Sobre el puesto
As a Threat Intelligence Analyst at Vorpcel, you will investigate the actors, infrastructure, campaigns and vulnerabilities that matter to our customers and products. You will work with open sources, internal telemetry, threat feeds and vulnerability intelligence to separate useful signal from noise.
You will produce tactical, operational and strategic intelligence that supports detection engineering, incident response, product decisions and customer guidance. Your analysis will explain what is happening, why it matters, how confident we are and what action should follow.
This role suits a curious and methodical analyst who can move from raw technical evidence to a concise assessment for both technical and business audiences.
Lo que harás
- Monitor threat actors, campaigns, malware, botnets and criminal infrastructure relevant to Vorpcel and its customers.
- Collect, validate and enrich intelligence from OSINT, internal telemetry, feeds and trusted communities.
- Investigate new CVEs, proof-of-concept releases and exploitation activity to assess urgency and exposure.
- Analyze indicators, infrastructure relationships and attacker behavior to identify patterns and attribution hypotheses.
- Map observed behaviors and techniques to MITRE ATT&CK and other useful analytical frameworks.
- Produce timely intelligence reports, customer advisories, executive briefings and technical notes.
- Provide actionable IOCs, TTPs and detection recommendations to security engineering and incident response.
- Correlate external intelligence with Vorpcel telemetry while preserving tenant isolation and data handling rules.
- Maintain source reliability, confidence levels and analytical assumptions in intelligence products.
- Improve collection plans, research workflows, automation and the team's intelligence knowledge base.
Lo que buscamos
- Demonstrated experience in threat intelligence, detection engineering, SOC analysis or incident response.
- Strong understanding of attacker tactics, techniques and procedures and the MITRE ATT&CK framework.
- Familiarity with the CVE ecosystem, exploit activity, phishing, credential abuse and adversary infrastructure.
- Ability to assess source reliability, express confidence and distinguish evidence from analytical judgment.
- Experience analyzing security telemetry, indicators and relationships across large or varied datasets.
- Practical Python skills for data analysis, API integrations and workflow automation.
- Clear, structured writing for technical, operational and executive audiences.
- Strong research discipline, curiosity and care when handling sensitive information.
- Nice to have: experience with malware analysis, reverse engineering, threat hunting or link analysis.
- Nice to have: GCTI, GCIH or equivalent practical training and published analytical work.