WARDION
1 month ago
Cyber Intelligence Analyst (CTI)
Sign up to save this job, get alerts, and apply with an optimized CV.
Company information
- Company
- WARDION
- Location
- México, Sonora, Hermosillo Mexico
- Posted
- 1 month ago
Job description
Wardion | Cybersecurity
About the Vacancy
At Wardion, we are expanding our technical team for a large-scale cybersecurity project. We are looking for a Cyber Intelligence Analyst with real experience managing a comprehensive threat intelligence platform, capable of anticipating external risks before they become incidents.
Responsibilities
Brand Protection and External Exposure
- Monitor brand impersonation attempts: similar domains (typosquatting), phishing sites, fake social media profiles, and fraudulent mobile applications that use the organization's identity.
- Track the exposure of executives and key personnel (VIP monitoring) to targeted threats.
- Detect and manage leaks of institutional credentials and data exposed in open sources, forums, and the Dark Web.
- Monitor mentions of the organization in risk channels (criminal forums, messaging channels, paste sites) and coordinate the corresponding response.
Vulnerability Intelligence
- Prioritize vulnerabilities based on real evidence of active exploitation, not just the CVSS score.
- Track zero-day vulnerabilities, as well as the appearance of proofs-of-concept (PoC) and their adoption by threat actors or malware families.
- Enrich the organization's vulnerability management process with real risk context to improve mitigation decision-making.
Attack Surface Management
- Maintain a continuous and updated inventory of internet-exposed assets (domains, subdomains, IP addresses, certificates, cloud services).
- Identify unknown or unauthorized assets (Shadow IT) that represent unmanaged risk.
- Detect insecure configurations, exposed services/ports, and expired or misconfigured certificates on the external perimeter.
- Track exposure risk derived from third parties and suppliers.
General Operation
- Define and maintain watchlists for assets, brands, domains, and key personnel.
- Prioritize (score) findings based on relevance, source credibility, and potential impact before escalating them.
- Integrate findings with the SOC (SIEM/SOAR/ticketing) and ensure documentary evidence of such integration.
- Operate under strict security controls (RBAC, logs, encryption) that ensure the integrity of the collected evidence.
Requirements
- Real experience managing an enterprise-level threat intelligence platform (not just consuming third-party reports).
- Hands-on knowledge of Dark Web monitoring, social media, and open sources (OSINT).
- Experience prioritizing risk based on active exploitation intelligence, beyond traditional CVSS.
- Familiarity with external attack surface management (ASM) concepts.
- Clear ethical and legal judgment regarding the limits of threat investigation.
- Desirable: GOSINT, CTIA, or equivalent experience in threat intelligence units.
We Offer
- High-impact and relevant scale project in the sector.
- A strategic role in risk anticipation, with direct visibility into the organization's external security posture.
- Technical growth within a specialized team.
Required skills
Interested in this position?
Create your free account and tailor your CV to match this job.