Overview
NVISO protects European society from cyber attacks by offering cybersecurity services to private and governmental organisations. Our values are Proud, Break Barriers, Care, and No BS.
Responsibilities
* Execute threat intelligence engagements and project-related tasks independently, based on guidance from the Threat Intelligence Manager in charge.
* Act as engagement lead or primary analyst on advanced TI engagements, including TIBER-EU, TLPT, and other intelligence-led security assessments.
* Manage stakeholder relationships throughout engagements, serving as the primary threat intelligence point of contact for clients, regulators, and internal teams.
* Coach and mentor junior threat intelligence analysts, providing technical guidance, reviewing deliverables, and supporting their professional development.
* Produce and deliver threat landscape reports (generic and targeted), capability maturity assessments, strategic intelligence briefings, and threat actor analysis tailored to client sectors and risk profiles.
* Conduct dark web monitoring assessments, identifying exposed credentials, leaked data, and digital risks beyond conventional security perimeters.
* Provide threat intelligence support during incident response engagements, including threat actor attribution, TTP analysis, and intelligence-driven containment and remediation recommendations.
* Deliver threat-based briefings and security awareness sessions for managerial and technical audiences, leveraging NVISO's incident response and threat intelligence experience.
* Drive continuous improvement of NVISO's threat intelligence processes, methodologies, and service offerings, ensuring alignment with regulatory requirements and industry best practices.
* Support the Threat Intelligence Manager with service strategy definition, business development activities, and contribution to proposals and client engagement planning.
* Maintain current knowledge of threat landscapes across key sectors, including TTPs of advanced persistent threat actors, emerging attack techniques, and evolving regulatory requirements.
* Support cross-functional collaboration with NVISO's incident response, red team, and SOC teams to provide integrated threat intelligence services.
Requirements
* You hold citizenship in one of the 32 NATO member states.
* 5+ years of experience in Cyber Security and at least 3+ years in cyber threat intelligence, including production of intelligence assessments, threat reporting, and client-facing delivery.
* Demonstrated experience delivering threat intelligence for TIBER-EU and/or TLPT assessments within the financial services sector.
* Strong understanding of threat landscapes across financial services, technology, and critical infrastructure sectors, including relevant threat actors, attack patterns, and regulatory requirements.
* Proven experience establishing or improving threat intelligence capabilities, processes, and programmes within organisations.
* Strong analytical and research skills, with proficiency in intelligence collection from open-source, dark web, and commercial threat intelligence platforms.
* Expertise in threat actor profiling, TTP analysis, and mapping to frameworks such as MITRE ATT&CK, Kill Chain & Diamond model.
* Experience supporting incident response activities with threat intelligence, including threat actor attribution and intelligence-driven recommendations.
* Proven ability to produce high-quality written intelligence products for technical and executive audiences.
* Strong stakeholder management and coaching skills, with experience presenting to senior executives, regulators, and technical teams, and mentoring junior analysts.
* Self-starter who takes ownership of deliverables and can work independently to execute complex projects under customer or manager direction.
* Language: German and English at C1+ proficiency for client-facing work across DACH.
Availability
* Standard business hours with occasional flexibility required during active client engagements and incident response support.
Travel
* Some limited travel within DE/AT/CH (~10%) for onsite engagements, workshops, and stakeholder meetings.
Benefits
* Working and learning from the best people in the European cyber security industry, with multiple SANS instructors and staff able to acquire deep technical security certifications (GSE, GXPN, GREM, GCFA, OSCP, etc.).
* An entrepreneurial and agile company that stimulates and supports new initiatives without losing sight of fun.
* Regular team-building and fun events.
* Dedicated personal coaching for each employee to support well-being and career growth.
* A training budget of €10,000 plus 10 days paid time off rolling over two years.
* Annual gross base salary between €91,000 and €118,000, depending on experience.
* Flexible working hours and home office possibilities (including working abroad within the EU).
* Reimbursement of Deutschlandticket + BahnCard 50 1st Class.
* Business bike leasing.
* Company pension scheme.
* 30 public holidays.
#J-18808-Ljbffr