Senior Cyber Threat Intelligence, CTI Analyst

🔥 13 hours ago

🇬🇧 United Kingdom – Remote

⏰ Full Time

🟠 Senior

🧐 Analyst

👻 Ghost score 11%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Live Nation Entertainment

Live Nation Entertainment

10,000+ employees

Founded 1996

📱 Media

💰 Post-IPO Debt on 2023-01

Media • Entertainment

Live Nation Entertainment is the global leader in live entertainment, powering unforgettable experiences around the world. Artist-powered and fan-driven, Live Nation works with musicians to bring their creativity to life on stages across the globe. As the top producer of concerts, ticket seller, and brand connector to music, Live Nation's platform leads the market in these three core industries. Their mission extends beyond entertainment, aiming to uplift, inspire, and create memories through the power of live music.

📋 Description

• Conduct hands-on cyber threat intelligence analysis focused on threat actors, campaigns, tactics, techniques, procedures, infrastructure, malware, phishing activity, ransomware, and cybercrime ecosystems targeting live entertainment, ticketing, and e-commerce. • Produce tactical, operational, and strategic intelligence products, including threat assessments, intelligence reports, executive briefings, RFIs, threat actor profiles, and actionable recommendations. • Own and support the intelligence lifecycle, including requirements gathering, collection, analysis, enrichment, dissemination, and feedback. • Translate raw threat data, OSINT, vendor intelligence, dark web research, internal telemetry, and partner reporting into actionable intelligence. • Conduct technical research on malicious infrastructure, tooling, and tradecraft, including infrastructure pivoting, malware and phishing kit triage, and campaign attribution analysis. • Surface detection opportunities and partner with Detection Engineering to create YARA, Sigma, or SIEM query content. • Support threat hunting, detection engineering, incident response, vulnerability management, fraud, and broader cyber defense teams. • Develop and refine Priority Intelligence Requirements, collection priorities, analytical workflows, and reporting processes. • Analyze threat actor behavior and map activity to MITRE ATT&CK. • Brief technical, business, and senior leadership stakeholders on threats, trends, business impact, and recommended actions. • Mentor and guide other analysts through influence, tradecraft coaching, intelligence writing, and analytical review. • Help mature CTI processes, tools, reporting standards, and intelligence outputs. • Support development and automation of threat analysis workflows and tooling; operate platforms such as MISP, ThreatConnect, EclecticIQ, or Anomali. • Periodically participate in on-call rotations and support incident response efforts.

