The analyst will monitor and evaluate cyber threats using internal and external intelligence feeds to prioritize customer vulnerability scans. They are also responsible for producing detailed intelligence reports and collaborating with internal teams to enhance the cybersecurity posture of customers.
Your job is to empower both our SOC analysts and customers by turning threat intelligence into prioritized actionable information. Your main responsibility will be to evaluate threats we observe in our SOC in conjunction with external threat intelligence feeds in order to properly analyze and prioritize customer vulnerability scans. You will be responsible for proactively monitoring and assessing threats, producing timely intelligence reports, and collaborating with internal teams to enable our customers to enhance their cybersecurity posture.
Primary Responsibilities
- Monitor various sources of threat intelligence, including open source intelligence (OSINT), dark web forums, proprietary feeds, and internal sources, to identify and evaluate potential cyber threats.
- Review security incidents detected by our MDR service to identify root cause and/or vulnerabilities being actively utilized in real world attacks.
- Participate in threat intelligence sharing communities and forums to contribute to and stay informed about the broader threat landscape.
- Analyze and interpret threat data, including vulnerability scans, to assess the potential impact and likelihood of different cyber threats to computer systems, networks, and data, and make the determination of critical vulnerabilities that need to be addressed right away for our customers.
- Produce detailed threat intelligence reports, including indicators of compromise (IOCs), tactics, techniques, and procedures (TTPs), and recommended mitigation strategies.
- Leverage external threat feeds in combination with knowledge gained from root cause analysis in order to provide unique insight into vulnerabilities being actively targeted by threat actors.
- Contribute to the continuous improvement of threat intelligence processes, tools, and methodologies.
- Empower our analysts in both our Phishing and MDR service by acting as an SME for current and emerging threats in the cyber threat landscape.
- Support client inquiries and understanding of cyber threats.
Non-Technical Skills Required
- Proven conflict management & verbal and written communication skills.
- Effective project and time management skills.
- Excellent analytical and multitasking skills.
Technical Skills Required
- Solid knowledge of common cyber threat vectors, tools, techniques, and procedures employed by threat actors.
- The ability to conduct detailed incident reviews aimed at identifying the underlying root causes and vulnerabilities exploited in real-world cyber attacks.
- Understanding of malware analysis reports produced by an automated malware analysis sandbox
- Experience in technical writing and able to write for both broad and different audiences.
Education and Experience
- At least 2-4 years of professional experience in security operations, incident response, or an area related to vulnerability management.
- Bachelor’s degree strongly preferred
Work Location
We are accepting candidates outside of the DC-Metro area for this position at this time. Applicants in the DC-Metro area may work remotely until the company has established an in-region office.
Work Authorization
Applicants must be authorized to work in the United States.
Expel does not sponsor immigration visas.
EEO Statement
Expel is an Equal Opportunity Employer: All qualified applicants will receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.
Salary Range
$126,500—$175,500 USD