Overview
WELCOME TO THE CSIRT THREAT TEAM AT SITA
We're the proactive cyber threat team responsible for keeping our airports, airlines, flying smoothly, and borders open. Our tech and communication innovations are the secret behind the success of the world's air travel industry. You'll find us at 95% of international hubs. We partner closely with over 2,500 transportation and government clients, each with their own unique needs and challenges. Our goal is to find fresh solutions and cutting-edge tech to make their operations run like clockwork.
Want to be a part of something big Are you ready to love your job The adventure begins right here, with you, at SITA.
About The Role & Team
Position Title
Threat Analyst
Profession / Career Stream
Cyber Security - Threat Intelligence & Threat Hunting
Grade
4
Reports To
Senior Manager Threat, CSIRT (EISO)
Locations
Cairo, Egypt (MEA)
Openings
4 (2 Cairo
As a Threat Analyst (Grade 4), you will be part of the CSIRT Threat Team within SITA's global Enterprise Information Security Office (EISO). Our mission is simple: proactively identify threats before they become incidents - essentially, determining who is knocking at our door. This dual-discipline role spans both Cyber Threat Intelligence (CTI) and Threat Hunting, enabling SITA to anticipate, detect, and act on adversary activity targeting SITA, its business units, subsidiaries, its customers and the broader aviation industry.
You will operate within a globally distributed team spanning primarily Montreal, Singapore, and Cairo, contributing to 24/7/365 operations coverage.
What You'll Do
Threat Intelligence
- Intelligence Gathering & Analysis - Collect and analyze data from OSINT, commercial threat feeds (Recorded Future, Mandiant), Aviation-ISAC, dark web forums, law enforcement, government and internal telemetry to identify emerging threats, threat actors, and vulnerabilities relevant to SITA and the aviation sector.
- Threat Actor Profiling - Research and maintain profiles on threat actor groups (nation-state APTs, cybercriminal syndicates, hacktivists) targeting aviation, critical infrastructure, and SITA's operations globally.
- Intelligence Dissemination - Produce and distribute intelligence products in clear, actionable formats including weekly Threat Newsletters, quarterly Threat Landscape Reports, Threat Actor Profiles, Flash Alerts, and Vulnerability & Exploit Intelligence briefs.
- Dark Web & Brand Monitoring - Monitor dark web marketplaces, data leak sites, paste sites, and underground forums for threats to SITA's brand, data, credentials, supply chain, and customer base.
- External Collaboration & Information Sharing - Engage with Aviation-ISAC, government CERTs, law enforcement, and industry peers to share intelligence and contribute to the collective defense of the aviation sector.
- Technical Intelligence Integration - Curate and feed IoCs (malware hashes, IPs, domains) into SIEM (Elastic), SOAR (XSOAR), and XDR platforms (including CrowdStrike Falcon, Palo alto Cortex, Microsoft Defender and others) to enhance automated detection.
Threat Hunting
- Proactive Threat Hunting - Develop and execute hypothesis-driven hunts based on adversary TTPs, threat intelligence, and the MITRE ATT&CK framework to discover hidden threats across SITA's endpoints, networks, cloud workloads, and airport infrastructure.
- Telemetry & Log Analysis - Analyze security logs, network traffic, endpoint telemetry (EDR/XDR), and system events using SIEM (Elastic/ELK) and XDR to identify anomalies, lateral movement, privilege escalation, and persistence mechanisms.
- Adversary Emulation Support - Collaborate with red/purple team exercises (AttackIQ BAS) to validate detection coverage, identify gaps, and test defensive controls.
- Intelligence-Driven Hunting - Operationalize threat intelligence (IoCs, IoAs, threat actor profiles) to drive targeted hunts against specific adversary campaigns relevant to SITA and the aviation sector.
- Documentation & Reporting - Document all hunt hypotheses, methodologies, findings, and recommended mitigations. Produce hunt reports and contribute to the internal AI knowledge base.
