{"id":1461079,"url":"https://alion.io/job/thales-group-threat-intelligence-analyst","title":"Threat Intelligence Analyst","company":{"id":143,"name":"Thales Group","domain":"thalesgroup.com","url":"https://alion.io/company/thales","size_band":"5000+","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":{"grade":"A","score":100,"open_postings":23,"ghost_share":0,"stale_share":0,"repost_share":0,"time_to_fill_p50_days":50,"computed_at":"2026-09-30T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"middle","employment_type":"full_time","work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Portugal"],"countries":["PT"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":32000,"max_usd":79000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":414},"experience_years_min":3,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"MISP","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"OpenCTI","optional":false},{"name":"PowerShell","optional":false},{"name":"Python","optional":false},{"name":"Recorded Future","optional":false},{"name":"SIEM","optional":false}],"status":"live","first_seen_at":"2026-09-29T12:23:30Z","employer_posted_date":"2026-09-29","last_verified_at":"2026-10-01T01:27:01Z","board_verified":true,"closed_at":null,"days_open":1,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":1},"description":"Location: Leca do Balio, PortugalKey Responsibilities\nSupport Digital Risk Protection (DRPS) activities, including monitoring leaks, external attack surfaces, fraud threats and digital risks.\nMonitor, identify, and analyze emerging cyber threats, threat actors, campaigns, and attack techniques.\nProduce tactical, operational, and strategic threat intelligence reports.\nConduct research on cybercriminal groups, ransomware operations, vulnerabilities, exploits, and threat trends.\nContribute to threat intelligence briefings, customer reports, executive and operational-level reports.\nAnalyze indicators of compromise (IOCs), tactics, techniques, and procedures (TTPs), and map findings to frameworks such as MITRE ATT&CK.\nEnrich threat intelligence platforms and knowledge bases.\nCollaborate with SOC, Incident Response, and other internal and external cybersecurity teams.\nParticipate in the continuous improvement of intelligence processes, methodologies, and automation initiatives.\nRequired Qualifications\nHigher education degree or technical-professional qualification in Cybersecurity, Computer Engineering, Networks, or a related field.\nMinimum of 3 years of experience in related roles.\nExperience with Digital Risk Protection, brand monitoring and Fraud monitoring.\nExperience with OSINT and SOCMINT techniques, dark web monitoring and intelligence gathering.\nKnowledge on Cyber Threat Intelligence and Threat Exposure Management platforms such as Recorded Future, Sixgill, Flare, or similar.\nExperience with Threat Intelligence Platforms (TIPs) such as OpenCTI, MISP, ThreatQ, or similar.\nUnderstanding of cyber threat actors, malware, ransomware, phishing, and common attack vectors.\nFamiliarity with threat intelligence frameworks and methodologies.\nRelevant certifications or training (e.g. CTIA, GCTI, CPTIA) will be considered an asset.\nStrong analytical, research, and report-writing skills and ability to communicate technical findings to both technical and non-technical audiences. \nTeam-oriented mindset, organizational skills, sense of responsibility, and ability to work effectively in dynamic and collaborative environments.\nBasic knowledge of malware analysis and network traffic analysis and familiarity with SIEM solutions and other security monitoring tools.\nBasic scripting and programing skills will be appreciated (Python, PowerShell, Bash).\nGood written communication skills and ability to understand technical English;\nNative Portuguese speaker and professional proficiency in English (C1).\nLocation: Lisbon or Porto (hybrid working model)","description_format":"text","description_chars":2571,"description_truncated":false,"requirements":{"experience_years_min":3,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[{"language":"Portuguese","level":"Proficiency (C2)","optional":false},{"language":"English","level":"Advanced (C1)","optional":false}]},"benefits":["Hybrid work"],"hiring_locations":[{"name":"Portugal","iso":"PT","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Threat Intelligence","Information Security","Satellite Manufacturing","Electronic Warfare"],"lifecycle":[{"event":"open","at":"2026-09-29T12:23:30Z"}],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":0,"expected_fill_days":50,"reasons":["conf:0","velocity","win:early","comp:brand"],"computed_at":"2026-09-30T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/thales-group-threat-intelligence-analyst","json_url":"https://alion.io/job/thales-group-threat-intelligence-analyst.json","meta":{"generated_at":"2026-10-01T02:02:54Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1653,"day_limit":5000,"remaining_today":3347,"minute_limit":60,"resets_at":"2026-10-02T00:00:00Z"}}}