← Zurück zur Liste
Stelle

Experienced CTI Analyst – Cybersecurity, Île-de-France

Sonstige • Vor Ort • Vollzeit • Frankreich Courbevoie, Frankreich

As an experienced CTI analyst you track adversary infrastructure, perform advanced threat hunting and analyse malware used by attacker groups, including state-backed APTs, working closely with the SOC, CERT and Red Team.

Stack

Responsibilities

  • ▹Map and track adversary infrastructure using OSINT sources and specialist tools (Censys, Shodan, PassiveTotal, etc.)
  • ▹Identify and monitor C2 servers, domains and technical artefacts used by attackers
  • ▹Build proactive detection methods based on network fingerprints and attribution techniques
  • ▹Study malicious payloads used by APT groups (state-sponsored or advanced cybercriminals)
  • ▹Analyse samples in sandboxes using dynamic and static analysis
  • ▹Identify malware obfuscation, persistence and communication mechanisms
  • ▹Turn technical information into actionable intelligence to improve detection and incident response
  • ▹Contribute to enriching Threat Intelligence platforms (MISP, OpenCTI, etc.) and to IoC dissemination
  • ▹Write detailed reports on attack campaigns, adversary TTPs (MITRE ATT&CK, MITRE ATLAS) and threat trends

Requirements

  • ▹Engineering school degree or equivalent
  • ▹At least 3-4 years of experience (excluding internships and work-study) in cyber threat intelligence, or in topics combining SOC detection and CTI
  • ▹Command of threat intelligence tools and security platforms
  • ▹Advanced technical skills in threat hunting, OSINT, network analysis and investigation of malicious infrastructure
  • ▹Experience reverse engineering malware and good knowledge of PE and ELF formats, packers and the languages used (C/C++, Python, ASM)
  • ▹Good understanding of APT groups, their operations, motivations and infrastructure
  • ▹Experience with Threat Intelligence tools and CTI platforms (MISP, OpenCTI, Yara, Sigma, etc.)
  • ▹Ability to write clear, actionable reports for both analysts and decision makers

Nice to have

  • ▹Cybersecurity certifications (e.g. CISSP, CEH, GIAC)
  • ▹Additional language skills such as Russian or Mandarin
  • ▹Threat Intelligence experience applied to TLPT (Threat-Led Penetration Testing)
  • ▹Knowledge of the malicious protocols used by RATs and C2s
  • ▹Ability to automate tasks with Python or other scripts
  • ▹Participation in conferences, CTFs or open-source CTI projects

Soft skills

Analytical mindAutonomyCuriosity about cybersecurity monitoring

What we offer

  • ▹Remote work up to 2 days a week depending on assignments
  • ▹Benefits package: health insurance, works council (CSE) perks, meal vouchers, profit-sharing agreement, holiday bonus and referral bonus
  • ▹More than 30 job families and many career opportunities
  • ▹Hundreds of trainings and self-paced platforms to prepare certifications
  • ▹Opportunity to get involved with the company foundation or the partner Vendredi
  • ▹Join the Tech'Me UP community (training, conferences, tech watch and more)

About the company

Sopra Steria is a major European tech player with 51,000 employees in nearly 30 countries, offering consulting, digital services and solutions that help clients with their digital transformation. Its cybersecurity business line has more than 2,500 experts in Europe (over half in France) and is also present in Toronto and Singapore.

Languages: Angol: folyékony, kétnyelvű szint, Orosz vagy mandarin: előny
Education: Mérnöki egyetemi végzettség vagy azzal egyenértékű

Ähnliche Stellen