Senior Cybercrime Threat Analyst
Advanced Cybercrime and Engagements
Posted on 2/25/2023
INACTIVE
Locations
Washington, DC, USA
Experience Level
Entry
Junior
Mid
Senior
Expert
Requirements
- 6+ years of professional experience in roles in cyber intelligence, cyber investigations, or other related disciplines
- Knowledge and experience with analytic tradecraft, the intelligence cycle, open-source intelligence gathering techniques, and strong intelligence writing skills, techniques, and methodologies
- Familiarity with legal and regulatory requirements for acquisition of digital information and the standards for collecting digital evidence under US Federal laws
- Significant experience conducting investigations and tracking campaigns on threat groups operating on the darknet with a focus on topics such as leaked databases and credentials, ransomware, DDoS operations, bot networks, criminal marketplaces and other current and emerging threats
- Deep knowledge and understanding of malicious tools and software used for cybercriminal activity and ability to track and trace groups using a wide range of telemetry
- Knowledge of money laundering, fraud, and current cyber-enabled crime TTPs
- Firm knowledge and understanding of most computer operating systems, networking concepts and security fundamentals
- Firm understanding of blockchain and cryptocurrencies technologies to include trades, transfers, tracking, maintaining, documentation and preservation
- Understanding of security best practices to maintain the anonymity of both yourself and Recorded Future while operating on dark web sources
- Ability to work well with others both senior and junior to yourself as part of a team working towards a unified goal
- Foreign language proficiency: strong preference for Russian, Chinese, Farsi, or Southeast Asian languages
- BA/BS or MA/MS degree or equivalent experience in Computer Science, Computer engineering, Computer programming, Digital Forensics, or a related discipline
- Government, security or law enforcement experience
- Extensive knowledge of Hacktivist trends and activities
- Extensive knowledge or understanding of the links and relationships between cybercriminal, hacktivist, extremist, and nation-state operations and organizations
- Extensive knowledge of money laundering TTPs
Responsibilities
- Create and devise new sourcing, collecting, and curating new data into the Recorded Future Platform
- Lead and direct finished intelligence products for Recorded Future Analyst on Demand clients
- Write reports ranging from brief descriptions of threats and threat actors to detailed finished intelligence reports for clients and the general public
- Able to engage with threat actors on a long-term basis in order to obtain additional information beyond what has been posted publicly on forums and similar platforms
- Propose and oversee proactive reporting topics on cybercriminal-related TTPs and trends for internal and public consumption
- Represent Recorded Future professionally at conferences and events including, but not limited to, webinars, speaking engagements, client presentations, scoping calls, and internal and external media engagements
- Work collaboratively across internal teams to help enhance Recorded Future's collection, sourcing, research, and reporting capabilities by mentoring more junior analysts
Enterprise cybersecurity intelligence platform
Company Overview
Recorded Future’s mission is to empower customers with real-time threat intelligence, to defend their organizations against threats at the speed and scale of the internet. Recorded Future’s Intelligence Cloud provides complete coverage across adversaries, infrastructure, and targets.
Benefits
- Professional development and career advancement
- Flexible work environment, be yourself
- Generous vacation policy
- Wellness programs
- Company outings
- Competitive compensation and benefits
- Free snacks, drinks, and coffee in the office
- Parental leave program
- Environmentally conscious
Company Core Values
- We have high standards
- We practice inclusion
- We act ethically