Remote job
Senior Threat Intelligence Researcher
Job details
About this role
Role overview
A senior research role dedicated to proactive threat intelligence and advanced threat hunting within an AI-driven cybersecurity environment. The position leads deep investigations of malware trends and adversary tradecraft, translating complex telemetry and external intelligence into clear briefings that help security leadership anticipate and counter emerging risks.
Responsibilities
- Lead hypothesis-driven threat hunts across endpoints, on-premises networks, and cloud environments to surface intrusions that evade conventional controls. - Combine internal hunt findings with intelligence from dark-web forums, leak sites, and research repositories to produce actionable threat briefings and risk assessments for senior stakeholders. - Pivot through EDR telemetry to map adversary footprints, analyzing execution, persistence, and lateral movement patterns across the estate. - Track shifts in adversary infrastructure externally by pivoting through domain registrations, SSL certificates, and passive DNS. - Develop and refine hunting strategies that anticipate changes in attacker tactics, techniques, and procedures. - Apply YARA-based content and validation practices to track emerging malware families and exploitation of newly disclosed vulnerabilities.
Requirements
- Demonstrated background in threat research, threat intelligence, or threat hunting. - Strong grasp of the cyber threat landscape, including prominent actors and their tactics, techniques, and procedures. - Analytical ability to surface patterns and trends within large, complex datasets. - Working knowledge of YARA, including rule authoring and detection validation. - Familiarity with frameworks such as MITRE ATT&CK, CISA KEV, EPSS, AMITT, and MISP Galaxy. - Experience with malware analysis tools and techniques, covering static, dynamic, sandbox-based, and debugging approaches. - Technical writing and content development capability.
Nice to have
- Solid understanding of how EDR platforms operate internally and how to maximize their telemetry. - Relevant certifications such as Certified Malware Analyst (CMA), Certified Reverse Engineering Analyst (CREA), or GIAC GREM. - Experience tracking vulnerability exploitation across a broad estate.
Benefits and work setup
- Base salary starting around 3,000 EUR per month, with an annual performance-based bonus paid in two installments; final offer reflects skills and experience. - Restricted Stock Units, an Employee Stock Purchase Plan, and a performance-linked bonus. - Flexible time off layered on five weeks of standard PTO, paid wellness days, gender-neutral parental leave, and fully paid short-term sick or nursing leave. - Life and disability insurance, a pension contribution, global business travel medical insurance, and an Employee Assistance Program. - Home office, meal, and wellbeing allowances, plus a multi-sport benefit program and a wellness coaching app. - Hybrid arrangement based in Prague (Karlin) or Brno (Clubco), or fully remote within the Czech Republic or Slovakia; Prague-based staff are expected on-site at least two days per week.