About the role
structured by ORIKey team member in cyber intelligence at a leading firm — researching global cyber threats, identifying correlated threats and impacts, producing finished intelligence assessments, and shaping cybersecurity strategy through threat-informed analysis. Join our elite Applied Cyber Threat Research (ACTR) team within the…
What you will do
- Conducts all-source analysis — fusing multiple intelligence and data sources (e.g., threat reporting, OSINT, technical telemetry, incident data, and vendor intelligence) into a coherent, corroborated intelligence picture and narrative.
- Builds and visualizes attack flows using the MITRE ATT&CK framework — mapping adversary TTPs to security controls and attack surface, highlighting control gaps, and framing findings and priorities against the current threat landscape.
- Develops finished intelligence assessments for a range of stakeholders at the tactical, operational, and strategic levels — spanning specific technologies and applications as well as new business contexts such as mergers and acquisitions targets and unfamiliar industries — to identify vulnerabilitie
- Conducts open-source collection across the surface, deep, and dark web and social media platforms, then reviews, corroborates, and validates collected data for reliability and analytic value before use.
- Proactively monitors and analyzes global cyber threats and performs in-depth research that supports broader cyber operations objectives (e.g., Threat Hunting, Red Team, Purple Team).
What they are looking for
- 4+ years of experience in cyber intelligence, threat assessment, or security research, focusing on cyber threat research and analysis.
- Ability to operationalize MITRE ATT&CK — converting adversary TTPs into attack flows, mapping techniques to controls and attack surface, and framing gaps and priorities against the current threat landscape.
- Proficiency with open-source intelligence (OSINT) collection across diverse sources — including the surface, deep, and dark web as well as social media platforms — and the ability to review, corroborate, and validate collected data for reliability and analytic value before use.
- Practical experience with modern integrated development environments (e.g., VS Code) and AI-assisted / agentic coding tools (e.g., Claude Code, GitHub Copilot) to accelerate the rapid prototyping, building, and testing of tools and automations — paired with the judgment to validate and review AI-gen
Nice to have
- Proficiency in scripting languages (Python, Bash, JavaScript, PowerShell) with experience in automating threat detection, analysis, and response.
- Experience within the Intelligence Community, Defense Intelligence Enterprise, or the broader Military Intelligence community, U.S. Government agencies, and interagency partners (e.g., DHS, DoD, DOJ, and other federal/interagency organizations) — bringing insight into adversary operations, intellige
- Understanding of and ability to action the intelligence lifecycle.
- Experience with SIEM/EDR tools, log analysis, and network traffic analysis to detect and investigate malicious or anomalous activity.
Full posting text
Key team member in cyber intelligence at a leading firm — researching global cyber threats, identifying correlated threats and impacts, producing finished intelligence assessments, and shaping cybersecurity strategy through threat-informed analysis.