Jobs and Careers
QU

Senior Threat Researcher (m/f/x) - Remote anywhere in Spain

QuoIntelligence
SpainRemotefull_timeVerifiedPosted 4 Nov 2024
💰 €55,485/yr

About the role

<h3>Company Description</h3><p>Founded in 2020, <strong>QuoIntelligence</strong> is Europe´s fastest growing startup in the field of <strong>Cyber Threat Intelligence</strong>. Headquartered in Germany, and incorporated in Italy and Spain, we provide companies and institutions with game-changing expertise in the fight against cybercrime. </p><p>Our <em>Intelligence Operation Team </em>analyzes the current and future cyber threat landscape to disseminate timely and accurate tactical/operational/strategic intelligence to external customers and industry peers. The team is distributed across Germany, Italy, Spain, and the US and its members come from both the private cyber security and defense sectors.</p><h3>Job Description</h3><p>We are looking to expand the team’s capabilities by recruiting a <strong>Senior Threat (CTI) Researcher </strong>remotely based anywhere in Spain. </p><p>Intelligence Operation Analysts deliver high value threat information that is tailored to customer needs and is to be shared with risk management specialists, security professionals and policy makers globally. </p><p><strong>Key areas of responsibility:</strong>​​​​</p><ul><li>Detect, investigate, track, and report on regionally focused malicious cyber activities and threat activity matching Clients’ Intelligence Requirements. </li><li>Work with other experienced Cyber/Geopolitical Intelligence analysts to develop tactical/operational/strategic Intelligence products following high writing style and analytical standards. </li><li>Identify, prioritize, and deploy various early detection mechanisms for new activity on malware families and threat actor groups of interest and continually improve threat hunting processes and documentation.  </li><li>Stay on top of developments within the APT threat landscape and track key developments by following publications, blogs, and mailing lists. </li><li>Support the management of critical incidents and crisis situations. </li><li>Work with Customer Success to drive the answering of clients’ Request for Information (RFI). </li><li>Train and mentor Junior researchers in the team. </li><li>Identify new datasets to ingest that enrich QuoIntelligence datalake, and work with the Exploitation&amp;Collection team to ingest such data at scale. </li><li>Propose new analytics which can be developed to improve and/or automate portions of the intelligence cycle. </li><li>Work with executives, technical SMEs, and customers (ad hoc) to enhance cybersecurity programs, incident response, and other activities. </li><li>Stay on top of developments within the threat landscape. </li></ul><h3>Qualifications</h3><p><strong>Qualifications &amp; Skills: </strong></p><ul><li>Bachelor’s degree in Computer Science, Computer Engineering, Information Security, Security Studies, Intelligence, or a related field. Alternatively, 4 additional years of experience in a similar role. </li><li>6 years of experience in Information Security and/or Threat Intelligence. </li><li>Demonstrable experience (public blog, conference presentations, Github projects) conducting technical threat analysis and research and tracking APT and e-crime actors using techniques such as the Diamond Model of Intrusion Analysis or Kill Chain, and knowledge of common TTPs used by cyber threat actors following MITRE ATT&amp;CK Matrix. </li><li>Technical knowledge in methods and procedures for network exploitation and mitigation. Must be able to distinguish different types of exploitation methods </li><li>Demonstrate knowledge in the TCP/IP and OSI model and apply the concept to analysis of log files and metadata. </li><li>Preferred experience with Structured Analytical Techniques, the intelligence cycle, and intelligence writing techniques and methodologies. </li><li>Experience clustering and tracking multiple state-sponsored activity groups using techniques such as the Diamond Model of Intrusion Analysis. </li><li>Knowledge of Windows and/or Linux malware analysis (behavior and static). </li><li>Extensive experience in hunting malicious infrastructures given networking indicators with tools such as Shodan, Censys, FOFA, VirusTotal etc. </li><li>Technical experience with Digital Forensic &amp; Incident Response (DFIR) </li><li>Preferred experience with the development of Intelligence Collection Plan (ICP). </li><li>Experience presenting to different audiences, such as clients, other security experts, and/ or in conferences. </li><li>Excellent interpersonal and teamwork skills; ability to work with globally distributed team members. </li><li>Fluent in English. Additional fluency in other languages such as Italian, Spanish, German or French will be considered as an asset.  </li></ul><h3>Additional Information</h3><p><strong>How is it to work here?</strong></p><ul><li>Fast growing startup in an ever-expanding market.</li><li>A lean organization with an open feedback culture.</li><li>Multicultural and multilingual organization.</li><li>Creative environment where tea

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

QuoIntelligence

View company profile →