About the Role
Team Cymru analysts make a difference every day, leading in the battle against those intent on harming others. This role provides a vital bridge between technical and strategic intelligence research, writing for both practitioner and senior leadership audiences to understand the impact of the threat, while explaining the technical details and rationale behind those assessments.
Responsibilities
- Conduct extensive, proactive research into threat actors, malware families, campaigns, and evolving TTPs.
- Investigate and present operational and strategic intelligence on threat actors, including attribution, motivation, capability assessment, and geopolitical context.
- Lead short- and long-term threat tracking projects, identifying intelligence gaps and proposing targeted research.
- Evaluate tools, methodologies, and best practices for understanding adversary TTPs, and share knowledge and techniques with peers.
- Perform deep network traffic and infrastructure analysis using Team Cymru's unique global dataset.
- Analyze PCAP, NetFlow, passive DNS (PDNS), open ports, certificates, and other datasets to map malicious infrastructure.
- Identify and refine indicators of compromise (IOCs) and threat actor TTPs, translating these into automated tracking mechanisms.
- Receive, triage, and respond to customer requests with timely, written technical threat intelligence reports.
- Ensure all finished intelligence products meet Team Cymru's analytic standards.
- Conduct peer review of colleagues' reporting.
- Work closely with colleagues in the development of analytical tools, data analytics systems, research methodologies, and analysis automation capabilities.
- Support threat detection and data acquisition teams to align signature development and telemetry collection.
- Participate in working groups, industry events, and community collaboration.
Requirements
- 5+ years of experience as a threat intelligence analyst, network forensics analyst, or IT security analyst.
- Exceptional oral and written communication skills, with the ability to produce customer-facing intelligence reports under time pressure.
- Proven track record of leading complex analytical projects or investigations.
- Ability to manage multiple concurrent work streams.
- Comfortable forming assessments from incomplete or ambiguous data.
- Proven ability to work effectively within a distributed, remote team environment.
- Willingness to conduct peer review and share tradecraft knowledge.
- Experience tracking APT, nation-state, or cybercriminal actors.
- Ability to contextualize actor activity within the broader geopolitical or strategic landscape.
- Outstanding network infrastructure and traffic analysis skills: PCAP, NetFlow, PDNS, open ports, certificates.
- Deep working knowledge of IP networking and internet services: DNS, HTTP/HTTPS, TLS, VPNs, and routing protocols (BGP).
- Demonstrated knowledge of operating system concepts.
- Experience developing and contextualizing indicators of compromise.
- Understanding of their deployment in host and network-level detection architectures.
- Working proficiency in SQL and querying and analyzing large disparate datasets.
- Strong familiarity with common OSINT platforms and research techniques.
- Occasional travel within the UK and internationally for customer workshops, industry events, and team meetings is required.
Skills
- Analytical tradecraft
- Deductive reasoning
- Critical thinking
- Structured analysis techniques
- Estimative language
- Confidence levels
- Network infrastructure analysis
- Network traffic analysis
- PCAP analysis
- NetFlow analysis
- Passive DNS (PDNS) analysis
- Open ports analysis
- Certificates analysis
- IP networking
- Internet services (DNS, HTTP/HTTPS, TLS, VPNs)
- Routing protocols (BGP)
- Operating system concepts
- Indicators of compromise (IOCs)
- SQL
- OSINT platforms
- Subject Matter Expert (SME) for a specific regional or threat actor group
- Programming or scripting proficiency (preferably Python)
- Public speaking
- AI systems
- Linux servers
- Malware analysis
- Network analysis (YARA, Zeek, Suricata, Sandbox reporting)
- Malware reverse engineering (static and dynamic analysis)
- Common tooling (Ghidra, IDA Pro, x64dbg)
- Hosting providers
- ISPs
- Internet exchanges
Location
- Remote
Work Type
- Remote
- Full-time
Experience Level
- Senior
Education Level
- Bachelor's degree in Computer Science, Computer Engineering, Cybersecurity, or equivalent (preferred)
About the Company
- Team Cymru is the leader in Internet Threat Intelligence.
- Our unique and global insight empowers an amazing team of analysts to develop industry leading intelligence that is critical to the success of our customer's cyber security efforts.
- Team Cymru is an ardent supporter of the Threat Intelligence community.
- We enable industry collaboration by hosting exclusive conferences each year.
- Our team members actively participate in working groups, attend industry events, and work directly with fellow community peers.
- At Team Cymru, we provide unmatched global threat intelligence that empowers organizations to proactively disrupt adversaries.
- You'll be at the forefront of cybersecurity innovation, helping customers harness the full power of our threat intelligence to achieve critical business and security outcomes.
- We offer a collaborative, mission-driven culture where your expertise and impact will directly contribute to improving global security.
Equal Opportunity
- Team Cymru is an equal opportunity employer and welcomes applicants from all backgrounds.
