職位描述
崗位職責(zé):
1. Proactively monitor and communicate cyber threat trends, vulnerabilities, indicators of compromise (IOCs), and tactics, techniques, and procedures (TTPs).
積極主動監(jiān)控和交流網(wǎng)絡(luò)威脅趨勢、漏洞、入侵指標(biāo)(IOC)、戰(zhàn)術(shù)、技術(shù)和程序(TTP)
2. Monitor external data sources and leverage resources to gather cyber threat and setup cyber threat intelligence infrastructure and payloads associated with priority threats.
監(jiān)控外部數(shù)據(jù)源,借助資源收集網(wǎng)絡(luò)威脅,建立網(wǎng)絡(luò)威脅情報基礎(chǔ)設(shè)施和與重點威脅相關(guān)的Payloads。
3. Familiarity with deep and dark web, covert communication channels, social media platforms, and other OSINT sources.
熟悉深網(wǎng)與暗網(wǎng)、隱蔽通信渠道、社交媒體平臺及其他開源情報(OSINT)來源。
4. Develop and produce intelligence reports focused on cyber events and trends, industry-level analysis of developing cybersecurity threats, and geopolitical events.
編制并發(fā)布聚焦網(wǎng)絡(luò)事件與趨勢、針對演進(jìn)中網(wǎng)絡(luò)安全威脅的行業(yè)級分析以及地緣政治事件的情報報告。
5. Analyze cyber-threat actors, groups, and events to report on prioritized TTPs, behaviors, motivations, malware analysis, etc.
分析網(wǎng)絡(luò)威脅行為體、組織及事件,形成針對優(yōu)先級TTPs(戰(zhàn)術(shù)、技術(shù)及程序)、行為模式、攻擊動機(jī)、惡意軟件分析等的專項報告。
6. Disseminate finished tactical, operational, and strategic threat intelligence products (reports, briefings, etc.).
分發(fā)完成的戰(zhàn)術(shù)、作戰(zhàn)和戰(zhàn)略威脅情報產(chǎn)品(報告、簡報等)。
7. Provide threat intelligence support for security incidents and respond to requests for information (RFIs) and participate in the drafting and production of company threat assessments.
為安全事件提供威脅情報支持,響應(yīng)信息請求(RFIs),參與公司威脅評估的起草和制作。
8. Support creation of deliverables including but not limited to Security/Incident Alerts, Intelligence Reports, Trend and summary reports, Client briefings
支持撰寫各類交付成果物,包括但不限于安全事件警報、情報分析報告、趨勢研判與態(tài)勢綜述報告、客戶專項簡報等。
任職要求:
1. University degree majoring in information security, information systems, computer science, and/or information management;
本科及以上學(xué)歷,信息安全、計算機(jī)科學(xué)或信息管理專業(yè);
2. Relevant experience in the field of threat intelligence
具備威脅情報領(lǐng)域相關(guān)經(jīng)驗
3. Solid understanding of MITRE ATT&CK,
對MITRE ATT&CK有深刻的理解
4. Experience in programming, SIEM integration or blue team preferred
有編程、SIEM集成或藍(lán)隊經(jīng)驗者優(yōu)先
5. Communication skills in both oral and written English and Chinese
優(yōu)秀的英文書寫、閱讀能力和良好的中文溝通能力;
6. Flexible, self-starter possessing intellectual curiosity;
工作靈活主動,具有求知欲;
查看全部