Threat Intelligence Researcher- CTI

 Posted 7 months ago
  
 Israel
  
5-10 years experience
Apply Now

Please mention DailyRemote when applying

AI Summary

Execute the CTI research roadmap and design innovative models for attribution and infrastructure prediction. Build high-signal EASM detectors and produce actionable intelligence for stakeholders.

At Dream, we redefine cyber defense vision by combining AI and human expertise to create products that protect nations and critical infrastructure. This is more than a job; It’s a Dream job. Dream is where we tackle real-world challenges, redefine AI and security, and make the digital world safer. Let’s build something extraordinary together. 


Dream's AI cybersecurity platform applies a new, out-of-the-ordinary, multi-layered approach, covering endless and evolving security challenges across the entire infrastructure of the most critical and sensitive networks. Central to our Dream's proprietary Cyber Language Models are innovative technologies that provide contextual intelligence for the future of cybersecurity.  


At Dream, our talented team, driven by passion, expertise, and innovative minds, inspires us daily. We are not just dreamers, we are dream-makers. 


The Dream Job

We are on an expedition to find you, someone who is passionate about turning research into reliable, production-grade capabilities. You’ll play a major role in building and shaping our next-gen CTI platform across attribution, pivoting, infrastructure prediction, EASM, and the STIX/OpenCTI knowledge base.


The Dream-Maker Responsibilities

  • Execute the CTI research roadmap across attribution, infra prediction, EASM, and the STIX knowledge base. 
  • Design and implement graph-pivoting, attribution heuristics, and temporal/link models (sequence/survival/Hawkes-style). 
  • Build high-signal EASM detectors: passive discovery and safe active probing per ROE; capture reproducible evidence. 
  • Normalize, enrich, and deduplicate intel into STIX 2.1 aligned to our ontology; maintain/enhance TAXII/OpenCTI/MISP connectors. 
  • Ship detectors/models and enrichment services with AI/Platform teams; contribute tests, docs, and runbooks. 
  • Curate datasets, define ground truth, and evaluate KPIs (coverage, lead-time, precision/recall, FPR); iterate to improve signal-to-noise. 
  • Produce watchlists, concise briefs, and early-warning hypotheses for stakeholders and priority investigations. 
  • Uphold governance, ethics, provenance, and data-quality standards. 

The Dream Skill Set

  • 4-7+ years in CTI/EASM/offensive research or adversary-infra analysis. 
  • DNS, BGP/ASNs, TLS/PKI & CT logs, hosting/CDN/cloud patterns, domain lifecycle, phishing ecosystems. 
  • Communities/embeddings/clustering; temporal/link modeling and practical evaluation. 
  • Passive discovery and safe active probing; evidence discipline and noise reduction. 
  • STIX 2.1, ATT&CK, TAXII; advantage for OpenCTI/MISP; ontology alignment and validation. 
  • Python (pandas, notebooks, scikit-learn, networkx/igraph); Neo4j/Elasticsearch; Kafka/SQS/Redis; Docker/Kubernetes. 
  • Prompting/tool-use for extraction/normalization; agentic patterns with guardrails and sanity checks. 
  • Analytical writing; collaborative, version-controlled workflow (Git); documentation rigor. 

Never Stop Dreaming...

If you think this role doesn’t fully match your skills but are eager to grow and break glass ceilings, we’d love to hear from you!  



Requirements

null

Similar Jobs

See all Remote Others jobs →

Personalize your Remote Job Search in 3 Easy Steps!

Discover remote opportunities in Others

Answer easy questions

Answer easy questions

200,000+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified