With 1,000+ intelligence professionals serving over 1,900 clients worldwide, Recorded Future is the world’s most advanced, and largest, intelligence company!
The Research on Request Team at Recorded Future is looking for a Threat Intelligence Analyst to assist in producing consistently high quality cyber threat intelligence to clients based on their specific intelligence requirements. This production will likely involve the review and analysis of infrastructure associated with a specific threat actor or campaign, or analysis of indicators associated with a specific incident. In additional, this analysis will be expected to product analysis in line with more general requirements, such as research into overall threats to an industry, region, or technology. The analyst will be primarily responsible for ad hoc intelligence requests. Writing either ad hoc or regular reports requires the ability to work with or automate regularly recurring datasets, while also requiring flexibility to quickly research and analyze a broad spectrum of cyber threat activity, from new attacks against automotive technology to patterns in malware development.
What You'll Do:
- Produce and review finished intelligence reports that address clients’ priority intelligence requirements across a broad range of cyber threat activity topics
- Research indicators of threat activity in the form of netflow / networking data, website / domain / IP infrastructure, security tooling logs, and email metadata
- Engage with clients across report lifecycle: initial scoping, finished intelligence delivery, and follow-up review / support
- Develop novel, automated, or simpler processes for research and analysis
- Work on projects across multiple research teams with sometimes tight deadlines
- 2+ years experience as a threat intelligence analyst or in similar position
- BA/BS or MA/MS degree or equivalent experience in Computer Science, Information Security, or a related field
- Strong understanding of TCP/IP, DNS, HTTP/S, SMTP, and common application-layer protocols
- Ability to analyze netflow data (e.g., source/destination IPs, ports, protocols, volumes, timing)
- Familiarity with routing, ASNs, CIDR, and IP ownership (WHOIS, RIRs)
- Experience investigating malicious domains, URLs, and IP addresses
- Familiarity with attacker infrastructure patterns (e.g., fast-flux, bulletproof hosting, VPS abuse, CDNs, domain generation algorithms)
- Ability to pivot across infrastructure artifacts to identify related activity
- Understanding of email headers and metadata (SPF, DKIM, DMARC, Message-ID, Received headers)
- Experience analyzing phishing, spoofing, and campaign-level email infrastructure
- Practical experience using common threat intelligence analysis models such as MITRE ATT&CK, the Diamond Model, and the Cyber Kill Chain
- Familiarity with and use of common cyber threat intelligence tools such as DomainTools, VirusTotal, SHODAN, etc.
- Ability to understand and analyze malicious scripts or artifacts written in common scripting languages such as Python, JavaScript, XML, etc.
- Demonstrable experience researching and analyzing cyber threats across either a) multiple industries or b) multiple timeframes. Including but not limited to finance, manufacturing, IT services, healthcare, and public sector.
- Managing client expectations based on pre-established scope of work and delivery timeframe
- Ability to convey complex technical and non-technical concepts with intent of delivering value to each client
- Excellent writing skills are mandatory, to be assessed via a writing sample
- Ability to analyze malware samples, including both static and dynamic analysis
- Working knowledge of at least one language other than English, with relevance preferred for regions with more active or sophisticated cyberattackers
- Experience working with clients to produce intelligence requirements, or reports / research in line with such requirements
- Demonstrable experience of conducting cyber threat investigations
#LI-Remote
Why should you join Recorded Future?
Recorded Future employees (or “Futurists”), represent over 40 nationalities and embody our core values of having high standards, practicing inclusion, and acting ethically. Our dedication to empowering clients with intelligence to disrupt adversaries has earned us a 4.6-star user rating on G2 and more than 50% of Fortune 100 companies as customers.
Want more info?
Blog & Podcast: Learn everything you want to know (and maybe some things you’d rather not know) about the world of cyber threat intelligence
Linkedin, Instagram & Twitter: What’s happening at Recorded Future
The Record: The Record is a cybersecurity news publication that explores the untold stories in this rapidly changing field
Timeline: History of Recorded Future
Recognition: Check out our awards and announcements
We are committed to maintaining an environment that attracts and retains talent from a diverse range of experiences, backgrounds and lifestyles. By ensuring all feel included and respected for being unique and bringing their whole selves to work, Recorded Future is made a better place every day.
If you need any accommodation or special assistance to navigate our website or to complete your application, please send an e-mail with your request to our recruiting team at [email protected]
Recorded Future is an equal opportunity and affirmative action employer and we encourage candidates from all backgrounds to apply. Recorded Future does not discriminate based on race, religion, color, national origin, gender including pregnancy, sexual orientation, gender identity, age, marital status, veteran status, disability or any other characteristic protected by law.
Recorded Future will not discharge, discipline or in any other manner discriminate against any employee or applicant for employment because such employee or applicant has inquired about, discussed, or disclosed the compensation of the employee or applicant or another employee or applicant.
Recorded Future does not administer a lie detector test as a condition of employment or continued employment. This is in compliance with the law of the Commonwealth of Massachusetts, and in alignment with our hiring practices across all jurisdictions.
Notice to Agency and Search Firm Representatives:
Recorded Future will not accept unsolicited resumes from any source other than directly from a candidate. Any unsolicited resumes sent to Recorded Future, including those sent to our employees or through our website, will become the property of Recorded Future. Recorded Future will not be liable for any fees related to unsolicited resumes.
Agencies must have a valid written agreement in place with Recorded Future's recruitment team and must receive written authorization before submitting resumes. Submissions made without such agreements and authorization will not be accepted and no fees will be paid.
Note: Our interview process for all final-round candidates requires a mandatory in-person interview or a live, scheduled video conference with the hiring manager. We do not conduct interviews via instant messaging or text. All communications during the application process will come from individuals within our HR department via their Recorded Future email address.

