• Lead and contribute to threat actor, malware family, and campaign tracking by correlating malware samples, infrastructure, delivery mechanisms, and adversary tradecraft
• Conduct end-to-end cyber threat intelligence research aligned with established frameworks such as the Cyber Threat Intelligence lifecycle, MITRE ATT&CK, and the Diamond Model
• Perform static and dynamic malware analysis across malicious binaries, scripts, and document-based delivery mechanisms
• Investigate malicious network infrastructure and command-and-control activity by pivoting across domains, Internet Protocol addresses, certificates, and related artifacts
• Translate intelligence findings into actionable detection and threat hunting logic using technologies such as YARA, Sigma, and Suricata
• Analyze Windows or macOS internals including application programming interfaces, obfuscation techniques, system calls, and execution behaviors
• Apply advanced open-source intelligence techniques, pivoting methodologies, and enrichment across multiple intelligence platforms and data sources
• Research Deep Web ecosystems including crimeware-as-a-service and ransomware-as-a-service operations
• Analyze and correlate large-scale datasets using technologies such as Structured Query Language, Python, or Excel to extract actionable intelligence insights
• Develop automation and enrichment workflows using scripting languages such as Python
• Partner closely with Security Operations Center and Managed Detection and Response teams to operationalize intelligence into detection, triage, and response workflows
• Support Request for Intelligence workflows by delivering timely and actionable intelligence to operational teams
• Provide escalation support for high-confidence threat events, including enrichment, attribution context, and recommended response actions
• Contribute real-time intelligence support during active incidents and investigations
• Develop intelligence-to-detection feedback loops that improve coverage and operational visibility
• Create scalable intelligence dissemination methods including alerts, intelligence briefs, and knowledge base updates
• Standardize analytical frameworks, intelligence validation practices, and operational research methodologies
• Publish technical research, tradecraft methodologies, blogs, whitepapers, or present at industry workshops and conferences