Senior Threat Intelligence Analyst -UK

Remote
Full Time
Experienced

Join the mission to make the digital world safer.

About Team Cymru

Team Cymru is the leader in Internet Threat Intelligence. Our unique and global insight empowers an amazing team of analysts to develop industry leading intelligence that is critical to the success of our customer's cyber security efforts.

Team Cymru is an ardent supporter of the Threat Intelligence community. We enable industry collaboration by hosting exclusive conferences each year. Our team members actively participate in working groups, attend industry events, and work directly with fellow community peers.

Job Description

Team Cymru analysts make a difference every day, leading in the battle against those intent on harming others. We are passionate about our mission, and we are looking for an additional teammate who shares in that passion. Do you have a strong background in analytic tradecraft, deductive reasoning, and critical thinking? Would you like to have access to our industry leading threat intelligence data? Are you a proven teammate, mentor, and technical leader? Would you like to join the battle and make a difference in the world? If so, opportunity knocks.

Team Cymru analysts work on research and reporting pertaining to our customers' security and intelligence requirements, empowering them to complete their mission effectively and efficiently. Additionally, our analysts undertake research into other threats and work closely with our engineering teams in the development of our world class analytical tools, data analytics systems, and analysis automation, as well as adding to the body of knowledge of those threats.

As a Senior Threat Intelligence Analyst, you will provide that vital bridge between technical and strategic intelligence research, writing for both practitioner and senior leadership audiences to understand the impact of the threat, while explaining the technical details and rationale behind those assessments, the best of both worlds!

Responsibilities:

Threat Research

● Conduct extensive, proactive research into threat actors, malware families, campaigns, and evolving TTPs to maintain relevance and deepen Team Cymru's body of knowledge

● Investigate and present operational and strategic intelligence on threat actors, including attribution, motivation, capability assessment, and geopolitical context

● Lead short- and long-term threat tracking projects, identifying intelligence gaps and proposing targeted research to address collection shortfalls

● Evaluate tools, methodologies, and best practices for understanding adversary TTPs, and proactively share knowledge and techniques with peers

Network and Infrastructure Analysis

● Perform deep network traffic and infrastructure analysis to support both customer requests and independent research, using Team Cymru's unique global dataset

● Analyze PCAP, NetFlow, passive DNS (PDNS), open ports, certificates, and other datasets to map malicious infrastructure and identify related threat actor assets

● Identify and refine indicators of compromise (IOCs) and threat actor TTPs, translating these into automated tracking mechanisms where possible to enable ongoing monitoring of threats and adversary groups

Reporting

● Receive, triage, and respond to customer requests with timely, written technical threat intelligence reports tailored to the customer's specific threat landscape and intelligence requirements

● Ensure all finished intelligence products meet Team Cymru's analytic standards: clear structure, appropriate use of estimative language and confidence levels, and actionable conclusions

● Conduct peer review of colleagues' reporting to maintain consistency, accuracy, objectivity, and analytic rigor across all published products

Collaboration

● Work closely with colleagues in the development of analytical tools, data analytics systems, research methodologies, and analysis automation capabilities

● Support our threat detection and data acquisition teams to align signature development and telemetry collection with overarching threat intelligence priorities

● Participate in working groups, industry events, and community collaboration as a representative of Team Cymru's intelligence capability

Qualifications & Experience

● 5+ years of experience as a threat intelligence analyst, network forensics analyst, or IT security analyst

● Preferably, a Bachelor's degree in Computer Science, Computer Engineering, Cybersecurity, or equivalent

● Exceptional oral and written communication skills, with the ability to produce customer-facing intelligence reports under time pressure. Experience using structured analysis techniques, estimative language, and confidence levels is preferred

● Proven track record of leading complex analytical projects or investigations, including the ability to manage multiple concurrent work streams

Additional Skills

● Well-developed analytical, deductive reasoning, and critical thinking skills; comfortable forming assessments from incomplete or ambiguous data

● Proven ability to work effectively within a distributed, remote team environment, including willingness to conduct peer review and share tradecraft knowledge

● Experience tracking APT, nation-state, or cybercriminal actors, with the ability to contextualize their activity within the broader geopolitical or strategic landscape

● Outstanding network infrastructure and traffic analysis skills: PCAP, NetFlow, PDNS, open ports, certificates

● Deep working knowledge of IP networking and internet services: DNS, HTTP/HTTPS, TLS, VPNs, and routing protocols (BGP)

● Demonstrated knowledge of operating system concepts, including experience developing and contextualizing indicators of compromise and understanding their deployment in host and network-level detection architectures

● Working proficiency in SQL and querying and analyzing large disparate datasets

● Strong familiarity with common OSINT platforms and research techniques

Highly Desirable Skills

● Subject Matter Expert (SME) for a specific regional or threat actor group, with demonstrable depth in their TTPs, infrastructure patterns, and campaign history

● Programming or scripting proficiency, preferably Python, for data processing, automation, or tool development

● Confident and skilled public speaker with experience presenting technical research to large audiences at industry conferences or similar forums

● Familiarity with using AI systems to rapidly prototype analytical tools and develop proof-of-concept projects

● Hands-on experience managing remote Linux servers and engineering custom Proof-of-Concept tools to extract, simulate, or generate unique threat data

● Working understanding of malware analysis and network analysis: YARA, Zeek, Suricata, Sandbox reporting

● Exposure to malware reverse engineering, including static and dynamic analysis techniques and common tooling (e.g. Ghidra, IDA Pro, x64dbg)

● Familiarity with the operational structures of hosting providers, ISPs, and internet exchanges, including how infrastructure is provisioned, attributed, and abused by threat actors

Travel

Occasional travel within the UK and internationally for customer workshops, industry events, and team meetings is required

Why Join Team Cymru? 

At Team Cymru, we provide unmatched global threat intelligence that empowers organizations to proactively disrupt adversaries. You'll be at the forefront of cybersecurity innovation, helping customers harness the full power of our threat intelligence to achieve critical business and security outcomes. 

We offer a collaborative, mission-driven culture where your expertise and impact will directly contribute to improving global security. 

Ready to make an impact?

Apply now and help shape the financial future of a company protecting millions worldwide.

This job description is not exhaustive. Responsibilities may evolve as needed. Team Cymru is an equal opportunity employer and welcomes applicants from all backgrounds. This is a remote position. 

Share

Apply for this position

Required*
We've received your resume. Click here to update it.
Attach resume as .pdf, .doc, .docx, .odt, .txt, or .rtf (limit 5MB) or Paste resume

Paste your resume here or Attach resume file

To comply with government Equal Employment Opportunity and/or Affirmative Action reporting regulations, we are requesting (but NOT requiring) that you enter this personal data. This information will not be used in connection with any employment decisions, and will be used solely as permitted by state and federal law. Your voluntary cooperation would be appreciated. Learn more.

Invitation for Job Applicants to Self-Identify as a U.S. Veteran
  • A “disabled veteran” is one of the following:
    • a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or
    • a person who was discharged or released from active duty because of a service-connected disability.
  • A “recently separated veteran” means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.
  • An “active duty wartime or campaign badge veteran” means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.
  • An “Armed forces service medal veteran” means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.
Veteran status



Voluntary Self-Identification of Disability
Voluntary Self-Identification of Disability Form CC-305
OMB Control Number 1250-0005
Expires 05/31/2026
Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Please check one of the boxes below:

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.

You must enter your name and date
Human Check*