Threat Intelligence Analyst
- Hiring from
- Portugal
- Work type
- Hybrid
- Posted
- Sep 29, 2026
Key Responsibilities
- Support Digital Risk Protection (DRPS) activities, including monitoring leaks, external attack surfaces, fraud threats and digital risks.
- Monitor, identify, and analyze emerging cyber threats, threat actors, campaigns, and attack techniques.
- Produce tactical, operational, and strategic threat intelligence reports.
- Conduct research on cybercriminal groups, ransomware operations, vulnerabilities, exploits, and threat trends.
- Contribute to threat intelligence briefings, customer reports, executive and operational-level reports.
- Analyze indicators of compromise (IOCs), tactics, techniques, and procedures (TTPs), and map findings to frameworks such as MITRE ATT&CK.
- Enrich threat intelligence platforms and knowledge bases.
- Collaborate with SOC, Incident Response, and other internal and external cybersecurity teams.
- Participate in the continuous improvement of intelligence processes, methodologies, and automation initiatives.
Required Qualifications
- Higher education degree or technical-professional qualification in Cybersecurity, Computer Engineering, Networks, or a related field.
- Minimum of 3 years of experience in related roles.
- Experience with Digital Risk Protection, brand monitoring and Fraud monitoring.
- Experience with OSINT and SOCMINT techniques, dark web monitoring and intelligence gathering.
- Knowledge on Cyber Threat Intelligence and Threat Exposure Management platforms such as Recorded Future, Sixgill, Flare, or similar.
- Experience with Threat Intelligence Platforms (TIPs) such as OpenCTI, MISP, ThreatQ, or similar.
- Understanding of cyber threat actors, malware, ransomware, phishing, and common attack vectors.
- Familiarity with threat intelligence frameworks and methodologies.
- Relevant certifications or training (e.g. CTIA, GCTI, CPTIA) will be considered an asset.
- Strong analytical, research, and report-writing skills and ability to communicate technical findings to both technical and non-technical audiences.
- Team-oriented mindset, organizational skills, sense of responsibility, and ability to work effectively in dynamic and collaborative environments.
- Basic knowledge of malware analysis and network traffic analysis and familiarity with SIEM solutions and other security monitoring tools.
- Basic scripting and programing skills will be appreciated (Python, PowerShell, Bash).
- Good written communication skills and ability to understand technical English;
- Native Portuguese speaker and professional proficiency in English (C1).
Location: Lisbon or Porto (hybrid working model)
About Thales
In a world that is increasingly fast moving, unpredictable – and full of opportunities, trust is essential for societies to flourish. Trust in our institutions. Trust in our systems. Trust in technology. Trust in each other.
And the people we all rely on to make the world go round, they rely on Thales. They come to us with big ambitions: to make life better, to keep us safer.
From the bottom of the oceans to the depths of space and cyberspace, we help our customers navigate uncertainty with confidence and new frontiers with optimism. Thinking smarter and acting faster - mastering ever greater complexity and every decisive moment along the way.
We collaborate to architect and deliver high technology solutions that are both imaginative and resilient, human-centered and sustainable. So that together we can harness the extraordinary power of technology to build a future we can all trust.