• Monitor and analyze cyber threat activity targeting the financial sector, alternative asset management, and adjacent industries using open-source, commercial, and internal sources, correlating across them to identify patterns and provide early warning of emerging campaigns
• Produce finished intelligence products and reports including recurring threat reporting, advisories, campaign profiles, actor dossiers, executive briefings, and visual products such as diagrams, tailored to both technical and non-technical audiences
• Map adversary behaviors to the MITRE ATT&CK framework and maintain threat actor profiles covering TTPs, intent, and relevance to Blackstone
• Extract, validate, enrich, and operationalize indicators of compromise (IOCs) to support detection engineering and incident response workflows
• Leverage AI and automation tooling to scale collection, enrichment, and operationalization of intelligence
• Partner with Alert, Detection & Response and Incident Response teams to translate intelligence into production detections (Splunk SPL, Sigma, YARA)
• Track zero-day and critical vulnerabilities, assess Blackstone’s exposure, and translate findings into new detections and preventions in coordination with detection and security engineering
• Support threat-informed vulnerability prioritization (CVSS, EPSS, CISA KEV) and coordinate remediation tracking with asset owners
• Operate and evolve the firm’s external Attack Surface Management (ASM) program, discovering and inventorying internet-facing assets across Blackstone and its portfolio companies, triaging newly discovered exposures and misconfigurations, and coordinating remediation
• Support Fusion Center digital-threat monitoring, including brand, executive, and reputational exposure across OSINT, social media, and dark web sources
• Contribute to intelligence sharing with trusted industry partners, ISACs (such as FS-ISAC), government partners (such as JCDC), and peer financial institutions
• Participate in incident response and the SOC on-call rotation (occasional, roughly every other month) to respond to escalated security incidents