STAFFY For people. For companies.
Back to jobs

New opportunity

Cybersecurity Intelligence Analyst – Threat Intelligence

About the company

We are a young and fast-growing recruiting company with five years of experience working across Latin America and the United States. We partner closely with teams and founders to help them build strong, high-impact teams through recruitment, outsourcing, and team-building services.

Our culture is built on effective communication, trust, and transparency. We believe great work happens when people feel heard, supported, and empowered to grow. Today, our team is made up of more than 80 professionals working across different projects throughout the region, collaborating remotely and learning from each other every day.

About the role

At Staffy, we’re seeking a Cybersecurity Intelligence Analyst – Threat Intelligence to build and operate a technical threat intelligence function supporting environments across cryptocurrency, critical energy infrastructure, and publicly traded financial markets.

This is not a report-summarizing or research-only position. The ideal candidate will be technically strong enough to independently collect, validate, enrich, and operationalize threat intelligence, correlate intelligence against the organization’s environment, and provide actionable insights to SOC and Incident Response teams.

You will work across threat actors, malware campaigns, ransomware, phishing, cryptocurrency-related threats, and adversary activity targeting critical infrastructure and public companies.

Responsibilities

  • Define and maintain Priority Intelligence Requirements (PIRs) in coordination with cybersecurity leadership, covering cryptocurrency threats, energy/OT-focused ransomware and nation-state activity, and financially motivated threats targeting public companies
  • Monitor and analyze threat actor activity, malware campaigns, and adversary TTPs using commercial and open-source intelligence sources such as Recorded Future, Mandiant Advantage, ThreatConnect, MISP, Bolster, or equivalent platforms
  • Track ransomware groups and threat actors targeting energy, critical infrastructure, and cryptocurrency organizations, providing early-warning advisories when relevant campaigns emerge
  • Extract, validate, enrich, and correlate Indicators of Compromise (IOCs) from multiple intelligence sources
  • Map adversary behavior and campaigns to the MITRE ATT&CK framework, including relevant IT and OT/ICS techniques
  • Perform technical analysis of malware samples, phishing campaigns, suspicious infrastructure, network data, and other raw intelligence sources to produce actionable indicators
  • Conduct dark web and closed-forum monitoring for mentions of the organization, executives, infrastructure, credentials, and other relevant exposures
  • Work directly with SOC teams to translate finished intelligence into SIEM/EDR detection rules, hunting queries, and other defensive actions
  • Support Incident Response activities by providing real-time threat context, including attribution assessment, adversary objectives, related campaigns, and known TTPs
  • Produce actionable intelligence products for both technical and executive audiences, including IOC bulletins, campaign analyses, threat assessments, and executive briefings
  • Monitor geopolitical developments and assess their potential cybersecurity impact on mining operations, energy infrastructure, and cryptocurrency exposure
  • Maintain and tune Threat Intelligence Platform (TIP) feeds, deduplication, enrichment, and scoring processes to improve signal-to-noise for security operations
  • Continuously evaluate intelligence sources and identify gaps in threat coverage relevant to the organization’s risk profile

Requirements

  • 3+ years of experience in Threat Intelligence, with demonstrated technical depth beyond research and reporting
  • Hands-on experience with at least one Threat Intelligence Platform (TIP) such as Recorded Future, Mandiant Advantage, ThreatConnect, Anomali, MISP, Bolster, or equivalent
  • Ability to independently extract, validate, and enrich IOCs from raw data including network traffic, malware samples, phishing emails, and security logs
  • Solid working knowledge of the MITRE ATT&CK framework and its application to both IT and OT/ICS environments
  • Experience developing detection logic or threat hunting queries, such as SIEM queries, YARA rules, or Sigma rules, based on intelligence
  • Strong technical writing skills, with the ability to communicate effectively with both highly technical teams and executive audiences
  • Familiarity with cryptocurrency-specific threats, including wallet compromise, exchange targeting, crypto-draining malware, or related attack techniques, or the ability to develop this expertise quickly
  • Demonstrated practical use of AI/LLM tools such as Claude, ChatGPT, GitHub Copilot, or equivalent to accelerate query and script generation, automation, technical documentation, intelligence analysis, and triage
  • Ability to critically evaluate AI-generated information and validate sources before incorporating it into intelligence products

Nice to have

  • Experience with a sector-specific ISAC/ISAO, such as E-ISAC or FS-ISAC, or previous government intelligence experience
  • Experience performing malware reverse engineering, including static or dynamic analysis
  • Experience tracking ransomware groups and Initial Access Brokers (IABs) targeting energy or critical infrastructure
  • GCTI, GREM, CTIA, or equivalent threat intelligence/cybersecurity certification
  • Familiarity with NERC CIP or energy-sector-specific threat reporting and intelligence requirements
  • Experience working with threat intelligence related to critical infrastructure, energy, financial services, or cryptocurrency

Benefits

  • People First culture
  • Referral Program
  • Free access to streaming platforms
  • Free access to Spotify Premium
  • GYM discount
  • Travel discount
  • E-Learning discount
  • Birthday-day gift
  • Points Program