Overview
Cyber Threat Intelligence Analyst Jobs in Dubai, United Arab Emirates at Hays
Title: Cyber Threat Intelligence Analyst
Company: Hays
Location: Dubai, United Arab Emirates
We are seeking a Cyber Threat Intelligence Analyst to join a high-performing Cyber Defense team responsible for proactively identifying, investigating, and responding to advanced cyber threats across enterprise environments.
The successful candidate will play a key role in Threat Intelligence, Threat Hunting, Incident Response, Digital Forensics, and Detection Engineering activities. This position requires a hands-on cybersecurity professional capable of analyzing attacker behavior, conducting investigations, developing detection capabilities, and providing actionable intelligence to strengthen the organization’s security posture.
Key Responsibilities
- Conduct proactive threat hunting activities across cloud and on-premises environments.
- Investigate and respond to cybersecurity incidents throughout the full incident response lifecycle.
- Perform digital forensic investigations, evidence collection, and root cause analysis.
- Analyze attacker tactics, techniques, and procedures (TTPs) using MITRE ATT&CK.
- Utilize Cyber Threat Intelligence (CTI) to identify, assess, and mitigate emerging threats.
- Develop and enhance detection use cases, correlation rules, and threat hunting methodologies.
- Correlate threat intelligence feeds with internal telemetry to identify security threats.
- Perform malware analysis and investigate suspicious files, processes, and network activity.
- Analyze security, application, and system logs to identify indicators of compromise.
- Support executive reporting through actionable threat and incident intelligence.
- Collaborate with SOC, DFIR, Infrastructure, and Security Engineering teams to improve cyber resilience.
- Contribute to continuous improvement of cyber defense processes, tooling, and automation
Required Skills & Experience
Core Cybersecurity Skills
- Cyber Threat Intelligence (CTI)
- Threat Hunting
- Incident Response (IR)
- Digital Forensics (DFIR)
- Malware Analysis
- Threat Detection & Detection Engineering
- Security Operations (SOC)
- MITRE ATT&CK Framework
- Cyber Kill Chain
- Root Cause Analysis
SIEM & Security Tools
Experience with one or more:
- Microsoft Sentinel
- Splunk
- QRadar
- ELK
- Chronicle
- ArcSight
EDR & Security Platforms
Experience with one or more:
- Microsoft Defender
- CrowdStrike Falcon
- SentinelOne
- Carbon Black
Technical Skills
- KQL
- SQL
- Python
- PowerShell
- Log Analysis
- Threat Intelligence Automation
- Threat Intelligence Platforms
Experience with one or more:
- Recorded Future
- Anomali
- Flashpoint
- ThreatQ
- Threat Intelligence Feed Management
Preferred Experience
- Threat Intelligence-driven hunting.
- Host and endpoint forensic investigations.
- Malware and network traffic analysis.
- Detection engineering and use-case development.
- Purple Team exercises and adversary simulation.
- Threat actor tracking and intelligence reporting.
- Incident response tabletop exercises.
- Cloud security monitoring and investigations.
- Executive-level incident and threat reporting.
Preferred Certifications
One or more of the following is highly desirable:
- GCIH
- GCFA
- GCIA
- GFCE
- CHFI
- OSCP
- CREST Threat Intelligence Analyst
- CREST Intrusion Analyst
- CrowdStrike Falcon Hunter / Responder
- eCTHP
- eCIR
Experience Required
- 5-8 years of cybersecurity experience.
- 3+ years in Threat Hunting, Incident Response, Threat Intelligence, Digital Forensics, or SOC operations.
- Experience working within enterprise-scale environments.
- Strong stakeholder communication skills and ability to present findings to technical and non-technical audiences.