THE CHALLENGE
We are looking for a Threat Intelligence Engineer. In this role, you will be on the front lines of our defense, helping to operationalize intelligence and build engineering solutions to counter emerging security threats. You'll work closely with various security and technology teams to integrate threat data into our security infrastructure, strengthening our defenses and protecting our organization. Your hands-on expertise will directly contribute to safeguarding Take-Two and its labels' systems, networks, and data. You will work with Take-Two's Information Security teams, reporting to the Director of Threat Intelligence.
WHAT YOU'LL TAKE ON
- Threat Intelligence Operations: Support the day-to-day operations of the cyber threat intelligence (CTI) program by managing threat feeds, parsing indicators of compromise (IOCs), and ensuring data quality across our platforms.
- Threat Analysis & Engineering: Analyze emerging threats and adversary tactics, techniques, and procedures (TTPs) to help engineer robust detection and prevention mechanisms.
- Enhance Our Security Posture: Collaborate with our Global Security Operations Center (GSOC), Detection Engineering, and Incident Response teams to ingest and operationalize threat intelligence into our SIEM, EDR, and firewalls.
- Automation & Integration: Build and maintain API integrations, scripts, and playbooks to automate indicator ingestion, correlation, and dissemination across security platforms.
- Security Infrastructure Support: Assist in the deployment, configuration, maintenance, and tuning of our Threat Intelligence Platforms (TIP) and related security engineering tools.
- Produce Actionable Reporting: Assist in generating timely intelligence alerts, briefs, and tactical reports for technical teams to provide context around active threats.
WHAT YOU BRING
- Experience: 2-4 years of experience in cybersecurity, with at least 1-2 years focused on threat intelligence, security engineering, or security operations (SOC).
- Technical Expertise: A solid understanding of network fundamentals, operating system internals, common attack vectors, and the general cyber threat landscape.
- Engineering Mindset: Experience working with APIs, data formats (JSON, XML, STIX/TAXII), and systems integration to streamline security workflows.
- Analytical Skills: The ability to analyze data from various sources (e.g., open-source intelligence, technical reports, internal logs) to draw technical conclusions and identify malicious activity.
- Intelligence Framework Knowledge: Familiarity with common threat intelligence and security frameworks like MITRE ATT&CK and the Cyber Kill Chain.
- Communication Skills: Strong written and verbal communication skills, with the ability to document engineering processes and communicate threat findings clearly.