SOC Cyber Threat Intelligence (CTI) Analyst
# SOC Cyber Threat Intelligence (CTI) Analyst **Lintas Media Danawa** · Jakarta · `On-site` 🕒 **Статус:** *Опубликовано: 8 дней назад* · *Источник: Indeed* --- ### About the Role Qualifications : - Minimum of 4–6+ years of technical experience in cybersecurity, with at least 2–3 years focused strictly on cyber threat intelligence or cybercrime investigation. - Demonstrated history of authoring comprehensive threat intelligence reports, whitepapers, or tactical advisories. - Preferred Professional Certifications - Candidates holding one or more of the following credentials will be highly prioritized: ● Dedicated Threat Intelligence : ○ GIAC Cyber Threat Intelligence ( GCTI ) ○ Certified Threat Intelligence Analyst ( CTIA ) ● Advanced Architecture & Response : ○ Certified Information Systems Security Professional ( CISSP ) ○ GIAC Certified Incident Handler ( GCIH ) Responsibilities : Intelligence Collection & Analysis - Monitor open-source intelligence (OSINT), closed hacker forums, commercial threat feeds, and dark web marketplaces to identify emerging exploits, malware variants, and active campaigns. - Track and profile Advanced Persistent Threats (APTs) and cybercriminal syndicates, documenting their specific Tactics, Techniques, and Procedures (TTPs). - Analyze global geopolitical events and industry-specific trends to predict upcoming shifts in the threat landscape targeting the organization's regional footprint. Operationalization & Detection Support - Translate raw threat data into highly actionable Indicators of Compromise (IoCs) and Indicators of Behavior (IoBs). - Partner with Threat Hunters and Detection Engineers to inject intelligence directly into SIEM watchlists, firewall blocks, and automated SOAR playbooks. - Author and issue timely tactical alerts, weekly threat briefings, and executive-level threat intelligence reports detailing the organization's immediate digital risk. Vulnerability & Brand Protection - Evaluate newly disclosed vulnerabilities (CVEs) against the organization's actual technology stack, guiding patching priorities based on active, real-world exploitation. - Track credential leaks, data dumps, and lookalike domain registrations to mitigate typosquatting, phishing infrastructure, and brand impersonation. Work Location: In person
Наблюдалась 2026-10-07, впервые 2026-09-28, источник — Indeed.