We are looking for a Threat Intelligence Researcher to join its Threat Intelligence Group and support the companys Cyber Threat Intelligence Exposure Management (CTIEM) services, Incident Response engagement and proactive services. In this position, you will identify, investigate, and monitor external cyber threats and organizational exposures across the open web, dark web, social media platforms, and other intelligence sources. You will help organizations understand and reduce their external attack surface, detect brand abuse and malicious activity targeting their assets, and develop innovative intelligence-driven monitoring capabilities leveraging automation and AI technologies.
The successful candidate should be a creative, highly motivated, and independent researcher with strong analytical skills, a deep understanding of attacker methodologies, and a passion for solving complex intelligence challenges. As part of the role, you will engage with clients, support operational teams, and contribute to the development of cutting-edge CTIEM capabilities.
Main Responsibilities:
Conduct proactive monitoring and investigations across the open web, dark web, forums, marketplaces, messaging platforms, and social media channels to identify threats targeting client organizations.
Analyze organizational exposure across external attack surfaces, including internet-facing assets, leaked information, exposed services, and emerging risks.
Investigate and identify brand abuse activities, impersonation attempts, phishing campaigns, fraudulent domains, and other malicious activities targeting clients.
Detect and assess data exposures and information leaks through a variety of intelligence sources, commercial platforms, and proprietary tools.
Utilize Attack Surface Management (ASM) platforms and related technologies to identify, prioritize, and assess external security exposures.
Develop and enhance intelligence collection, detection, and monitoring capabilities through automation and AI-driven solutions, primarily using Python.
Produce comprehensive intelligence reports, exposure assessments, and actionable recommendations for clients and internal stakeholders.
Engage directly with clients to present findings, explain risks, and support remediation efforts.
Collaborate closely with Incident Response teams to support ongoing investigations.
Requirements: Main Requirements
3+ years of experience in Cyber Threat Intelligence, Exposure Management, Threat Research, Cyber Investigations, or related cybersecurity domains.
Proven experience conducting investigations across open web, dark web, and social media intelligence sources.
Strong understanding of attacker methodologies with emphasis on reconnaissance, phishing, credential theft, social engineering, and initial access techniques.
Experience with Attack Surface Management (ASM), External Attack Surface Management (EASM), Digital Risk Protection (DRP), or related technologies.
Experience identifying brand abuse, impersonation campaigns, phishing infrastructure, and malicious domain activity.
Familiarity with data leak investigations, exposed credentials monitoring, and external exposure analysis.
Hands-on experience developing automation, intelligence collection, or detection capabilities using Python.
Strong analytical and investigative mindset with the ability to connect disparate pieces of information into meaningful intelligence.
Excellent written and verbal communication skills, including the ability to communicate technical findings clearly to clients and executives.
Self-motivated, independent, and accountable, with the ability to manage investigations from initiation through delivery.
Team player with strong interpersonal skills and a collaborative approach.
This position is open to all candidates.