Login Enter

WARDION

1 month ago

Cyber Intelligence Analyst (CTI)

Sign up free Log in

Sign up to save this job, get alerts, and apply with an optimized CV.

Company information

Company
WARDION
Location
México, Sonora, Hermosillo Mexico
Posted
1 month ago
View all jobs at WARDION

Job description

Wardion | Cybersecurity

About the Vacancy

At Wardion, we are expanding our technical team for a large-scale cybersecurity project. We are looking for a Cyber Intelligence Analyst with real experience managing a comprehensive threat intelligence platform, capable of anticipating external risks before they become incidents.

Responsibilities

Brand Protection and External Exposure

  • Monitor brand impersonation attempts: similar domains (typosquatting), phishing sites, fake social media profiles, and fraudulent mobile applications that use the organization's identity.
  • Track the exposure of executives and key personnel (VIP monitoring) to targeted threats.
  • Detect and manage leaks of institutional credentials and data exposed in open sources, forums, and the Dark Web.
  • Monitor mentions of the organization in risk channels (criminal forums, messaging channels, paste sites) and coordinate the corresponding response.

Vulnerability Intelligence

  • Prioritize vulnerabilities based on real evidence of active exploitation, not just the CVSS score.
  • Track zero-day vulnerabilities, as well as the appearance of proofs-of-concept (PoC) and their adoption by threat actors or malware families.
  • Enrich the organization's vulnerability management process with real risk context to improve mitigation decision-making.

Attack Surface Management

  • Maintain a continuous and updated inventory of internet-exposed assets (domains, subdomains, IP addresses, certificates, cloud services).
  • Identify unknown or unauthorized assets (Shadow IT) that represent unmanaged risk.
  • Detect insecure configurations, exposed services/ports, and expired or misconfigured certificates on the external perimeter.
  • Track exposure risk derived from third parties and suppliers.

General Operation

  • Define and maintain watchlists for assets, brands, domains, and key personnel.
  • Prioritize (score) findings based on relevance, source credibility, and potential impact before escalating them.
  • Integrate findings with the SOC (SIEM/SOAR/ticketing) and ensure documentary evidence of such integration.
  • Operate under strict security controls (RBAC, logs, encryption) that ensure the integrity of the collected evidence.

Requirements

  • Real experience managing an enterprise-level threat intelligence platform (not just consuming third-party reports).
  • Hands-on knowledge of Dark Web monitoring, social media, and open sources (OSINT).
  • Experience prioritizing risk based on active exploitation intelligence, beyond traditional CVSS.
  • Familiarity with external attack surface management (ASM) concepts.
  • Clear ethical and legal judgment regarding the limits of threat investigation.
  • Desirable: GOSINT, CTIA, or equivalent experience in threat intelligence units.

We Offer

  • High-impact and relevant scale project in the sector.
  • A strategic role in risk anticipation, with direct visibility into the organization's external security posture.
  • Technical growth within a specialized team.


Required skills

Interested in this position?

Create your free account and tailor your CV to match this job.