Sygnia

Threat Intelligence Researcher

Sygnia  •  Tel Aviv, IL (Onsite)  •  18 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Sygnia is a top-tier cyber technology and services company providing consulting, incident response support, threat intelligence, and monitoring services for organizations worldwide. Sygnia works with companies to proactively build their cyber resilience and to respond to and defeat attacks within their networks. It is the trusted advisor and cybersecurity service provider of IT and security teams, senior management, and boards of leading organizations worldwide, including Fortune 100 companies.

The company draws on top talent from elite military technology units and across the cybersecurity industry and is home to some of the world’s top cyber experts. Described by Forbes as a “cyber security delta force,” Sygnia applies technological superiority, digital combat experience, data analytics, and a business-driven mindset to help organizations excel in the age of cyber.

Sygnia is looking for a Threat Intelligence Researcher to join its Threat Intelligence Group and support the company’s Cyber Threat Intelligence Exposure Management (CTIEM) services, Incident Response engagement and proactive services. In this position, you will identify, investigate, and monitor external cyber threats and organizational exposures across the open web, dark web, social media platforms, and other intelligence sources. You will help organizations understand and reduce their external attack surface, detect brand abuse and malicious activity targeting their assets, and develop innovative intelligence-driven monitoring capabilities leveraging automation and AI technologies.

The successful candidate should be a creative, highly motivated, and independent researcher with strong analytical skills, a deep understanding of attacker methodologies, and a passion for solving complex intelligence challenges. As part of the role, you will engage with clients, support operational teams, and contribute to the development of cutting-edge CTIEM capabilities.

Main Responsibilities

  • Conduct proactive monitoring and investigations across the open web, dark web, forums, marketplaces, messaging platforms, and social media channels to identify threats targeting client organizations.
  • Analyze organizational exposure across external attack surfaces, including internet-facing assets, leaked information, exposed services, and emerging risks.
  • Investigate and identify brand abuse activities, impersonation attempts, phishing campaigns, fraudulent domains, and other malicious activities targeting clients.
  • Detect and assess data exposures and information leaks through a variety of intelligence sources, commercial platforms, and proprietary tools.
  • Utilize Attack Surface Management (ASM) platforms and related technologies to identify, prioritize, and assess external security exposures.
  • Develop and enhance intelligence collection, detection, and monitoring capabilities through automation and AI-driven solutions, primarily using Python.
  • Produce comprehensive intelligence reports, exposure assessments, and actionable recommendations for clients and internal stakeholders.
  • Engage directly with clients to present findings, explain risks, and support remediation efforts.
  • Collaborate closely with Incident Response teams to support ongoing investigations.

Requirements

Main Requirements

  • 3+ years of experience in Cyber Threat Intelligence, Exposure Management, Threat Research, Cyber Investigations, or related cybersecurity domains.
  • Proven experience conducting investigations across open web, dark web, and social media intelligence sources.
  • Strong understanding of attacker methodologies with emphasis on reconnaissance, phishing, credential theft, social engineering, and initial access techniques.
  • Experience with Attack Surface Management (ASM), External Attack Surface Management (EASM), Digital Risk Protection (DRP), or related technologies.
  • Experience identifying brand abuse, impersonation campaigns, phishing infrastructure, and malicious domain activity.
  • Familiarity with data leak investigations, exposed credentials monitoring, and external exposure analysis.
  • Hands-on experience developing automation, intelligence collection, or detection capabilities using Python.
  • Strong analytical and investigative mindset with the ability to connect disparate pieces of information into meaningful intelligence.
  • Excellent written and verbal communication skills, including the ability to communicate technical findings clearly to clients and executives.
  • Self-motivated, independent, and accountable, with the ability to manage investigations from initiation through delivery.
  • Team player with strong interpersonal skills and a collaborative approach.
Sygnia

About Sygnia

Sygnia is a cyber technology and services company, providing high-end consulting and incident response support for organizations worldwide.

Sygnia works with companies to proactively build their cyber resilience and to respond and defeat attacks within their networks. It is the trusted advisor and cyber security service provider of IT and security teams, senior managements and boards of leading organizations worldwide, including Fortune 100 companies.

The company draws on top talent from the ranks of elite military technology units and from across the cyber industry. It applies technological supremacy, digital combat experience, data analytics and a business-driven mindset to cyber, to deliver military grade security to business.

Sygnia was launched with Team8 group, supported by leading investors and design partners, including Microsoft, Cisco, Qualcomm, Intel, Bessemer, Innovation Endeavors, and Temasek. Since October 2018, Sygnia is a Team8 and a Temasek International company.

Industry
IT & Software
Company Size
201-500 employees
Headquarters
Tel Aviv, IL
Year Founded
2015
Website
sygnia.co
Social Media