Listing Description
Job Description
Mandiant is seeking a Threat Intelligence Analyst to join our Threat Pursuit team as part of our Adversary Operations division. You will be focused on collection and research efforts as a means to provide Mandiant customers with analytical insights into malware distribution operations. You will play an important role within Mandiant's intel organization, as your analysis will directly support front line incident responders to prevent and detect highly impactful threats.
Your time will be split between tracking changes in known distribution operations, conducting discovery operations to identify new and emerging threats, and conducting research into attacker TTPs.
Responsibilities:
- Conduct extensive research on malware distribution operations
- Conduct long term research projects focused on actor TTPs
- Conduct research into new and emerging malware families
- Bypass threat actor guardrails to conduct malware collection operations
- Conduct threat actor and malware clustering
- Maintain current knowledge of tools and best-practices in advanced persistent threats; tools, techniques, and procedures (TTPs) of attackers; and forensics and incident response
- Perform strategic, tactical, and operational research and analysis of adversarial cyber threats, and the geopolitical context they operate in
- Identify and hunt for related TTPs across all internal/external repositories
- Correlate collected intelligence, to build upon a larger knowledge base of tracked threat activity
- Ability to work with little direct oversight
Qualifications
Required Skills:
- 5 + years of experience in an analytical role of either a Threat Analyst, network forensics analyst, or security engineer/ consultant Ability to quickly triage & classify malware families by using sandboxes and manual analysis
- 5 + years of experience in Investigative or Incident Response environments
- 2+ years of experience conducting basic static and dynamic analysis
- Ability to manually unpack malware
- Basic understanding of graph databases
- Ability to write small scripts/programs in Python, Go, Perl, Ruby or similar
- Proven track record of successfully managing and executing on short term and long-term projects
Desired Skills:
- Proven analytical leadership skills with the ability to prioritize and execute
- Excellent communication and presentation skills with the ability to address both technical and non-technical audiences
- Capable of documenting and explaining technical details/efforts in a concise, actionable manner
- Strong problem solving, troubleshooting, and analysis skills
- Experience working in fast-paced environments
- Self-driven, proactive, hardworking, creative, team-player
Listing Details
- Citizenship: Not Provided
- Incentives: Not Provided
- Education: Not Provided
- Travel: Not Provided
- Telework: Full Telecommute