Cyber Intelligence Analyst
What makes the role special
Founded in 2003 and headquartered in Singapore, Group-IB is a leading creator of cybersecurity technologies to investigate, prevent, and fight digital crime. Combating cybercrime is in the company’s DNA, shaping its technological capabilities to defend businesses, citizens, and support law enforcement operations.
Group-IB’s Digital Crime Resistance Centers (DCRCs) are located in the Middle East, Europe, Central Asia, and Asia-Pacific to help critically analyze and promptly mitigate regional and country-specific threats. These mission-critical units help Group-IB strengthen its contribution to global cybercrime prevention and continually expand its threat-hunting capabilities.
ABOUT THE ROLE
The selected candidate will be responsible for generating comprehensive cyber threat reports for both internal stakeholders and clients/partners. The reports will primarily cover Advanced Persistent Threat (APT) activities, intrusion tactics, techniques and procedures (TTP), as well as targeted entities. The role will involve leveraging internal and external resources to investigate threats and vulnerabilities, while also analyzing different threat actors and their attack infrastructure.
YOUR MISSION
- Analyzing IOCs and TTPs of the Threat Actors from the META Threat Landscape;
- Craft, maintain, and document detection opportunities within the Threat Intelligence platform;
- Perform necessary correlation and research to create useful, compelling, and context-rich alerts for customers;
- Pursue research into current threats and industry trends to be aware of the most up-to-date threats in the META Threat Landscape;
- Drive initiatives to create detection content based on findings stemming from threat hunts and ad hoc detection opportunities;
- Develop mitigation and countermeasure strategies from collected threat intelligence;
- Leveraging MITRE ATT&CK categorization to align observed threat actor activity to Tactics, Techniques, and Procedures (TTPs).
- Create professional reports on a specific threat or the threat landscape in general.
WHAT WE ARE LOOKING FOR
- Understanding and interest in the threat landscape in the META region.
- Experience in analyzing the cybercrime community and profiling the threat actors.
- Basic knowledge of scripting language (Python, Bash).
- Knowledge of network technologies and principles of functioning of data networks, understanding of the features of the common data transfer protocols.
- Knowledge of OS architecture and operating principles.
- Good interpersonal skills, as well as the ability to communicate effectively orally and in writing.
- Experience in working with the next sources: Virustotal, Urlscan, Shodan, RiskIQ, Public sandboxes
WHAT SETS YOU APART
- Group-IB or other Threat Intelligence platforms
WHY CHOOSE GROUP-IB
Group-IB is a global leader in cybersecurity technologies that investigate, predict, prevent, and fight digital crime. We help organizations reduce risk and protect trust. Trusted by governments, major industries, and law enforcement, we deliver adversary-focused, predictive threat intelligence and cyber fraud fusion solutions that detect, analyse, and mitigate regional and country-specific digital crimes.
- Work with real stakes. Group-IB investigates active cybercriminal groups, responds to breaches affecting critical infrastructure, and develops technologies used by law enforcement agencies including INTERPOL, Europol, and Afripol across 60+ countries. We've conducted 1,550+ cybercrime investigations alongside 600+ enterprise customers globally. When you join Group-IB, your work directly disrupts digital crime.
- Grow your way. Choose your own path: deepen your craft as a technical expert, step into leadership, move across to another team, or relocate to one of our Digital Crime Resistance Centers across the Americas, Europe, the Middle East & Africa, Central Asia, and the Asia-Pacific. Your growth is our growth — Group-IB's expansion across 60+ active country operations means real career acceleration.
- We fund professional certifications at company expense — whether you're pursuing CEH, CISSP, OSCP, or specialized certifications in forensics and penetration testing. You don't have to choose between doing the job and advancing your credentials.
- Work alongside industry leaders. Our Unified Risk Platform — Threat Intelligence, Digital Risk Protection, Attack Surface Management, Managed XDR, and more — is recognized by Gartner, Forrester, KuppingerCole, and Datos Insights. Frost & Sullivan named us a 2025 Global Technology Innovation Leader. When you work here, you're building technologies that set the industry standard.
- Real challenges, real expertise. You'll take on complex, real-world problems alongside adversary-centric researchers and incident response experts spread across six continents. We've built 21+ years of proprietary telemetry through 1,500+ joint investigations. No two threats look alike — and neither do the skills you'll develop.
- A team that is genuinely international. Our people come from different countries, speak different languages, and bring different perspectives. What connects us is a shared mission: fighting cybercrime and making the world safer. We care about your wellbeing and happiness as much as your output.
