Cyber Threat Intelligence Analyst
We are seeking a talented and driven Cyber Threat Intelligence Analyst to work with us in Herzliya, with a strong foundation in threat research and applied AI. In this role, you will build how we track and research mobile threats, including nation-state APT groups and mercenary and commercial spyware vendors, and turn that research into new detection logic, rules, tools, and other actionable outputs for DFFIND. You'll bring that same builder's instinct to AI opportunities beyond threat intelligence as well, turning promising ideas into tools that make a real difference across the company. Responsibilities: Research and track threat actors relevant to mobile security, including nation-state APT groups and mercenary and commercial spyware vendors. Develop your own methods and tools for collecting and analyzing threat intelligence from open, commercial, and closed sources. Turn intelligence findings into new detection logic, rules, tools, and other actionable outputs for DFFIND. Maintain threat actor and campaign profiles, mapped to frameworks such as MITRE ATT&CK for Mobile. Identify gaps in current detection coverage and propose new priorities based on the threat landscape. Write clear intelligence reports, briefings, and blog posts for stakeholders. Spot opportunities to apply AI beyond threat intelligence, and design, build, and ship the tools to act on them. Carry AI projects from early ideas through to a working tool in production. Requirements: Several years of experience in threat intelligence, threat research, or a similar security analysis role. A track record of building your own tools, methods, or workflows rather than just using what's already there. Working knowledge of the mercenary spyware and mobile APT landscape, or a demonstrated ability to ramp up quickly in this space. Familiarity with threat intelligence frameworks (MITRE ATT&CK, Diamond Model, or similar). Proficiency with Reverse Engineering of binary samples Proficiency in Python and YARA, with the ability to also use other scripting and programming languages as required. Strong, practical knowledge of AI and LLMs, and experience applying them to real workflows, from prototyping through to production. Strong written communication skills. Comfort working independently and driving projects with minimal oversight. Eligibility to hold, or ability to obtain, a security clearance appropriate to the customer engagements this role supports. Preferred: Experience shipping AI-powered tools or products. Background in a government, military, or national intelligence environment. Familiarity with mobile OS internals and/or forensic concepts. Publications or public research related to mobile threats, spyware, or applied AI in security. What we offer: Joining a team of established and experienced security experts in a mission-driven, high-impact company. Collaborative, creative, and growth-focused environment. High ownership: autonomy over how you approach the work. Meaningful problems: your work touches detection of the most sophisticated threats targeting government and national security customers. Deep technical exposure: close collaboration with engineers and researchers working on the newest mobile threats and exploitation techniques. Competitive compensation and access to the tools and infrastructure needed to do the job well.
Find your next role on Israel's job board.
Browse all jobs