Scope
Threat Intelligence Senior Analyst monitors and analyzes cyber threats to help the organization stay ahead of attacks. The role focuses on identifying threat actors, understanding their tactics, and turning intelligence into actionable insights to strengthen security defenses. Lead investigations, support incident responses, and provide strategic guidance while collaborating with SOC and cybersecurity teams.
Also mentor others and help shape security strategy based on evolving risks.
What We Expect from You
- Bachelor’s degree or above in Information Technology, Cybersecurity, Computer Studies or related disciplines
- 6+ years of IT work experience with 3+ years of which in Cyber Threat Intelligence (CTI) or Cyber Threat Hunting (CTH)
- Work exposure gained from leading professional services/consultancy firms, cloud platform service providers, banking/financial institutions, government institutions, integrated resort/luxury hotels would have an advantage
- Fluent in English and Cantonese is a MUST
- Strong understanding of cyber threat landscape and attack methodologies, network security, endpoint detection, cloud environment and malware analysis
- Familiar with frameworks such as MITRE ATT&CK and D3FEND
- Able to translate technical intelligence into business impact
- Experienced in SIEM (Splunk, Sentinel etc.), EDR/XDR platforms (CrowdStrike, Defender, etc.), Threat Intelligence Platforms (RecordFuture, Mandiant, ThreatConnect, Anomali etc.) with Scripting (Python, PowerShell, PowerAutomate) a plus
- Professional certifications in cyber security such as GIAC Cyber Threat Intelligence (GCTI), Certified Threat Intelligence Analyst (CTIA), GIAC Security Essentials (GSEC), Systems Security Certified Practitioner (SSCP), CompaTIA Security+, Certified Ethical Hacker (CEH), GIAC Certified Incident Handler (GCIH), GIAC Certified Intrusion Analyst (GCIA), GIAC Certified Enterprise Defender (GCED), GIAC Security Expert (GSE) or Certified Information Systems Security Professional (CISSP) is preferred
- You will be based in Hong Kong for this role with some business travels when required
What You Will Do
- Collect, analyze and interpret cyber threat intelligence from multiple sources (OSINT, commercial feeds, internal telemetry)
- Identify emerging threat actors, tactics, techniques and procedures (TTPs)
- Correlate threat data to assess risks relevant to the organization’s environment
- Lead proactive threat hunting using intelligence-driven hypotheses
- Investigate alerts, incidents and suspicious activities to determine scope and impact
- Participate in cross-functional incident response coordination
- Map adversary behavior to frameworks such as MITRE ATT&CK
- Produce high-quality intelligence reports (strategic, tactical, operational)
- Track threat actor groups, campaigns, malware families and attack infrastructure
- Monitor dark web, forums and underground communities when applicable
- Collaborate and work closely with SOC, Red Team and vulnerability management teams
- Utilize Threat Intelligence Platforms (TIPs) to manage indicators (IOCs) and context
- Work with SIEM, EDR and SOAR tools to enrich detection and response capabilities
- Assess cyber threats in the context of business risk and geopolitical development
- Provide recommendations for risk mitigation and security improvement