Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Threat Intelligence Analyst image - Rise Careers
Job details

Threat Intelligence Analyst

About the Role

Abnormal Security is looking for a Threat Intelligence Analyst with expertise in threat hunting, detection engineering, and operational intelligence to combat cloud-based phishing attacks, account takeovers (ATO), and business email compromise (BEC). In this role, you will perform threat hunts in Cloud/SaaS environments, extract actionable intelligence, and collaborate with R&D and Engineering teams to enhance security detections and counter evolving adversary tactics.

Who you are

  • Deeply experienced in Threat Intelligence & Threat Hunting, with a focus on Cloud/SaaS threats.
  • Strong understanding of phishing, cloud-native threats, and adversary TTPs targeting identity and email security.
  • Data-driven mindset, with experience analyzing large datasets using SQL, PySpark, and other query-based analysis tools.
  • Skilled at bridging threat intelligence with engineering teams, ensuring insights translate into effective security controls.
  • Comfortable working in agile, cross-functional teams, driving threat research into practical security improvements.
  • Proven ability to present complex technical concepts to both technical and non-technical audiences.
  • Results-driven, highly collaborative, self-motivated, and adaptable in fast-paced environments.

What you will do

Threat Hunting & Threat Intelligence

  • Perform threat hunting and investigative research in Cloud/SaaS environments, focusing on email security, phishing, and account takeovers.
  • Identify MFA bypass techniques, phishing infrastructure, and cloud-native attack methods targeting enterprise SaaS environments.
  • Fuse internal telemetry, OSINT, and third-party intelligence sources to uncover and disrupt evolving threat actor campaigns.
  • Develop threat models and attack hypotheses to identify new cloud-focused attack vectors.
  • Conduct incident triage and investigative support for escalated incidents, providing internal teams with expertise on threat actors’ tools, techniques, and procedures (TTPs).

Detection Engineering

  • Collaborate with R&D and Engineering teams to translate threat intelligence into scalable detections and mitigations.
  • Design and refine cloud threat detection logic, hunting queries, and behavioral analytics to identify attacker activity.
  • Analyze phishing toolkits, adversary infrastructure, and cloud-native attack methodologies to enhance proactive defenses.
  • Work with product security teams to improve email security and identity protection mechanisms in Cloud/SaaS platforms.

Security Research

  • Track and analyze threat actor groups, phishing campaigns, and cloud-based attack methodologies.
  • Provide technical intelligence briefings to R&D and Engineering teams to inform security product improvements.
  • Partner with internal stakeholders to evaluate emerging threats and recommend security enhancements for SaaS environments.

Must Haves 

  • Deep Expertise: 5+ years in cyber threat intelligence, threat hunting, or security research.
  • 3+ years of experience in threat hunting and threat research within cloud ecosystems.
  • Expertise in cloud security, SaaS-based attacks, and email security threats (ATO, BEC, phishing, MFA bypass, etc.).
  • Strong data analysis skills with experience using SQL, PySpark, or other query languages to investigate large-scale threats.
  • Deep understanding of MITRE ATT&CK, phishing tactics, and adversary infrastructure analysis.
  • Hands-on experience with email security platforms, cloud threat analytics, and security automation
  • Collaborative Mindset: Ability to work cross-functionally with other departments such as R&D, Engineering, and Operations to achieve comprehensive cybersecurity coverage.

Nice to Have 

  • Security certifications (GCTI, GCFA, CISSP, or similar).
  • Experience in security engineering, cloud-native security, or advanced detection development.
  • Background in threat modeling, adversary emulation, or attacker TTP analysis.
  • Experience working in high-scale SaaS environments, analyzing large security datasets.

 

#LI-LB3

Abnormal Security Glassdoor Company Review
4.9 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
Abnormal Security DE&I Review
4.7 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
CEO of Abnormal Security
Abnormal Security CEO photo
Evan Reiser
Approve of CEO

Average salary estimate

$100000 / YEARLY (est.)
min
max
$80000K
$120000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

Similar Jobs
Photo of the Rise User
McCalla Raymer Leibert Pierce Remote Iselin, New Jersey, United States
Posted 3 days ago

We are seeking a detail-oriented Cybersecurity Analyst to join our team in Iselin, NJ, dedicated to safeguarding our organization's assets against cyber threats.

Photo of the Rise User
CSN Collision Remote No location specified
Posted 4 days ago

CSN Collision seeks a motivated Junior Developer to enhance their technology systems that support collision repairs in a fast-paced environment.

Photo of the Rise User
General Dynamics Information Technology Hybrid Washington, District of Columbia, United States
Posted 13 days ago

Join a leading technology services company as a Systems Engineer focusing on Citrix operations for the Department of State.

Posted 5 days ago

Join Delaware Nation Investments as a System Administrator and play a key role in supporting Air Force Sustainment Center's IT and cybersecurity operations.

Photo of the Rise User
Posted 3 days ago

Join T5 Data Centers as a Data Center Technician, where your skills will help maintain and enhance critical IT infrastructure for enterprise clients.

Photo of the Rise User
Posted 4 days ago

Join RESPEC as a Microsoft Power Platform Developer to drive innovative low-code solutions for critical environmental and regulatory challenges.

Photo of the Rise User
Microsoft Hybrid Richmond, Virginia, United States
Posted 12 days ago
Inclusive & Diverse
Mission Driven
Social Impact Driven
Passion for Exploration
Dare to be Different
Diversity of Opinions
Reward & Recognition
Empathetic
Feedback Forward
Work/Life Harmony
Collaboration over Competition
Growth & Learning
Transparent & Candid
Customer-Centric
Rise from Within
Friends Outside of Work
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Learning & Development
Work Visa Sponsorship
Employee Resource Groups
401K Matching
Paid Time-Off
Maternity Leave
Social Gatherings
Company Retreats

Become a key player in Microsoft’s cloud services infrastructure as a Data Center Technician in Richmond, Virginia.

Photo of the Rise User

Join SPS Commerce as an Applications Engineer to enhance technology operations and deliver innovative solutions in a dynamic environment.

Photo of the Rise User

Standard Chartered is seeking a Site Reliability Engineer in Newark to enhance their Financial Institution Clearing services through robust technology strategies and operational excellence.

Photo of the Rise User
Citi Hybrid Tampa Florida United States
Posted 5 days ago
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony

Citi invites experienced candidates to apply for a senior role as an Applications Development Technology Lead Analyst, leveraging your expertise to enhance applications systems.

Photo of the Rise User

Join Renesas as a Senior Global Microsoft Endpoint Engineer and play a key role in shaping their global endpoint computing strategy.

Photo of the Rise User

Seeking a Simulator Technician Maintenance III/Lead with strong leadership skills to join Advanced IT Concepts, dedicated to supporting military training systems.

Photo of the Rise User
Posted 11 days ago

Join Uni Systems to lead the design and implementation of Microsoft-based IT infrastructures in a supportive and dynamic environment.

Abnormal Security's Mission is to make the world a safer place through new applications of Machine Learning and AI technologies. We have started with email security, but that is just the beginning.

103 jobs
MATCH
Calculating your matching score...
BENEFITS & PERKS
Dental Insurance
Disability Insurance
Flexible Spending Account (FSA)
Vision Insurance
Performance Bonus
Family Medical Leave
Paid Holidays
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
February 20, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY