Essential Functions/Responsibilities
• Assist with collection, processing, and analysis tasks across the intelligence requirements-to-dissemination workflow.
• Help maintain the intelligence requirements register under guidance from senior team members.
• Draft threat actor profiles, campaign summaries, and indicator packages for technical audiences; refine products based on senior engineer feedback.
• Ingest, validate, and score indicators of compromise (IOCs) from commercial feeds (e.g., Recorded Future), open-source, and internal sources.
• Support integration of IOC pipelines with SIEM and EDR platforms, including Sumo Logic and CrowdStrike Falcon/NG SIEM.
• Apply confidence scoring and structured formats (e.g., STIX 2.1) to intelligence artifacts; escalate data quality issues to senior team members.
• Monitor open-source package registries (npm, PyPI, Go, Maven, and others) and CI/CD pipeline integrity signals for indicators of adversarial activity including typosquatting, dependency confusion, and build-pipeline compromise.
• Contribute to the internal supply chain threat detection program by assisting with data collection, documentation, and detection logic testing.
• Assist broader cybersecurity and security operations functions — including CSIRT, Vulnerability Management, and PSIRT — with alert triage, threat research, and DLP investigation enrichment, as capacity allows.
• Support security investigations by researching threat actor behaviors, identifying relevant IOCs, and providing contextual summaries.
• Prepare threat intelligence summaries and briefing materials for internal consumers including CSIRT and Vulnerability Management.
• Identify opportunities for workflow improvements within own area and recommend changes to senior team members.
• Learn and follow applicable standards for intelligence data handling, sharing agreements, and governance; contribute to supporting documentation as directed.
• Other tasks and activities as assigned.