Junior Cyber Threat Analyst
Junior Cyber Threat Analyst
INFINITO0-2 Years
- Posted a day ago
- Be among the first 10 applicants
Job Description
Role Background
TTP MNL reports on technical subject matter such as malware developments, offensive security tools, vulnerability exploits, cloud security, and mobile security. Junior Cyber Threat Analysts are expected to continuously familiarize themselves with these topics and identify threat leads from a variety of sources. Junior Cyber Threat Analysts are also expected to analyze malware and create effective detections, which their senior peers will review and validate. Junior Cyber Threat Analysts must be able to communicate this subject matter effectively to various audiences, both verbally and in writing.
Specific Duties and Responsibilities
Key Detail Identification: During research, identify and take note of infection chains, host and network IoCs, malware samples, threat actors, and MITRE ATT&CK tactics and techniques
Cadence: Write at least 2 TTP Instance notes daily
Quality: Authored TTP Instances should include minimal grammatical or syntax errors. Plagiarism is not acceptable.
Report any potential or committed non-conformity, observation and/or security event or risks to immediate supervisor.
Required Skills
TTP MNL reports on technical subject matter such as malware developments, offensive security tools, vulnerability exploits, cloud security, and mobile security. Junior Cyber Threat Analysts are expected to continuously familiarize themselves with these topics and identify threat leads from a variety of sources. Junior Cyber Threat Analysts are also expected to analyze malware and create effective detections, which their senior peers will review and validate. Junior Cyber Threat Analysts must be able to communicate this subject matter effectively to various audiences, both verbally and in writing.
Specific Duties and Responsibilities
- Threat Lead Identification: Research new adversary tactics, techniques, and procedures (TTPs) using open sources (public information such as security vendor reporting, social media, code repositories); closed sources (dark web and underground forums); and proprietary sources.
Key Detail Identification: During research, identify and take note of infection chains, host and network IoCs, malware samples, threat actors, and MITRE ATT&CK tactics and techniques
- Author Insikt Notes: Write TTP Instances detailing identified threat leads. TTP Instances include a combination of information from open-source reporting and
Cadence: Write at least 2 TTP Instance notes daily
Quality: Authored TTP Instances should include minimal grammatical or syntax errors. Plagiarism is not acceptable.
- Malware Analysis: Using sandbox environments and static analysis tools, analyze malware samples associated with threat leads.
- Detection Engineering: Create malware or vulnerability detections (e.g. YARA, Sigma, Snort) that can be used for threat hunting, detection, and classification. Cadence: Create at least 1 malware or vulnerability detection per month Delivery: In most cases, these detections will be delivered alongside a TTP Instance.
- Information Security: Adhere to and implement Infinit-O's quality and information security policies and carry out its processes and procedures accordingly. Protect client-supplied and generated-for-client information from unauthorized access, disclosure, modification, destruction, or interference (see also Table of Offenses)
Report any potential or committed non-conformity, observation and/or security event or risks to immediate supervisor.
Required Skills
- Strong written communication in English
- Demonstrable experience writing reports on technical subject matter (e.g. malware, vulnerability exploits, offensive security tools) in a clear, concise, and logical format
- Disciplined time management
- Self-starting, self-motivated, and thrive in a collaborative environment
- Ability to receive and apply constructive feedback from peers and leadership
- B.S. equivalent in computer science, information systems, or cyber intelligence
- At least six (6) months of professional experience
- Experience working with open-source intelligence (OSINT) and/or large data sets
- Experience working with sandboxes, virtual machines, and malware analysis tools
- Familiarity with the MITRE ATT&CK Framework, including the ability map reported
- activity to ATT&CK tactics and techniques
- Familiarity with interpreting and mapping cyberattacks to the Diamond Model of Intrusion Analysis
- Adeptness in cybersecurity and data protection
- Experience creating malware detections (e.g. YARA, Sigma, Snort)
- Proficiency in scripting or programming languages (PHP, C, C#, C++, Python, PowerShell, Go, JavaScript, Rust)

