
REMOTE CLEAREDFINANCIAL CRIMEFULL-TIME
Overview
Enovise's Threat Intelligence practice serves financial institutions, sovereign entities, and CNI operators who cannot afford to be surprised. As a Cyber Threat Intelligence Analyst, you will produce finished intelligence — not raw data summaries — that informs defensive posture, incident response prioritisation, and executive decision-making. You will track adversary campaigns, map emerging financial crime TTPs, and integrate threat feeds into operational workflows across client environments. Your analysis will be consumed by SOC leads, CISO teams, and in some cases, government stakeholders.
Responsibilities
- Produce strategic, operational, and tactical intelligence reports tailored to client risk profiles across the financial sector.
- Track and profile advanced threat actors targeting financial institutions, payment networks, and critical infrastructure.
- Analyse malware samples, phishing campaigns, and initial access broker activity to identify emerging threat patterns.
- Monitor dark web, closed forums, and threat intelligence platforms for client-relevant indicators and actor communications.
- Collaborate with DFIR and fusion centre teams to enrich incident response with real-time adversary context.
- Develop and maintain threat actor profiles, campaign timelines, and TTP matrices for internal and client use.
- Brief senior client stakeholders and translate complex threat intelligence into clear executive-level communication.
Requirements
- 3+ years of experience in cyber threat intelligence, ideally within a financial services, government, or MSSP environment.
- Strong understanding of MITRE ATT&CK, Diamond Model, and structured analytic techniques.
- Experience tracking financially motivated threat actors, including FIN groups, ransomware operators, and fraud networks.
- Proficiency with OSINT tooling, threat intelligence platforms (MISP, Recorded Future, or equivalent), and SIEM environments.
- Demonstrated ability to produce finished intelligence products — not just indicator lists.
- Eligibility for security clearance; prior cleared work is a strong advantage.
- Excellent analytical writing — your reports will be read at board level.
Nice to Have
- Experience with SWIFT CSP threat modelling or payment fraud typology analysis.
- Knowledge of cryptocurrency tracing and blockchain analytics.
- Familiarity with nation-state cyber espionage operations and geopolitical threat contexts.
- GCTI, CREST CTI, or equivalent certification.