Back to all jobs
C

Senior Cyber Threat Intelligence & Forensics Analyst

CallTek

WorldwideRemote3w ago
Employment
Full-time
Seniority
Senior

About the role

We are looking for a seasoned cybersecurity professional to bridge the gap between "knowing the enemy" and "stopping the attack." You will lead our Threat Intelligence efforts to predict and detect adversaries, spearhead Incident Response when breaches occur, and perform deep-dive Digital Forensics (DFIR) to understand the how and why. This is a high-impact role requiring technical depth, analytical rigor, and the ability to stay calm under fire.

Key Responsibilities:

1. Threat Intelligence (Predict & Prevent)

  • Adversary Tracking: Monitor TTPs (Tactics, Techniques, and Procedures) of relevant threat actors using the MITRE ATT&CK framework.
  • Intelligence Lifecycle: Collection, processing, analysis, and dissemination of actionable intelligence to internal stakeholders.
  • Detection Engineering: Translate raw intelligence into custom SIEM alerts, YARA rules, and Sigma signatures.

2. Incident Response (Detect & Respond)

  • Crisis Management: Act as the technical lead during high-severity security incidents, coordinating containment and eradication efforts.
  • Threat Hunting: Conduct proactive hunts across the environment to identify stealthy persistence or lateral movement that automated tools missed.
  • Playbook Development: Design and automate IR playbooks to reduce Mean Time to Respond (MTTR).

3. Digital Forensics (Analyze & Document)

  • Evidence Acquisition: Perform dead-box and live-memory forensics on Windows, Linux, and Cloud environments (AWS/Azure/GCP).
  • Root Cause Analysis: Reconstruct attack timelines to determine the initial vector and the extent of data exfiltration.
  • Reporting: Translate complex technical findings into "executive-level" reports for legal, compliance, and leadership teams.

Requirements

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field.
  • Experience: 5+ years in a dedicated SOC, IR, or Intel role (ideally within a CSIRT or MSSP).
  • The Toolkit: Mastery of tools like Splunk/ELK, CrowdStrike/SentinelOne/VisionOne, Magnet AXIOM/FTK/EnCase/Autopsy, Sandbox, Volatility, and Wireshark.
  • Programming: Ability to script in Python or PowerShell to automate repetitive tasks or parse forensic artifacts.
  • Certifications: We value skills over paper, but GIAC (GCIH, GCFA, GCTI), CFE, CTIA or CHFI are highly preferred.
  • Familiarity with incident response processes and frameworks.
  • Strong analytical and problem-solving skills with attention to detail.
  • Excellent verbal and written communication skills to present complex technical information clearly.

741,000+ hidden jobs like this

CallTek and thousands of companies post here first — often days before LinkedIn or Indeed. Your first 5 applications are free; go Pro to apply without limits.

Everything Pro unlocks:

  • Unlimited applications — free stops at 5
  • Track every application in one place
  • Apply straight to the source, one click
  • Save & organize roles you love
  • Roles pulled from company boards before the big sites

Weekly

$9.99
$4.99/week

For an active search. Cancel anytime.

Most popular

Monthly

$24.99
$12.99/month

The smart pick. Save 35% vs weekly.

Lifetime

$99
$49.99once

Pay once. Every future feature, forever.