Threat Analyst
Job Summary
Were the proactive cyber threat team responsible for keeping our airports airlines flying smoothly and borders open. Our tech and communication innovations are the secret behind the success of the worlds air travel industry. Youll find us at 95% of international hubs. We partner closely with over 2500 transportation and government clients each with their own unique needs and challenges. Our goal is to find fresh solutions and cutting-edge tech to make their operations run like clockwork.
Want to be a part of something big Are you ready to love your job The adventure begins right here with you at SITA.
As a Threat Analyst you will be part of the CSIRT Threat Team within SITAs global Enterprise Information Security Office (EISO). Our mission is simple: proactively identify threats before they become incidents - essentially determining who is knocking at our door. This dual-discipline role spans both Cyber Threat Intelligence (CTI) and Threat Hunting enabling SITA to anticipate detect and act on adversary activity targeting SITA its business units subsidiaries its customers and the broader aviation industry.
You will operate within a globally distributed team spanning primarily Montreal Singapore and Cairo contributing to 24/7/365 operations coverage.
- Intelligence Gathering & Analysis - Collect and analyze data from OSINT commercial threat feeds (Recorded Future Mandiant) Aviation-ISAC dark web forums law enforcement government and internal telemetry to identify emerging threats threat actors and vulnerabilities relevant to SITA and the aviation sector.
- Threat Actor Profiling - Research and maintain profiles on threat actor groups (nation-state APTs cybercriminal syndicates hacktivists) targeting aviation critical infrastructure and SITAs operations globally.
- Intelligence Dissemination - Produce and distribute intelligence products in clear actionable formats including weekly Threat Newsletters quarterly Threat Landscape Reports Threat Actor Profiles Flash Alerts and Vulnerability & Exploit Intelligence briefs.
- Dark Web & Brand Monitoring - Monitor dark web marketplaces data leak sites paste sites and underground forums for threats to SITAs brand data credentials supply chain and customer base.
- External Collaboration & Information Sharing - Engage with Aviation-ISAC government CERTs law enforcement and industry peers to share intelligence and contribute to the collective defense of the aviation sector.
- Technical Intelligence Integration - Curate and feed IoCs (malware hashes IPs domains) into SIEM (Elastic) SOAR (XSOAR) and XDR platforms (including CrowdStrike Falcon Palo alto Cortex Microsoft Defender and others) to enhance automated detection.
- Proactive Threat Hunting - Develop and execute hypothesis-driven hunts based on adversary TTPs threat intelligence and the MITRE ATT&CK framework to discover hidden threats across SITAs endpoints networks cloud workloads and airport infrastructure.
- Telemetry & Log Analysis - Analyze security logs network traffic endpoint telemetry (EDR/XDR) and system events using SIEM (Elastic/ELK) and XDR to identify anomalies lateral movement privilege escalation and persistence mechanisms.
- Adversary Emulation Support - Collaborate with red/purple team exercises (AttackIQ BAS) to validate detection coverage identify gaps and test defensive controls.
- Intelligence-Driven Hunting - Operationalize threat intelligence (IoCs IoAs threat actor profiles) to drive targeted hunts against specific adversary campaigns relevant to SITA and the aviation sector.
- Documentation & Reporting - Document all hunt hypotheses methodologies findings and recommended mitigations. Produce hunt reports and contribute to the internal AI knowledge base.
- Incident Response Support - Provide threat intelligence context and hunting capabilities to CSIRT during security incidents - including threat actor attribution TTP analysis forensic context and containment recommendations.
- Continuous Improvement - Contribute to the maturity of the CTI and Threat Hunting programs by refining collection requirements (PIRs) hunt methodologies detection content and feedback loops with stakeholders.
- Detection Engineering - Assist the development and refining of detection rules SIEM use cases and hunting playbooks based on hunt findings to continuously improve SITAs automated detection capabilities.
- Bachelors Degree in Cybersecurity Computer Science Information Security Intelligence Studies or equivalent in a related field.
- At least one recognized certification such as: GCTI GCIH GCFA CEH CySA GIAC OSCP Security CREST CTIA or CCTHP.
- 2 years of experience in cyber threat intelligence threat hunting SOC L2 or incident response.
- Hands-on experience with SIEM (Elastic) and EDR/XDR platforms (CrowdStrike Falcon / Cortex / Defender).
- Experience with Threat Intelligence Platforms (Recorded Future MISP OpenCTI).
- Familiarity with SOAR/XSOAR platforms for automation of intelligence and hunting workflows.
- Practical experience with the MITRE ATT&CK framework Diamond Model or Cyber Kill Chain for both intelligence analysis and hunt hypothesis development.
- Proficiency in OSINT collection techniques and tools (Maltego SpiderFoot Shodan etc.).
- Proficiency in log analysis and forensic techniques across endpoint network and memory.
- Solid understanding of networking protocols operating systems internals (Windows/Linux) and common attack vectors.
- Familiarity with malware analysis concepts (static/dynamic) and intrusion detection systems.
- Scripting skills in Python PowerShell or KQL/EQL for data processing automation and custom hunting queries.
- Familiarity with intelligence sharing standards (STIX/TAXII).
Skill | Expected Level |
Threat Intelligence Analysis | L3 - Practitioner |
Threat Hunting Techniques | L3 - Practitioner |
SIEM / EDR Querying & Analysis | L3 - Practitioner |
OSINT Collection & Analysis | L3 - Practitioner |
Incident Response Support | L2-L3 |
Communication & Reporting | L3 - Practitioner |
Problem Solving | L3 - Practitioner |
- Strong analytical and critical thinking abilities - able to assess credibility relevance and impact of threat data.
- Excellent written and verbal communication - ability to translate complex technical findings into actionable intelligence for both technical and executive audiences.
- Intellectual curiosity and passion for continuous learning in a rapidly evolving threat landscape.
- Ability to work independently and collaboratively across a globally distributed team and rotating shifts.
- Cairo role: Fluency in Arabic for regional OSINT collection and MEA-focused threat hunting and intelligence.
- Singapore role: Fluency in Chinese (Mandarin) for APAC-focused APT tracking and intelligence.
- Experience in the aviation sector.
- Familiarity with Breach and Attack Simulation (BAS) tools such as AttackIQ.
- Experience producing operational and tactical threat intelligence for technical audiences.
- Flex Week - Work from home up to 2 days/week (subject to teams needs)
- Flex Location - Take up to 30 days a year to work from any location in the world
- Employee Wellbeing - EAP for you and your dependents 24/7 365 days/year
- Professional Development - LinkedIn Learning SANS training and industry certifications
- Competitive Benefits - Competitive benefits aligned with your local market
SITA is an Equal Opportunity Employer. We value a diverse support of our Employment Equity Program we encourage women aboriginal people members of visible minorities and/or persons with disabilities to apply and self-identify in the application process.
Required Experience:
IC
About Company
At SITA we lead one of the most exciting and advanced industries in the world. With us, there are no limits for people looking to explore the edges of possibility and beyond. We are the world’s leading specialist in air transport communications and information technology. Around the ... View more