Cyber Threat Modeling Integration Engineer

Cyber Threat Modeling Integration Engineer

Posted 1 day ago by 1753948450

Negotiable
Outside
Remote
USA

Summary: The Cyber Threat Modeling Integration Engineer role focuses on developing and updating custom parsers and connectors for the Operational Defense Intelligence Network (ODIN), enhancing the organization's threat intelligence capabilities. The position requires collaboration with various teams to improve security posture and integrate innovative technologies. Candidates must possess strong technical skills in Cyber Threat Intelligence and programming, particularly in Python. This is a remote position based in the USA, classified as outside IR35.

Key Responsibilities:

  • Develop and update custom parsers/connectors for ODIN to automate data importation from intelligence sources.
  • Support the development of additional parsers/connectors and periodic updates of existing ones.
  • Design and implement solutions to enhance security across multiple platforms.
  • Develop security content for tools used by the Threat Management team.
  • Integrate custom technology to improve alert accuracy for Threat Management teams.
  • Create well-documented code and process documentation.
  • Utilize REST and SOAP APIs to enhance detection and response capabilities.
  • Collaborate with Cyber Command Security Sciences team for continuous security improvement.
  • Handle special projects and initiatives as assigned.

Key Skills:

  • At least 4 years of experience in Cyber Threat Intelligence initiatives.
  • Proficient in Python.
  • Ability to leverage REST APIs for tool and platform integration.
  • Proficient in git version control and git life-cycle development.
  • Excellent verbal and written communication skills.
  • Basic understanding of Agile development model.

Salary (Rate): undetermined

City: undetermined

Country: USA

Working Arrangements: remote

IR35 Status: outside IR35

Seniority Level: undetermined

Industry: IT

Detailed Description From Employer:

Position: Cyber Threat Modeling Integration Engineer

Location: Remote

Duration: 12 months

Scope of services tasks:

  • CTI currently leverages contract engineers to develop and update custom parsers / connectors for the Operational Defense Intelligence Network (ODIN), CTI's primary threat intelligence platform and workbench. These parsers / connectors are used to automate the importation of data and reports into ODIN from our internal and external intelligence and data sources, which are critical to core CTI functions and workflows, including disseminating intelligence to its stakeholder-facing finished intelligence (FINTEL) platform, Threat Observables and Reports (ThOR).
  • CTI requires development of several additional parsers / connectors to meet organizational requirements and support periodic updates and tuning of existing parsers / connectors.
  • The access to shared threat intelligence and models enabled by these parsers connectors provides a wider view into the network threat spectrum as provided by multiple threat models, vendors and industry partners.
  • Design and implement solutions that enhances the security posture of tools across multiple platforms.
  • Develop security content for tools and technologies that the Threat Management team relies
  • on to ensure business as usual functioning.
  • Integrate innovative and custom technology to improve accuracy of alerts and notifications
  • received by teams within Threat Management.
  • Create well documented and clearly articulated code, process and services documentation.
  • Understanding REST and SOAP API usage and implementing solutions utilizing APIs from Cyber Command utilized solutions, that enhance detection and response capabilities of the OTI Threat Management.
  • Work closely with Cyber Command Security Sciences team to ensure continuous improvement of the security posture of key tools and technologies that protect the City of New York.
  • Handle special projects and initiatives as assigned. Timekeeping system and the project manager must approve those hours worked above the weekly maximum.

Mandatory Skills/Experience:

Candidates who do not have the mandatory skills will not be considered.

  • At least 4 years of experience in Cyber Threat Intelligence initiatives, including enhancing prevention, detection, response and recovery efforts through various technical and operational methods.
  • Proficient in Python.
  • Ability to leverage REST API s to build tool and platform integration.
  • Proficient in git version control and git life-cycle development.
  • Excellent verbal and written communication skills are required.
  • Basic understanding of Agile development model.

Desirable skills/experience:

  • Experience working with Open CTI.
  • Experience developing parsers for text-based resources.
  • Understanding of public cloud platforms and experience with utilizing platforms such as Azure, AWS or Google Cloud.
  • Experience working in a security environment and/or supporting security teams from a technical standpoint.
  • Familiarity with using version control source-code repositories.