Sr CyberSec Spec Threat Intel
3 days ago
Winnipeg, Manitoba, Canada
Canadian Tire Corporation
Full-time
Free with email or Google
Save this job and keep your search organized
Create a free account to save jobs, create alerts and return to this listing from your dashboard.
Free with email or Google
Develop and operationalize cyber threat intelligence (CTI) capabilities, including reporting, analysis, and dissemination of actionable intelligence.
Collect, process, and analyze tactical, operational, and strategic threat intelligence from internal and external sources.
Produce high-quality intelligence products (response recommendations, advisories, alerts, reports, briefings) tailored to both technical and executive audiences.
Conduct threat trend analysis and correlation across diverse intelligence sources to identify emerging threats, shifts in adversary TTPs, and opportunities for resilience improvement.
Support incident response (IR) and threat hunting activities by providing timely intelligence, context, and adversary insights to active investigations.
Develop and maintain threat intelligence processes, including ASM, IOC lifecycle management and governance within the Threat Intelligence Platform (TIP).
Build and execute structured research plans on emerging threats, including assessing business impact, identifying capability gaps, and recommending mitigation strategies.
Establish and maintain intelligence-sharing processes and partnerships across internal teams and external stakeholders (e.g., ISACs, industry partners).
Act as a trusted CTI advisor to Security Operations, Incident Response, Vulnerability Management, and other cyber functions.
Identify and drive continuous improvements across CTI capabilities, including tooling, workflows, and intelligence quality.
What You’ll Do
Develop and operationalize cyber threat intelligence (CTI) capabilities, including reporting, analysis, and dissemination of actionable intelligence. Collect, process, and analyze tactical, operational, and strategic threat intelligence from internal and external sources. Produce high-quality intelligence products (response recommendations, advisories, alerts, reports, briefings) tailored to both technical and executive audiences. Conduct threat trend analysis and correlation across diverse intelligence sources to identify emerging threats, shifts in adversary TTPs, and opportunities for resilience improvement. Support incident response (IR) and threat hunting activities by providing timely intelligence, context, and adversary insights to active investigations. Develop and maintain threat intelligence processes, including ASM, IOC lifecycle management and governance within the Threat Intelligence Platform (TIP). Build and execute structured research plans on emerging threats, including assessing business impact, identifying capability gaps, and recommending mitigation strategies. Establish and maintain intelligence-sharing processes and partnerships across internal teams and external stakeholders (e.g., ISACs, industry partners). Act as a trusted CTI advisor to Security Operations, Incident Response, Vulnerability Management, and other cyber functions. Identify and drive continuous improvements across CTI capabilities, including tooling, workflows, and intelligence quality. Frontier AI & Advanced Capabilities
Leverage frontier AI and machine learning models to enhance threat intelligence collection, enrichment, correlation, and analysis. Apply AI-driven techniques to identify patterns in adversary behavior, predict attack trends, and improve early warning capabilities. Collaborate with internal teams (SOC, IR, Detection Engineering, Architecture) to embed AI-driven intelligence into detection, response, and automation workflows (e.g., SIEM, SOAR, EDR). Support the responsible adoption of AI in cybersecurity, including validating outputs, reducing model bias, and ensuring intelligence accuracy and reliability. Translate complex AI-driven insights into actionable recommendations for both technical teams and senior stakeholders. Contribute to the development of AI-enabled use cases such as automated IOC generation, threat summarization, adversary profiling, and intelligence-to-detection pipelines. What You Bring
Degree in Cybersecurity, Computer Science, Digital Forensics, or a related field (or equivalent experience). Minimum of 4+ years in cybersecurity, with hands-on experience in threat intelligence, threat hunting, incident response, or security operations. Strong analytical and critical thinking skills, with the ability to translate complex data into actionable intelligence. Experience producing intelligence products and communicating effectively with both technical and business stakeholders. Ability to operate independently and collaboratively in a fast‑paced, high‑pressure environment. Specialized Knowledge
Strong understanding of CTI frameworks (MITRE ATT&CK®, Cyber Kill Chain®, Diamond Model). Knowledge of threat landscape, adversaries (APTs, cybercrime), and TTPs. Familiarity with TIP platforms, IOC lifecycle management, and intelligence workflows. Experience supporting SOC/IR functions, including threat hunting and investigation support. Understanding of security technologies (S
Develop and operationalize cyber threat intelligence (CTI) capabilities, including reporting, analysis, and dissemination of actionable intelligence. Collect, process, and analyze tactical, operational, and strategic threat intelligence from internal and external sources. Produce high-quality intelligence products (response recommendations, advisories, alerts, reports, briefings) tailored to both technical and executive audiences. Conduct threat trend analysis and correlation across diverse intelligence sources to identify emerging threats, shifts in adversary TTPs, and opportunities for resilience improvement. Support incident response (IR) and threat hunting activities by providing timely intelligence, context, and adversary insights to active investigations. Develop and maintain threat intelligence processes, including ASM, IOC lifecycle management and governance within the Threat Intelligence Platform (TIP). Build and execute structured research plans on emerging threats, including assessing business impact, identifying capability gaps, and recommending mitigation strategies. Establish and maintain intelligence-sharing processes and partnerships across internal teams and external stakeholders (e.g., ISACs, industry partners). Act as a trusted CTI advisor to Security Operations, Incident Response, Vulnerability Management, and other cyber functions. Identify and drive continuous improvements across CTI capabilities, including tooling, workflows, and intelligence quality. Frontier AI & Advanced Capabilities
Leverage frontier AI and machine learning models to enhance threat intelligence collection, enrichment, correlation, and analysis. Apply AI-driven techniques to identify patterns in adversary behavior, predict attack trends, and improve early warning capabilities. Collaborate with internal teams (SOC, IR, Detection Engineering, Architecture) to embed AI-driven intelligence into detection, response, and automation workflows (e.g., SIEM, SOAR, EDR). Support the responsible adoption of AI in cybersecurity, including validating outputs, reducing model bias, and ensuring intelligence accuracy and reliability. Translate complex AI-driven insights into actionable recommendations for both technical teams and senior stakeholders. Contribute to the development of AI-enabled use cases such as automated IOC generation, threat summarization, adversary profiling, and intelligence-to-detection pipelines. What You Bring
Degree in Cybersecurity, Computer Science, Digital Forensics, or a related field (or equivalent experience). Minimum of 4+ years in cybersecurity, with hands-on experience in threat intelligence, threat hunting, incident response, or security operations. Strong analytical and critical thinking skills, with the ability to translate complex data into actionable intelligence. Experience producing intelligence products and communicating effectively with both technical and business stakeholders. Ability to operate independently and collaboratively in a fast‑paced, high‑pressure environment. Specialized Knowledge
Strong understanding of CTI frameworks (MITRE ATT&CK®, Cyber Kill Chain®, Diamond Model). Knowledge of threat landscape, adversaries (APTs, cybercrime), and TTPs. Familiarity with TIP platforms, IOC lifecycle management, and intelligence workflows. Experience supporting SOC/IR functions, including threat hunting and investigation support. Understanding of security technologies (S