🎯 Requirements

• 5+ years of hands-on cyber threat intelligence experience in a dedicated CTI, cyber intelligence, or threat intelligence function. • Demonstrated experience conducting threat actor analysis, adversary tracking, campaign analysis, IOC/TTP analysis, and intelligence production, including use of MITRE ATT&CK or similar frameworks. • Strong understanding of the intelligence lifecycle, including requirements, collection, analysis, dissemination, and stakeholder feedback. • Proven ability to produce clear, actionable intelligence reports, assessments, briefings, and RFIs for technical and non-technical stakeholders. • Experience supporting threat hunting, incident response, detection engineering, vulnerability management, or security operations through intelligence outputs. • Experience mentoring, guiding, or influencing other analysts as a senior individual contributor or functional lead. • Strong knowledge of system, network, and application security, including Windows and Linux internals. • Experience analyzing threats using SIEM, EDR, and TIP platforms; familiarity with OSINT, dark web sources, ISACs, Recorded Future, Mandiant, Flashpoint, Anomali, ThreatConnect, and VirusTotal. • Hands-on experience investigating adversary infrastructure using passive DNS, WHOIS, TLS certificate, and internet-scan data. • Experience triaging malware, phishing kits, or attacker tooling using sandbox or detonation environments and extracting IOCs, C2 infrastructure, and behavioral indicators. • Proficiency in at least one query language (KQL, SPL, CQL, SQL), ability to read and understand code, and working scripting ability such as Python or Bash. • Strong written and verbal communication skills and ability to translate complex threat activity into business-relevant risk. • Cyber threat intelligence experience within live entertainment, ticketing, e-commerce, payments, or another high-volume consumer transaction environment. • Experience building or maturing CTI processes such as Priority Intelligence Requirements, collection plans, reporting standards, RFI workflows, or intelligence dissemination models. • Experience with ransomware, cybercrime, fraud-related threat intelligence, third-party exposure, or credential exposure analysis. • Experience conducting dark web, underground forum, or cybercrime ecosystem research, including persona management and operational security tradecraft. • Experience with static or dynamic malware analysis and reverse engineering using tools such as Ghidra, IDA, or x64dbg, or with network flow analysis and host forensics. • Experience authoring detection content such as YARA, Sigma, or Suricata rules, or SIEM correlation searches. • Experience tracking offensive tooling and C2 frameworks such as Cobalt Strike, Sliver, or Mythic. • Familiarity with STIX/TAXII, threat intelligence enrichment pipelines, or TIP administration and automation. • Familiarity with AWS, Azure, or GCP and securing cloud environments. • Exposure to AI use cases within cyber threat intelligence. • Experience collaborating with external intelligence-sharing groups such as ISACs, InfraGard, CISA, law enforcement, or intelligence community partners. • Security certifications such as GCTI, GCFA, GREM, OSCP, or CISSP. • Strong experience with question-driven analysis and structured analytic techniques. • Ability to analyze and correlate TTPs to an enterprise environment. • Ability to analyze and step through code to obtain potential IOCs or detection opportunities. • Ability to identify anomalies and trends across vast, unstructured datasets. • Ability to investigate adversary infrastructure and pivot from a single indicator to broader campaign infrastructure. • Comfortable performing initial triage of malware samples, phishing kits, and attacker tooling in sandbox or detonation environments. • Working knowledge of common C2 frameworks, commodity malware families, and phishing ecosystems. • Sound operational security practices for OSINT, dark web, and underground forum research. • Ability to script enrichment and automation against threat intelligence and security tool APIs. • Proven experience tracking advanced threat actors and financially motivated cybercrime groups. • Strong command of the intelligence lifecycle and MITRE ATT&CK framework, including MITRE Navigator. • Skilled intelligence writer able to author and peer review products for technical and executive audiences. • Experience developing Priority Intelligence Requirements and collection priorities for a large organization. • Ability to brief technical, business, and senior leadership stakeholders. • Ability to mentor and guide other analysts. • Capability to operate within high-stakes, time-sensitive investigations. • Ability to translate complex threat activity into business-relevant risk and decision support.

🏖️ Benefits

• A collaborative and inclusive environment focused on mentorship, diversity of thought, and continuous growth. • Remote-friendly and flexible work culture. • Exposure to a wide range of threat landscapes across live entertainment, e-commerce, and cloud infrastructure. • A chance to directly shape the maturity and impact of Live Nation’s global threat intelligence function. • 401(K) retirement program with employer match

Apply Now

Similar Jobs

🔥 16 hours ago

Abnormal Security

501 - 1000

🔒 Cybersecurity

Senior Customer Trust Analyst building Abnormal AI’s EMEA customer-trust program. Translating security requirements into controls and assurances while supporting revenue-critical reviews.

🔥 21 hours ago

Climate Bonds Initiative

51 - 200

💼 Consulting

🏥 Healthcare

🤝 Non-profit

Senior Policy Analyst leading climate finance policy analysis and stakeholder engagement. Supporting Climate Bonds Initiative’s global mission to mobilise capital for climate action.

🕒 5 days ago

Calero

501 - 1000

💼 Consulting

📦 Logistics

📣 Marketing

Audit Analyst analyzing customer billing, inventory, and contract data for Calero, a telecom expense management company. Identifying disputes, optimizing costs, and reporting client savings.

🕒 August 19

SOCOTEC UK & Ireland

1001 - 5000

🏗️ Construction

💼 Consulting

Asbestos Analyst conducting surveys, air monitoring, and clearance testing for SOCOTEC’s UK environmental and safety consultancy. Producing compliant reports across diverse infrastructure and commercial projects.

🕒 August 18

Wiz

201 - 500

🔒 Cybersecurity

Senior Deal Desk Analyst structuring complex Central European enterprise SaaS deals for Wiz, a cloud and AI security company. Optimizing pricing, CPQ, contracting, approvals, and sales operations across regional markets.