Cross-Functional
- Incident Response Support - Provide threat intelligence context and hunting capabilities to CSIRT during security incidents - including threat actor attribution, TTP analysis, forensic context, and containment recommendations.
- Continuous Improvement - Contribute to the maturity of the CTI and Threat Hunting programs by refining collection requirements (PIRs), hunt methodologies, detection content, and feedback loops with stakeholders.
- Detection Engineering - Assist the development and refining of detection rules, SIEM use cases, and hunting playbooks based on hunt findings to continuously improve SITA's automated detection capabilities.
Qualifications
ABOUT YOUR SKILLS
Education & Professional Qualifications
- Bachelor's Degree in Cybersecurity, Computer Science, Information Security, Intelligence Studies, or equivalent in a related field.
- At least one recognized certification such as: GCTI, GCIH, GCFA, CEH, CySA+, GIAC, OSCP, Security+, CREST, CTIA, or CCTHP.
Experience
- 2+ years of experience in cyber threat intelligence, threat hunting, SOC L2+, or incident response.
- Hands-on experience with SIEM (Elastic) and EDR/XDR platforms (CrowdStrike Falcon / Cortex / Defender).
- Experience with Threat Intelligence Platforms (Recorded Future, MISP, OpenCTI).
- Familiarity with SOAR/XSOAR platforms for automation of intelligence and hunting workflows.
- Practical experience with the MITRE ATT&CK framework, Diamond Model, or Cyber Kill Chain for both intelligence analysis and hunt hypothesis development.
Technical Skills
- Proficiency in OSINT collection techniques and tools (Maltego, SpiderFoot, Shodan, etc.).
- Proficiency in log analysis and forensic techniques across endpoint, network, and memory.
- Solid understanding of networking protocols, operating systems internals (Windows/Linux), and common attack vectors.
- Familiarity with malware analysis concepts (static/dynamic) and intrusion detection systems.
- Scripting skills in Python, PowerShell, or KQL/EQL for data processing, automation, and custom hunting queries.
- Familiarity with intelligence sharing standards (STIX/TAXII).
Functional Skills
Skill
Expected Level
Threat Intelligence Analysis
L3 - Practitioner
Threat Hunting Techniques
L3 - Practitioner
SIEM / EDR Querying & Analysis
L3 - Practitioner
OSINT Collection & Analysis
L3 - Practitioner
Incident Response Support
L2-L3
Communication & Reporting
L3 - Practitioner
Problem Solving
L3 - Practitioner
Soft Skills
- Strong analytical and critical thinking abilities - able to assess credibility, relevance, and impact of threat data.
- Excellent written and verbal communication - ability to translate complex technical findings into actionable intelligence for both technical and executive audiences.
- Intellectual curiosity and passion for continuous learning in a rapidly evolving threat landscape.
- Ability to work independently and collaboratively across a globally distributed team and rotating shifts.
NICE-TO-HAVE
- Cairo role: Fluency in Arabic for regional OSINT collection and MEA-focused threat hunting and intelligence.
- Singapore role: Fluency in Chinese (Mandarin) for APAC-focused APT tracking and intelligence.
- Experience in the aviation sector.
- Familiarity with Breach and Attack Simulation (BAS) tools such as AttackIQ.
- Experience producing operational and tactical threat intelligence for technical audiences.
What We Offer
- Flex Week - Work from home up to 2 days/week (subject to team's needs)
- Flex Location - Take up to 30 days a year to work from any location in the world
- Employee Wellbeing - EAP for you and your dependents 24/7, 365 days/year
- Professional Development - LinkedIn Learning, SANS training, and industry certifications
- Competitive Benefits - Competitive benefits aligned with your local market
SITA is an Equal Opportunity Employer. We value a diverse workforce. In support of our Employment Equity Program, we encourage women, aboriginal people, members of visible minorities, and/or persons with disabilities to apply and self-identify in the application process.
Salary / Compensation Note
Hidden (-999)