





Niche security skillset but metro location and mid-level experience increase applicant density.
Threat intelligence requires specialized cyber HUMINT, tooling, and ransomware expertise, limiting cross-industry transferability.
Explicit 3+ years, specific ransomware/APT experience, MITRE and tooling requirements make filters strict.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Lead tracking and mapping of global threat activities including ransomware, cybercrime ecosystems, and APT campaigns through infrastructure analysis and HUMINT source development.
Conduct Initial Access Vector (IAV) mapping to analyze infiltration techniques and affiliate ecosystems specifically in ransomware operations.
Produce actionable tactical to strategic intelligence reports leveraging frameworks like MITRE ATT&CK, Diamond Model, and Cyber Kill Chain for global stakeholders.
Minimum 3 years experience in threat intelligence, malware analysis, threat hunting, or digital investigations.
Proven experience tracking ransomware groups, access brokers, or APT campaigns using OSINT, dark web, and technical telemetry.
Strong knowledge of MITRE ATT&CK, MITRE Engage, Diamond Model, and Cyber Kill Chain frameworks.
Required skills with C2 frameworks, IAV analysis, and OSINT tools like Shodan, VirusTotal; strong communication skills for technical and executive audiences.
Experienced in detailed infrastructure hunting campaigns and complex threat actor profiling across multiple cybercrime ecosystems.
Practically skilled in synthesizing multi-source threat data into structured research outputs and intelligence reports.
Actively contributes to the cybersecurity community through research publications, blogs, presentations, or open-source tooling.