Thales logo

Threat Intelligence Analyst

Hiring from
Portugal
Work type
Hybrid
Posted
Sep 29, 2026
Is this job info correct?
Location: Leca do Balio, Portugal

Key Responsibilities

  • Support Digital Risk Protection (DRPS) activities, including monitoring leaks, external attack surfaces, fraud threats and digital risks.
  • Monitor, identify, and analyze emerging cyber threats, threat actors, campaigns, and attack techniques.
  • Produce tactical, operational, and strategic threat intelligence reports.
  • Conduct research on cybercriminal groups, ransomware operations, vulnerabilities, exploits, and threat trends.
  • Contribute to threat intelligence briefings, customer reports, executive and operational-level reports.
  • Analyze indicators of compromise (IOCs), tactics, techniques, and procedures (TTPs), and map findings to frameworks such as MITRE ATT&CK.
  • Enrich threat intelligence platforms and knowledge bases.
  • Collaborate with SOC, Incident Response, and other internal and external cybersecurity teams.
  • Participate in the continuous improvement of intelligence processes, methodologies, and automation initiatives.

Required Qualifications

  • Higher education degree or technical-professional qualification in Cybersecurity, Computer Engineering, Networks, or a related field.
  • Minimum of 3 years of experience in related roles.
  • Experience with Digital Risk Protection, brand monitoring and Fraud monitoring.
  • Experience with OSINT and SOCMINT techniques, dark web monitoring and intelligence gathering.
  • Knowledge on Cyber Threat Intelligence and Threat Exposure Management platforms such as Recorded Future, Sixgill, Flare, or similar.
  • Experience with Threat Intelligence Platforms (TIPs) such as OpenCTI, MISP, ThreatQ, or similar.
  • Understanding of cyber threat actors, malware, ransomware, phishing, and common attack vectors.
  • Familiarity with threat intelligence frameworks and methodologies.
  • Relevant certifications or training (e.g. CTIA, GCTI, CPTIA) will be considered an asset.
  • Strong analytical, research, and report-writing skills and ability to communicate technical findings to both technical and non-technical audiences.
  • Team-oriented mindset, organizational skills, sense of responsibility, and ability to work effectively in dynamic and collaborative environments.
  • Basic knowledge of malware analysis and network traffic analysis and familiarity with SIEM solutions and other security monitoring tools.
  • Basic scripting and programing skills will be appreciated (Python, PowerShell, Bash).
  • Good written communication skills and ability to understand technical English;
  • Native Portuguese speaker and professional proficiency in English (C1).

Location: Lisbon or Porto (hybrid working model)


Interested in finding out more about Thales and why you should join us?
Say HI* to new career opportunities.

Similar jobs

Apply for this job