職位描述
崗位職責(zé):
1. Proactively monitor and communicate cyber threat trends, vulnerabilities, indicators of compromise (IOCs), and tactics, techniques, and procedures (TTPs).
積極主動(dòng)監(jiān)控和交流網(wǎng)絡(luò)威脅趨勢(shì)、漏洞、入侵指標(biāo)(IOC)、戰(zhàn)術(shù)、技術(shù)和程序(TTP)
2. Monitor external data sources and leverage resources to gather cyber threat and setup cyber threat intelligence infrastructure and payloads associated with priority threats.
監(jiān)控外部數(shù)據(jù)源,借助資源收集網(wǎng)絡(luò)威脅,建立網(wǎng)絡(luò)威脅情報(bào)基礎(chǔ)設(shè)施和與重點(diǎn)威脅相關(guān)的Payloads。
3. Familiarity with deep and dark web, covert communication channels, social media platforms, and other OSINT sources.
熟悉深網(wǎng)與暗網(wǎng)、隱蔽通信渠道、社交媒體平臺(tái)及其他開源情報(bào)(OSINT)來源。
4. Develop and produce intelligence reports focused on cyber events and trends, industry-level analysis of developing cybersecurity threats, and geopolitical events.
編制并發(fā)布聚焦網(wǎng)絡(luò)事件與趨勢(shì)、針對(duì)演進(jìn)中網(wǎng)絡(luò)安全威脅的行業(yè)級(jí)分析以及地緣政治事件的情報(bào)報(bào)告。
5. Analyze cyber-threat actors, groups, and events to report on prioritized TTPs, behaviors, motivations, malware analysis, etc.
分析網(wǎng)絡(luò)威脅行為體、組織及事件,形成針對(duì)優(yōu)先級(jí)TTPs(戰(zhàn)術(shù)、技術(shù)及程序)、行為模式、攻擊動(dòng)機(jī)、惡意軟件分析等的專項(xiàng)報(bào)告。
6. Disseminate finished tactical, operational, and strategic threat intelligence products (reports, briefings, etc.).
分發(fā)完成的戰(zhàn)術(shù)、作戰(zhàn)和戰(zhàn)略威脅情報(bào)產(chǎn)品(報(bào)告、簡(jiǎn)報(bào)等)。
7. Provide threat intelligence support for security incidents and respond to requests for information (RFIs) and participate in the drafting and production of company threat assessments.
為安全事件提供威脅情報(bào)支持,響應(yīng)信息請(qǐng)求(RFIs),參與公司威脅評(píng)估的起草和制作。
8. Support creation of deliverables including but not limited to Security/Incident Alerts, Intelligence Reports, Trend and summary reports, Client briefings
支持撰寫各類交付成果物,包括但不限于安全事件警報(bào)、情報(bào)分析報(bào)告、趨勢(shì)研判與態(tài)勢(shì)綜述報(bào)告、客戶專項(xiàng)簡(jiǎn)報(bào)等。
任職要求:
1. University degree majoring in information security, information systems, computer science, and/or information management;
本科及以上學(xué)歷,信息安全、計(jì)算機(jī)科學(xué)或信息管理專業(yè);
2. Relevant experience in the field of threat intelligence
具備威脅情報(bào)領(lǐng)域相關(guān)經(jīng)驗(yàn)
3. Solid understanding of MITRE ATT&CK,
對(duì)MITRE ATT&CK有深刻的理解
4. Experience in programming, SIEM integration or blue team preferred
有編程、SIEM集成或藍(lán)隊(duì)經(jīng)驗(yàn)者優(yōu)先
5. Communication skills in both oral and written English and Chinese
優(yōu)秀的英文書寫、閱讀能力和良好的中文溝通能力;
6. Flexible, self-starter possessing intellectual curiosity;
工作靈活主動(dòng),具有求知欲;
查看全部