Cyber R&D

CTI Analyst

This is some text inside of a div block.

About The Position

Every nation has data. Few can protect it. Fewer still can act on it.

Dream is the sovereign AI and national cyber-defense company for governments.

We help nations secure their most critical systems, connect fragmented information at a national scale, and turn their most sensitive data into decisions, all fully sovereign.

This is more than a job. It's a Dream job, where you'll work at a global scale alongside some of the best AI researchers, cyber operators, and government experts in the world.

We defend nations against the most advanced threats in the world with a national security suite that offers AI-native resilience against APTs with visibility, insights and mediation across Posture, CTI, and Detection & Response, all fully sovereign.

The Dream Job

We are on an expedition to find you, a CTI Analyst who is passionate about turning raw threat data into clear, evidence-backed intelligence and operational outcomes. You’ll play a major role in advancing our next-gen CTI platform across threat actor attribution, adversary infrastructure analysis, External Attack Surface Management (EASM), and STIX-based knowledge management - Working closely with the Engineering, MLOps, and Data teams to deliver high-signal intelligence that drives action. 

The Dream-Maker Responsibilities

  • Execute the CTI research roadmap across threat actor attribution, adversary infrastructure analysis, EASM insights, and STIX-based knowledge management. 
  • Conduct in-depth infrastructure and campaign analysis, including domain/IP relationships, hosting patterns and certificates. 
  • Identify, validate, and track Indicators of Compromise (IOCs) and emerging threats using passive sources and approved active techniques. 
  • Normalize, enrich, deduplicate, and maintain intelligence in STIX 2.1, aligned with internal ontology and quality standards. 
  • Collaborate with the Engineering, MLOps, and Data teams to translate intelligence into actionable intelligence, alerts, and customer-facing outputs. 
  • Produce high-quality intelligence reports, threat briefs, watchlists, and early-warning assessments for internal teams and customers. 
  • Support investigations by providing contextual analysis, confidence scoring, and evidence-backed assessments. 
  • Ensure adherence to governance, ethics, sourcing, provenance, and data-quality standards across all intelligence outputs. 

The Dream Skill Set

  • 3–6+ years of experience in Cyber Threat Intelligence, SOC/IR intelligence support, EASM, or adversary infrastructure analysis. 
  • Strong understanding of DNS, IPs, ASNs, hosting/cloud providers, TLS/PKI, domain lifecycle, and phishing infrastructure. 
  • Hands-on experience with open-source and commercial CTI sources (OSINT, feeds, telemetry, reputation systems). 
  • Practical knowledge of STIX 2.1, MITRE ATT&CK, TAXII; experience with OpenCTI and/or MISP is a strong advantage. 
  • Ability to perform passive discovery and controlled active validation, with a focus on accuracy, evidence discipline, and noise reduction. 
  • Experience using Python for analysis and enrichment (pandas, notebooks); familiarity with Neo4j or Elasticsearch is a plus. 
  • Strong analytical and threat-intelligence writing skills, able to translate technical findings into clear, actionable insights. 
  • Comfortable working in a collaborative, version-controlled environment (Git), with attention to documentation and reproducibility. 
  • Curious, methodical, and impact-driven mindset with a strong sense of intelligence rigor and accountability. 

Never Stop Dreaming...

If you think this role doesn’t fully match your skills but are eager to grow and break glass ceilings, we’d love to hear from you!  


Fill out the form to get in touch with our Expert Team.

Thank you!
Your submission has been received!
Oops! Something went wrong while submitting the form.