
Posted a day ago
Senior CIRT/Threat Intel Analyst
S&P GlobalSenior CIRT/Threat Intel Analyst
Perks & benefits
Education AllowanceHealth InsurancePaid Leave
Requirements
3+ years information security experience, Knowledge of MITRE ATT&CK, Hands-on experience with SIEM (Splunk preferred), Experience with TIPs (MISP, OpenCTI, or Recorded Future), Advanced knowledge of network protocols, Experience analyzing cloud/SaaS logs
Skills
incident responseThreat IntelligenceSplunk
About the role
Responsibilities
- Coordinate and triage response to cybersecurity events and conduct forensic analysis across endpoints, networks, cloud, and SaaS.
- Integrate threat intelligence into investigations by enriching IOCs, mapping activity to MITRE ATT&CK, and identifying threat actor TTPs.
- Develop, maintain, and operationalize Incident Response playbooks, SOPs, and collection plans.
- Work closely with the SOC to deliver containment, remediation, and root cause analysis.
- Create and tune detections in SIEM/SOAR and EDR using intelligence signals such as YARA or Sigma.
- Produce consumable intelligence outputs, including flash alerts, threat overviews, and executive briefs.
- Contribute to vulnerability surfacing and advise on risk-based prioritization of emerging threats.
Requirements
- 3+ years of information security experience with a focus on incident response, threat hunting, or threat intelligence.
- Hands-on experience with a SIEM, with a preference for Splunk.
- Experience with Threat Intelligence Platforms (TIPs) such as MISP, OpenCTI, or Recorded Future.
- Strong knowledge of the MITRE ATT&CK framework and attacker tradecraft.
- Advanced knowledge of network protocols (TCP/IP, HTTP) and operating systems.
- Experience analyzing system, application, and cloud/SaaS logs.
- Excellent communication skills for producing clear, actionable technical and executive-level reports.
Preferred Qualifications
- Experience in the financial services industry.
- Familiarity with hypothesis-driven or behavior-based threat hunting techniques.
- Knowledge of cloud provider threat models and telemetry (AWS, Azure, GCP, M365).
- Relevant industry certifications such as GCTI, GCFA, GCIH, or FOR578.
- Exposure to malware analysis and the creation of Sigma or YARA rules.
Benefits
- Health & Wellness coverage designed for mind and body.
- Generous flexible downtime and time off.
- Continuous learning opportunities and career growth resources.
- Financial security through competitive pay, retirement planning, and student loan contribution programs.
- Family-friendly perks and various retail discounts.
About the Company
S&P Global delivers Essential Intelligence® that shapes decision making. We provide the world’s leading organizations with the right data, connected technologies, and expertise they need to move ahead and solve complex challenges in a changing economic landscape.
ScoutJobs Agent
Get matches like this delivered daily
Sign up free — we'll pull jobs that fit your CV from across the web and rank them for you.
Get started — it's freeSenior CIRT/Threat Intel Analyst
S&P Global · London
