Emerging Threats Analyst - Threat Intelligence

Trinity Cyber is a leading developer and provider of advanced cybersecurity technologies and services.  Our breakthrough core technology can deeply, quickly, and precisely interrogate and transform Internet sessions, creating a family of products and services.  As a secure edge, our system automatically identifies, neutralizes and transforms malicious Internet traffic in line and at line speed with granularity and precision beyond other cybersecurity technologies.  As an API-driven file inspection platform, it delivers sub-second conviction results and metadata to third-party providers like email security and packet capture vendors.  It can also deliver rapid file context and content to cybersecurity analysts.  Our customers and go-to-market partners are growing and span multiple industries.

An Emerging Threats Analyst at Trinity Cyber is responsible for digging deep into the world of open source and proprietary threat intelligence. You will work alongside a team of motivated developers, threat analysts, and operators to translate some of the newest and most complex vulnerabilities, exploits, and threats in cyber space into actionable outcomes. You will be responsible for collecting intelligence that fuels the development of signatures, heuristics, and mitigations within Trinity Cyber’s exclusive technology, as well as communicating and documenting such findings within a team environment.

  1. Utilizing open source and paid intelligence to understand new and existing vulnerabilities, exploits, techniques, malware families, and malicious infrastructure.
  2. Synthesizing and reporting this information to internal teams to protect customers in a quick manner.
  3. Working with external vendors to understand the intelligence they provide and use it in new and exciting ways that benefit Trinity Cyber.
  4. Working collaboratively with threat analysts, engineers, and customer success teams to deliver intelligence in a timely manner.
  5. Documenting your work, process, and outcomes to several audiences – from internal to external.
  6. Developing automation (with Python) to enhance the following:
    •    Collection of Open Source Intelligence (OSINT)
    •    Dissemination of intelligence to partners
    •    Enrichment of threat intelligence data within repositories, portals, and databases.
  7. Constantly improving your knowledge of the Cybersecurity community as a whole.
  1. Curiosity, tenacity, and out of the box thinking.
  2. Strong logical/critical thinking abilities, especially analyzing potentially malicious artifacts and infected hosts.
  3. Experience with open source research and the ability to do it both securely and anonymously.
  4. Experience tracking one or more of the following (over multiple months/years)
    o    Actors
    o    TTPs
    o    Malware Families
    o    Malicious Infrastructure
  5. Functional experience with scripting languages (python, javascript, etc.) to work with data coming from APIs, databases, and to automate daily tasks.
  6. Experience working with free or paid Threat Intelligence Platforms (TIPs) to track techniques, IOCs, and other relevant information.
  7. Working knowledge of network protocols (TCP, UDP, HTTP(S), DNS) and common file types (Binaries, Documents, Scripts) to understand where threats may live within them.
  8. The ability to write and understand signatures (Yara, Snort, Suricata, Bro) at a TTP level rather than indicator level.
  9. Functional understanding of decoding and deobfuscating malware communications.
  10. The ability to categorize, triage, and analyze passive network traffic.
  11. The ability to translate technical vocabulary into meaningful, higher level situational awareness and finished reports.
  12. An ideal candidate would possess a Bachelors degree in the area of Science, Technology, Engineer, Math or a related field and have 2 – 4 years of cyber security experience.  A Masters degree would be plus.
  13. Must possess the highlest level of personal integrity, value team success over individual achievement, have the ability to contribute significantly to extending a culture of collaboration, both internally and externally, in order to maintain the superior reputation of Trinity Cyber, and enjoy having fun.