Threat Intelligence Analyst

Hybrid
CompanyALICE
LocationLondon, UK
Category-
DepartmentIntelligence
Seniority-
WorkplaceHybrid
Posted2026-09-16
Viacomeet

Description

Alice is seeking to hire a Threat Intelligence Analyst to join our growing underground monitoring team. At Alice we conduct threat intelligence research and analysis, produce analytical reports and proactively monitor ongoing and emerging incidents.

As a Threat Intelligence Analyst at Alice you will be in charge of:

  • Research and analysis of multiple threat intelligence sources on the deep and dark web to assess threats and TTP’s of threat actors across different fraudulent ecosystems.
  • Produce technical reports for clients describing threat actor TTPs, analysis and exploits relevant for Alice’s clients.
  • Work closely with Team Leads and stakeholders, as well as other analysts to produce intelligence reports, and feedback according to client needs.
  • Review, enrich and provide analyst tradecraft for other team members as part of the delivery process.
  • Prepare assessments of current threats and trends based on collection, research and analysis of classified intelligence collected by the team.
  • Develop and maintain analytical procedures to meet changing requirements and ensure maximum operational success, while following high security measures.
  • Ability to work both individually and as a part of a team

Must Have

  • At least 5 years of experience in intelligence hunting in cyber or threat investigation industries
  • WebInt / OSINT experience
  • BA degree or equivalent
  • Strong English communication skills: strong ability to explain the threats both verbally and in writing
  • Must have demonstrated experience in gathering and evaluating internet information from social media, chats and darknet forums
  • High communication skills

Nice to Have

  • Foreign language skills
  • Technical threat hunting experience, DIFR or other advanced cybersecurity operations
  • Experience with research and intelligence collection platforms such as: URLScan, VirusTotal, Intel471, Recorded Future, Flashpoint, or equivalent