Jobs and Careers
SA

Operational Cyber Threat Intelligence Analyst

SAP
Newtown Square, PA, US, 19073, United Statesfull_timeVerifiedPosted 8 Aug 2024

About the role

We help the world run better


At SAP, we enable you to bring out your best. Our company culture is focused on collaboration and a shared passion to help the world run better. How? We focus every day on building the foundation for tomorrow and creating a workplace that embraces differences, values flexibility, and is aligned to our purpose-driven and future-focused work. We offer a highly collaborative, caring team environment with a strong focus on learning and development, recognition for your individual contributions, and a variety of benefit options for you to choose from. 

 

Founded in 1972 in Germany, SAP stands as a global leader in enterprise software and cloud technology, serving businesses of all sizes across various industries. Renowned for its innovative solutions, SAP provides a comprehensive suite of software applications ranging from ERP (Enterprise Resource Planning) and CRM (Customer Relationship Management) to analytics and supply chain management. With a customer-centric approach, SAP empowers organizations to streamline operations, drive efficiency, and gain valuable insights to make informed business decisions. Through its robust cloud platform, SAP offers scalable and agile solutions that enable businesses to adapt to evolving market demands and digital transformations seamlessly. With a steadfast commitment to innovation and excellence, SAP continues to shape the future of technology and remains a trusted partner for businesses worldwide.

 

SAP is seeking an experienced Operational Cyber Threat Intelligence Analyst to work in SAP’s Cyber  Intelligence & Threat Hunting team as part of the larger Detect Organization.  This is a position that requires deep knowledge of threat actor TTPs and the technical prowess to collect, process, and exploit raw data to identify and disrupt advanced cyber adversaries.   Successful candidates will have demonstrable experience using advanced scripting and automation skills to collect a wide range of raw telemetry and signals to drive threat detection operations.  Operating “left of boom,” this position requires a proactive and innovative analyst capable of leveraging a diverse range of collection methods—including emerging artificial intelligence tools—to identify and exploit the most actionable data sets available.  Additionally, this role will work with the Strategic Intelligence team to help translate tactical and operational threats into strategic risk reporting and over-the-horizon threat assessments.

 

In this role you will craft custom scripts to collect highly actionable information that enables cyber intelligence operations and informs the organization’s understanding of the threat landscape at the adversary level.  In addition, you will work with SIEM and SOAR technologies to further exploit and operationalize collected information to drive threat detection and threat hunting efforts.  You will identify gaps in tooling utilization and optimize existing technologies to further mature and scale cyber intelligence capabilities.  You will work with peer security teams and relevant stakeholders across lines of business to collect and disseminate threat intelligence as well as support critical incidents and investigations.  You will identify, pivot, and enumerate adversarial infrastructure and build automated playbooks to drive proactive security actions across the organization. Lastly, this role requires a consummate team player willing to go above and beyond in delivering a world class operational cyber threat intelligence capability in support of SAP and its global business.

 

 

Key Responsibilities:

 

  • Identify, track, and analyze cyber threat actors and their tactics, techniques, and procedures (TTPs) to help drive threat detection operations (TDO) by supporting detection engineering detection logic creation.
  • Develop and maintain automated tools and scripts to enhance the collection and processing of cyber threat intelligence.
  • Identify opportunities to drive tool optimization (i.e., threat intelligence platform) through advanced integrations with wider organizational technology stack.
  • Track and enumerate prioritized adversary C2 infrastructure using open source tools to enable “left of boom” analysis and trigger automated playbook actions.
  • Identify opportunities to integrate generative AI technologies into intelligence collection, processing, and analysis workflows.
  • Use coding skills (e.g., Python, PowerShell) to create custom solutions for data extraction, correlation, and analysis.
  • U

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

SAP

View company profile →