Work setup: Hybrid setup 24x RTO/month) in MOA Pasay Philippines
Shift Schedule: Day Shift (Possible Weekend Coverage)
Required Qualifications:
- Must be a College Graduate
- Must have 12 years of experience in Technical Writing and Malware Analysis
- Demonstrable experience writing reports on technical subject matter (e.g. malware vulnerability exploits offensive security tools) in a clear concise and logical format
- Must have familiarity with MITRE ATT&CK framework including the ability map reported
- Must have familiarity with OSINT research (OpenSource Intelligence)
- Nice to have: Scripting knowledge experience creating malware detections (e.g. YARA Sigma Snort) and experience creating vulnerability detections (e.g. Nuclei)
- Experience working with sandboxes virtual machines or other malware analysis tools
- Familiarity with interpreting and mapping cyberattacks to the Diamond Model of Intrusion Analysis
Specific Duties and Responsibilities
Threat Lead Identification: Research new adversary tactics techniques and procedures (TTPs) using open sources (public information such as security vendor reporting social media code repositories); closed sources (dark web and underground forums); and proprietary sources.
- Subject Matter: Threat leads should focus on team priority intelligence requirements (PIRs). Examples of such subject matter include malware developments offensive security tools vulnerability exploits cloud security and mobile security.
- Key Detail Identification: During research identify and take note of infection chains host and network IoCs malware samples threat actors and MITRE ATT&CK tactics and techniques
Author Insikt Notes: Write TTP Instances detailing identified threat leads. TTP Instances include a combination of information from opensource reporting and your own analysis (i.e. code review static malware analysis). TTP Instances are written and formatted to help our customers understand infection chains while also helping them prepare and validate their defenses.
- Cadence: Write at least 2 TTP Instance notes daily
- Quality: Authored TTP Instances should include minimal grammatical or syntax errors. Plagiarism is not acceptable.
Why Apply
- Hybrid Work Setup
- Equipment provided
- HMO Coverage
- Worklife Balance
- Engagement Activities
- Telecommunication Allowance for Team Leaders and Up
- Performancebased Bonuses (Quarterly)
- For work onsite days the office is located near transport terminals (Mall of Asia Pasay)