities, cryptography, scripting skills (python, shell, powershell, etc.)
- Good knowledge of the EU threat landscape and cyber threat activity, including actors, TTPs, and targets.
- Experience clustering and tracking multiple state-sponsored activity groups using techniques such as the Diamond Model of Intrusion Analysis
- Knowledge of the signals of specific threat actors, their cross-platform tactics, and how they evolve or change over time.
- Good knowledge of the different types of malwares and how they operate. Ability to perform simple assessments of malicious files being comfortable with basic static and dynamic analysis.
- Familiarity with common IOC formats for both host and network level continuous monitoring, such as YARA and Sigma
- Excellent critical thinking and interpersonal and teamwork skills; ability to work with globally distributed team members.
- Fluency in English.
- Current holder of an EU Passport or a permanent work permit for Spain
Desirable skills and experience:
- Experience with big data indexing and searching utilities such as Elastic Search
- Knowledge of the specifics regarding Italian and/ or German threat landscapes.
Additional Information
How is it to work here?
- Fast growing startup in an ever-expanding market.
- A lean organization with an open feedback culture.
- Multicultural and multilingual organization.
- Creative environment where team members are encouraged to contribute to processes, decisions, planning and culture.
What's the pay like?
For this job and country, the band we have set starts at 49,500€ TTC. This is:
- Base Salary: 41,818 € gross annual salary
- Bonus: 10% of annual gross base salary
- Benefits: 3,500€ for Year1 as outlined below.
What's in it for you?
- Work from anywhere in Spain or Italy!
- Great opportunity to build a career as the company doubles in size in the next 12 months.
- Be comfortable: 1,000 EUR gross home office budget.
- Be learning: 2,000 EUR / year personal development budget.
- Be well: 500 EUR gross / year wellness allowance
- Be with your team: team get-together budgets.
- Yearly global meetups in great locations. In 2022 we spent a week in Rome. This year we'll spend the last week of September in Rimini!
What's the recruitment process like?
- You apply and fill a couple of screening questions.
- We review all applications.
- We invite the top 25% to an online assessment via Vervoe and interview with our People Team via MS Teams.
- We schedule the top 4-5 candidates with our Head of Intel Ops and our principal analyst.
- We make an offer and conduct background checks.
QuoIntelligence is an equal opportunity employer. We strongly believe that diversity is essential for good intelligence work and are committed to creating an inclusive environment for all employees.
By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply