CTI - Senior
EY
EY
Join EY as a Senior Cyber Threat Intelligence Analyst and play a crucial role in safeguarding our clients. This position involves advanced threat intelligence monitoring, comprehensive report writing, and utilizing diverse intelligence platforms. You will be instrumental in developing and maintaining custom threat intelligence feeds, integrating them into SIEM solutions, and delivering detailed reports aligned with client needs. The role requires flexibility to work within the EST timezone for optimal team overlap and on-call availability for critical tasks.
This is an opportunity to leverage your expertise within a globally recognized firm committed to building a better working world through data, AI, and advanced technology. You will contribute to shaping the future with confidence by addressing pressing cybersecurity challenges.
As a Senior Cyber Threat Intelligence Analyst, you will monitor and analyze threats using leading platforms such as ZeroFox or Digital Shadows. You will craft detailed technical cybersecurity reports and gather intelligence through OSINT, IOC validation, domain registrar lookups, VirusTotal, and dark web searches. Developing and sustaining custom intelligence feeds with platforms like MISP, leveraging Python, Azure, and Linux scripting, will be a key function.
Responsibilities also include managing feeds through platforms like Anomali or ThreatQ, and integrating them into SIEMs, especially Microsoft Sentinel. You will execute domain and social media takedowns, and create tailored client reports. Applying knowledge of MITRE ATT&CK, D3FEND, and the Cyber Kill Chain is essential. Data visualization using Excel or Power BI, along with preparing and delivering PowerPoint presentations, are also core duties. You will collaborate with MSSPs and be prepared for on-call responsibilities.
We seek a candidate with a minimum of 3 years in threat intelligence monitoring and at least 1 year in report writing. Proficiency in OSINT, IOC validation, domain lookups, VirusTotal, and dark web searching is required. Experience with Python, Azure, and Linux scripting, alongside familiarity with threat intelligence platforms for feed management, is necessary. You should have experience integrating feeds into SIEMs, particularly Microsoft Sentinel, and proven success with domain/social media takedowns.
A strong grasp of MITRE ATT&CK, D3FEND frameworks, and the Cyber Kill Chain is vital. Excellent English writing and verbal communication skills are essential, along with proficiency in Excel/Power BI for data visualization and PowerPoint for reporting. The ability to work effectively under pressure, prioritize tasks, and collaborate with MSSPs is important. Cybersecurity certifications are a plus. Availability to work evening shifts within the EST timezone for onshore/client team overlap is also required.
EY Global Delivery Services ( EY GDS)
Cybersecurity