Cyber Threat Intelligence Analyst

Full Time
Atlanta, GA, USA
8 months ago
Strength in Trust 

OneTrust is the trust intelligence cloud platform organizations use to transform trust from an abstract concept into a measurable competitive advantage. Organizations globally use OneTrust to enable the responsible use of data while protecting the privacy rights of individuals, implement and report on their cyber security program, make their social impact goals a reality, and create a speak up culture of trust. Over 14,000 customers use OneTrust's technology, including half of the Global 2,000. OneTrust currently ranks #24 on the Forbes Cloud 100 list of top private cloud companies in the world and employs over 2,000 people in regions across North America, South America, Asia, Europe, and Australia.

The Challenge

An experienced Cyber Threat Intelligence Analyst is needed to support the mission of our Cyber Threat Intelligence team by providing innovative, high-quality cyber threat intelligence, leveraging cutting-edge technologies and analytical techniques to identify and mitigate emerging threats and support effective risk management across at OneTrust. This will be achieved by analyzing and tracking adversaries, creating and sharing intelligence both internal and external to CISO, and creating and updating cyber threat profiles for leadership.

Your Mission
  • Identify and assess the capabilities and activities of cyber criminals or foreign intelligence entities.
  • Communicate with various teams across the organization.
  • Gather and refine intelligence requirements.
  • Identify and develop threat signatures from all available sources, both internal and external.
  • Maintain and improve a Collection Management Framework for both internal and external data sources.
  • Maintain threat indicators within a threat intelligence platform.
  • Implement and support standard procedures for incident response.
  • Interface with Information Security and Incident Response Teams.
  • Provide insights to other team members on nuances of cloud computing services, such as storage, databases, analytics, and IAM, as well as networking technologies, architectures, and network traffic analysis to support other analysts who do not have cloud or networking experience.
  • Develop models for identifying incident-type activity, of malware or bad actors, using statistical analysis and industry recognized constructs such as the Diamond Model, the MITRE ATT&CK framework, and the Cyber Kill Chain.
  • Develop dashboards to assist in automation and awareness for incident response using a threat intelligence platform and Splunk.
  • Review incident logs or artifacts and search for patterns.
  • Build and refine a threat hunting program.
  • Explore patterns in network and system activity through log correlation using Splunk and other tools.
  • Investigate evidence of threats against Windows, Linux, MacOS, Database, Applications, web servers, firewalls or other relevant technologies.
  • Review IOC’s to assess impact to organization.
  • Share IOC’s with internal and external teams for validation and collaboration.
You Are
  • Must have strong working knowledge of:
    • Cyber Threat Intelligence Analysis and Reporting.
    • Cyber Defense Techniques.
    • Adversary Tactics, Techniques, and Procedures (TTPs).
    • Boolean Logic.
    • TCP/IP Fundamentals.
    • Network Level Exploits.
    • Cloud Computing Concepts (AWS, Azure, GCP).
    • Threat Management.
  • Must have excellent oral and written communication skills and interpersonal and organizational skills.
  • Networking experience.
  • Statistical modeling and analysis experience to infer possible cybersecurity threats.
  • Experience in analysis in investigations, such as in IT, law enforcement, military intelligence, or business analytics.
  • Interest in learning about Windows, Linux, MacOS, Database, Application, Web server, firewall, SIEM and log analysis
  • Strong communication and interpersonal skills to effectively communicate with team-members from both technical and non-technical backgrounds.
  • Must be highly motivated with the ability to self-start, prioritize, multi-task and work in a team setting.
  • Understanding of intelligence cycle, MITRE ATT&CK Framework, Cyber Kill Chain, and Diamond Model
  • 5+ years of experience working as a Cyber Threat Intelligence Analyst
  • Familiarity with common network vulnerability/penetration testing
  • Experience with: ThreatConnect, Splunk, Azure, Recorded Future, CrowdStrike, Wiz, Proofpoint
  • An understanding of log data from cloud providers such as Azure, AWS, and GCP.
  • Experience evaluating systems, networks, and devices for vulnerabilities.
  • Splunk query-development expertise.
  • Experience on an Incident Response team performing Tier I/II initial incident triage.
  • Excellent writing skills.

For California, Colorado, Connecticut, Nevada, New York, Rhode Island, and Washington-based candidates: the annual base pay range for this role is listed below. Within this range, individual pay is determined by several factors, including location, job-related skills, work experience, and relevant education and/or training. This role may also be eligible for discretionary bonuses, equity, and/or commissions, as well as benefits.

Salary Range$101,250—$151,875 USDWhere we Work

OneTrust embraces a hybrid working model. Our Working@ OneTrust initiative is our way of clarifying where we hire, how we work together, and where we’re located in that hybrid model.  

The underlying “why” for Working@ is that we are intentional about the culture that we want to create together. That includes bringing teams together, in-person, throughout the year to collaborate, build connections, learn from each other, and celebrate our wins toFinish Stronger.  

We are committed to a flexible approach informed by a set of guiding principles. You’ll see that reflected in our worker designations: “Office-flex” and “Location-flex”.

  • Office-flex: Like a traditional hybrid model, OneTrust “Office-flex” employees may be asked to work in an office periodically if they are within a commutable distance to a OneTrust office. This includes coming into the office for our Company Kickoff, Company All Hands, and other larger company events. Beyond that, we give our leaders and teams the flexibility to set additional guidelines based on the nature of your role.  
  • Location-flex: Similar to other companies’ remote policies, for OneTrust “Location-flex" roles, you will primarily work from your home office location. However, you may be required to travel to our OneTrust offices or customer sites periodically based on the nature of your role.

Each role may have specific requirements, so we encourage you to verify the location of the role with your recruiter during your first interview.

Benefits

As an employee at OneTrust, you will be part of the OneTeam. That means you’ll receive support physically, mentally, and emotionally so that you can do your best work both in and out of the office. This includes comprehensive healthcare coverage, flexible PTO, equity stock options, annual performance bonus opportunities, retirement account support, 14+ weeks of paid parental leave, career development opportunities, company-paid privacy certification exam fees, and much more. Specific benefits differ by country. For more information, talk to your recruiter or visit onetrust.com/careers.

Resources  

Check out the following to learn more about OneTrust and its people: 

  • OneTrust Careers on YouTube
  • @LifeatOneTrust on Instagram
Your Data

You have the right to have your personal data updated or removed. You also have the right to have a copy of the information OneTrust holds about you. Further details about these rights are available on the website in our Privacy Overview. You can change your mind at any time and have your personal data removed from our database. In order to do this you must contact us and let us know you wish to be removed. The request should be made on the Data Subject Request Form.

Our Commitment to You 

When you join OneTrust you are stepping onto a launching pad — the countdown has begun. The destination? A career without boundaries working alongside a diverse and inclusive crew who is passionate about doing meaningful work. As a pioneer, your voice and expertise will help chart the direction of an entirely new industry — Trust. Our commitment to putting people first starts with you. Your growth is part of the mission. Our goal is to give you the power to embark on the next phase of your uniquely, unique career 

OneTrust provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by local laws.