Every nation has data. Few can protect it. Fewer still can act on it.
Dream is the sovereign AI and national cyber-defense company for governments.
We help nations secure their most critical systems, connect fragmented information at a national scale, and turn their most sensitive data into decisions, all fully sovereign.
This is more than a job. It's a Dream job, where you'll work at a global scale alongside some of the best AI researchers, cyber operators, and government experts in the world.
We defend nations against the most advanced threats in the world with a national security suite that offers AI-native resilience against APTs with visibility, insights and mediation across Posture, CTI, and Detection & Response, all fully sovereign.
The Dream JobWe are on an expedition to find you, a CTI Analyst who is passionate about turning raw threat data into clear, evidence-backed intelligence and operational outcomes. You’ll play a major role in advancing our next-gen CTI platform across threat actor attribution, adversary infrastructure analysis, External Attack Surface Management (EASM), and STIX-based knowledge management - Working closely with the Engineering, MLOps, and Data teams to deliver high-signal intelligence that drives action.
The Dream-Maker Responsibilities- Execute the CTI research roadmap across threat actor attribution, adversary infrastructure analysis, EASM insights, and STIX-based knowledge management.
- Conduct in-depth infrastructure and campaign analysis, including domain/IP relationships, hosting patterns and certificates.
- Identify, validate, and track Indicators of Compromise (IOCs) and emerging threats using passive sources and approved active techniques.
- Normalize, enrich, deduplicate, and maintain intelligence in STIX 2.1, aligned with internal ontology and quality standards.
- Collaborate with the Engineering, MLOps, and Data teams to translate intelligence into actionable intelligence, alerts, and customer-facing outputs.
- Produce high-quality intelligence reports, threat briefs, watchlists, and early-warning assessments for internal teams and customers.
- Support investigations by providing contextual analysis, confidence scoring, and evidence-backed assessments.
- Ensure adherence to governance, ethics, sourcing, provenance, and data-quality standards across all intelligence outputs.
- 3–6+ years of experience in Cyber Threat Intelligence, SOC/IR intelligence support, EASM, or adversary infrastructure analysis.
- Strong understanding of DNS, IPs, ASNs, hosting/cloud providers, TLS/PKI, domain lifecycle, and phishing infrastructure.
- Hands-on experience with open-source and commercial CTI sources (OSINT, feeds, telemetry, reputation systems).
- Practical knowledge of STIX 2.1, MITRE ATT&CK, TAXII; experience with OpenCTI and/or MISP is a strong advantage.
- Ability to perform passive discovery and controlled active validation, with a focus on accuracy, evidence discipline, and noise reduction.
- Experience using Python for analysis and enrichment (pandas, notebooks); familiarity with Neo4j or Elasticsearch is a plus.
- Strong analytical and threat-intelligence writing skills, able to translate technical findings into clear, actionable insights.
- Comfortable working in a collaborative, version-controlled environment (Git), with attention to documentation and reproducibility.
- Curious, methodical, and impact-driven mindset with a strong sense of intelligence rigor and accountability.
If you think this role doesn’t fully match your skills but are eager to grow and break glass ceilings, we’d love to hear from you!
Skills Required
- 3-6+ years experience in Cyber Threat Intelligence, SOC/IR intelligence support, EASM, or adversary infrastructure analysis.
- Strong understanding of DNS, IPs, ASNs, hosting/cloud providers, TLS/PKI, domain lifecycle, and phishing infrastructure.
- Hands-on experience with open-source and commercial CTI sources (OSINT, feeds, telemetry, reputation systems).
- Practical knowledge of STIX 2.1, MITRE ATT&CK, and TAXII.
- Experience with OpenCTI and/or MISP.
- Ability to perform passive discovery and controlled active validation with evidence discipline.
- Experience using Python for analysis and enrichment (pandas, notebooks).
- Familiarity with Neo4j or Elasticsearch for enrichment/analysis.
- Strong analytical and threat-intelligence writing skills; produce reports, briefs, and assessments.
- Comfortable working in a version-controlled environment (Git) with attention to documentation and reproducibility.
- Adherence to governance, ethics, sourcing, provenance, and data-quality standards.
Dream (dreamgroup.com) Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Dream (dreamgroup.com) and has not been reviewed or approved by Dream (dreamgroup.com).
-
Equity Value & Accessibility — Funding and growth stage in a competitive AI/cyber market are framed as enabling competitive cash-and-equity offers, though the company has not disclosed specifics. Candidates are advised to confirm equity structure and eligibility directly given the lack of public detail.
Dream (dreamgroup.com) Insights
What We Do
Dream is a pioneering AI cybersecurity company delivering revolutionary defense through artificial intelligence. Our proprietary AI platform creates a unified security system safeguarding assets against existing and emerging generative cyber threats. Dream's advanced AI automates discovery, calculates risks, performs real-time threat detection, and plans an automated response. With a core focus on the "unknowns," our AI transforms data into clear threat narratives and actionable defense strategies. Dream's AI cybersecurity platform represents a paradigm shift in cyber defense, employing a novel, multi-layered approach across all organizational networks in real-time. At the core of our solution is Dream's proprietary Cyber Language Model, a groundbreaking innovation that provides real-time, contextualized intelligence for comprehensive, actionable insights into any cyber-related query or threat scenario.









