Enter a job title or keyword

Lead Threat Analyst (Cyber Threat Intelligence | Threat Hunting | GCTI)

Sita


Job Location:

Cairo - Egypt

Monthly Salary: Not provided by the employer
Posted: 29 September 2026 (22 hours ago)
Application Deadline: 27 December 2026
Vacancies: 1 Vacancy

Job Summary

Description External
WELCOME TO SITA

Were the proactive cyber threat team responsible for keeping our airports airlines flying smoothly and borders secure. Our tech and communication innovations are the secret behind the success of the worlds air travel industry. Youll find us at 95% of international hubs. We partner closely with over 2500 transportation and government clients each with their own unique needs and challenges. Our goal is to find fresh solutions and cutting-edge tech to make their operations run like clockwork.

Want to be a part of something big Are you ready to love your job The adventure begins right here with you at SITA.

ABOUT THE ROLE & TEAM

Position Title

Lead Threat Analyst - Cairo

Profession / Career Stream

Cyber Security Cyber Threat Intelligence & Threat Hunting

Grade

5

Reports To

Senior Manager Threat CSIRT (EISO)

Location

Cairo Egypt (MEA)

Openings

1

As the Lead Threat Analyst (Grade 5) in Cairo you will serve as the regional team lead part of the CSIRT Threat Team within SITAs global Enterprise Information Security Office (EISO). Our mission is simple: proactively identify threats before they become incidents - essentially determining who is knocking at our door. This dual-discipline role spans both Cyber Threat Intelligence (CTI) and Threat Hunting enabling SITA to anticipate detect and act on adversary activity targeting SITA its business units subsidiaries its customers and the broader aviation industry. You will be acting as a lead and mentor for the Cairo MEA Region based analysts and hunters.

You will oversee both the intelligence production pipeline and proactive threat hunting operations for the Cairo hub ensuring alignment with SITAs global CSIRT mission and 24/7x365 coverage model.

WHAT YOULL DO
Leadership
  • Lead the Cairo CTI & Hunting Team - Mentor and develop Cairo-based Threat Intelligence Analysts and Threat Hunters set team targets and objectives aligned with our SOC strategy and foster professional growth.
  • Operational Coordination - Ensure seamless shift handoffs between Cairo Singapore and Montreal to maintain continuous global coverage.
  • Stakeholder Communication - Serve as the primary Cairo subject matter expert liaison to CSIRT leadership reporting significant findings hunt outcomes and intelligence products to senior management.
  • Quality Assurance - Review and approve intelligence products and hunt reports produced by the Cairo team before dissemination.
Threat Intelligence (Hands-On)
  • Intelligence Program Execution - Oversee the full intelligence lifecycle: collection requirements (PIRs) gathering analysis production dissemination and feedback.
  • Strategic & Operational Intelligence - Produce and oversee high-quality finished intelligence products including Threat Landscape Reports Threat Actor Profiles Flash Alerts and executive briefings with a focus on MEA regional threats.
  • Source Management - Manage relationships with intelligence sources including Recorded Future Mandiant Aviation-ISAC government CERTs and regional law enforcement.
  • Dark Web Operations - Oversee dark web monitoring and credential exposure investigations ensuring timely escalation and remediation coordination.
Threat Hunting (Hands-On)
  • Hunt Strategy & Methodology - Develop and maintain threat hunting hypotheses tactics techniques and procedures. Lead the team in proactive hypothesis-driven hunts aligned with MITRE ATT&CK during the MEA time zone.
  • Detection Engineering Oversight - Ensure hunt findings are translated into updated SOC use cases detection rules and SIEM content to continuously improve automated defenses.
  • Adversary Emulation Coordination - Coordinate purple team and attack simulations exercises validate detection coverage and drive remediation of identified gaps.
  • Incident Response Integration - Lead the Cairo teams support during major security incidents providing both intelligence context and forensic hunting capabilities to MEA CSIRT Incident responders.
Qualifications External
ABOUT YOUR SKILLS
Education & Professional Qualifications
  • Bachelors Degree in Cybersecurity Computer Science Information Security Intelligence Studies or equivalent. Masters degree is a plus.
  • At least one recognized certification such as: GCTI GCIH GCFA GREM OSCP CEH CISM or CISSP.
Experience
  • 5 years of experience in cyber threat intelligence threat hunting or incident response with at least 2 years in a lead or supervision type of role.
  • Demonstrated experience mentoring a team of security analysts or hunters.
  • Hands-on expertise with SIEM (Elastic) EDR/XDR (CrowdStrike Falcon Cortex XDR) and Threat Intelligence Platforms (Recorded Future MISP OpenCTI).
  • Hands-on expertise with SOAR/XSOAR for automation of intelligence and hunting workflows.
Technical Skills
  • Advanced proficiency in log analysis forensics and threat hunting across endpoint network cloud and identity telemetry.
  • Strong scripting skills in Python PowerShell KQL/EQL for hunting queries automation and data processing.
  • Deep understanding of OSINT collection dark web intelligence and malware analysis (static/dynamic).
  • Knowledge of intelligence sharing frameworks (STIX/TAXII TLP) and industry collaboration models.
Functional Skills

Skill

Expected Level

Team Leadership

L3L4

Threat Intelligence Analysis

L4 Master

Threat Hunting Techniques

L3L4

Detection Engineering

L3 Practitioner

Incident Management

L3 Practitioner

Communication & Stakeholder Management

L4 Master

Problem Solving

L4 Master

Soft Skills
  • Proven leadership - ability to inspire and mentor team peers
  • Exceptional written and verbal communication able to produce executive-level briefings and translate technical findings for non-technical audiences.
  • Strategic thinker with an operational mindset balancing long-term program development with day-to-day tactical execution.
  • Strong cross-cultural awareness and ability to collaborate across global time zones.
NICE-TO-HAVE
  • Fluency in Arabic strongly preferred for regional OSINT MEA threat landscape and local stakeholder engagement.
  • Experience in the aviation sector.
  • Familiarity with Breach and Attack Simulation (BAS) tools such as AttackIQ.
  • Prior experience standing up or scaling a regional security team.
WHAT WE OFFER
  • Flex Week Work from home up to 2 days/week (subject to teams needs)
  • Flex Location Take up to 30 days a year to work from any location in the world
  • Employee Wellbeing EAP for you and your dependents 24/7 365 days/year
  • Professional Development LinkedIn Learning SANS training and industry certifications
  • Competitive Benefits Competitive benefits aligned with your local market

SITA is an Equal Opportunity Employer. We value a diverse support of our Employment Equity Program we encourage women aboriginal people members of visible minorities and/or persons with disabilities to apply and self-identify in the application process.

Salary / Compensation Note
Hidden (-999)

Required Experience:

IC


About Company

Company Logo

At SITA we lead one of the most exciting and advanced industries in the world. With us, there are no limits for people looking to explore the edges of possibility and beyond. We are the world’s leading specialist in air transport communications and information technology. Around the ... View more

View Profile View Profile