Threat Intelligence Researcher- CTI

Posted 22 Days Ago
Be an Early Applicant
Tel Aviv, ISR
Hybrid
Mid level
Artificial Intelligence • Security • Cybersecurity
The Role
The Threat Intelligence Researcher will lead CTI research, design attribution models, build EASM detectors, and maintain STIX connectors, focusing on improving intelligence quality and governance standards.
Summary Generated by Built In
Description

Every nation has data. Few can protect it. Fewer still can act on it.

Dream is the sovereign AI and national cyber-defense company for governments.

We help nations secure their most critical systems, connect fragmented information at a national scale, and turn their most sensitive data into decisions, all fully sovereign.

This is more than a job. It's a Dream job, where you'll work at a global scale alongside some of the best AI researchers, cyber operators, and government experts in the world.

We defend nations against the most advanced threats in the world with a national security suite that offers AI-native resilience against APTs with visibility, insights and mediation across Posture, CTI, and Detection & Response, all fully sovereign.

The Dream Job

We are on an expedition to find you, someone who is passionate about turning research into reliable, production-grade capabilities. You’ll play a major role in building and shaping our next-gen CTI platform across attribution, pivoting, infrastructure prediction, EASM, and the STIX/OpenCTI knowledge base.

The Dream-Maker Responsibilities
  • Execute the CTI research roadmap across attribution, infra prediction, EASM, and the STIX knowledge base. 
  • Design and implement graph-pivoting, attribution heuristics, and temporal/link models (sequence/survival/Hawkes-style). 
  • Build high-signal EASM detectors: passive discovery and safe active probing per ROE; capture reproducible evidence. 
  • Normalize, enrich, and deduplicate intel into STIX 2.1 aligned to our ontology; maintain/enhance TAXII/OpenCTI/MISP connectors. 
  • Ship detectors/models and enrichment services with AI/Platform teams; contribute tests, docs, and runbooks. 
  • Curate datasets, define ground truth, and evaluate KPIs (coverage, lead-time, precision/recall, FPR); iterate to improve signal-to-noise. 
  • Produce watchlists, concise briefs, and early-warning hypotheses for stakeholders and priority investigations. 
  • Uphold governance, ethics, provenance, and data-quality standards. 
The Dream Skill Set
  • 4-7+ years in CTI/EASM/offensive research or adversary-infra analysis. 
  • DNS, BGP/ASNs, TLS/PKI & CT logs, hosting/CDN/cloud patterns, domain lifecycle, phishing ecosystems. 
  • Communities/embeddings/clustering; temporal/link modeling and practical evaluation. 
  • Passive discovery and safe active probing; evidence discipline and noise reduction. 
  • STIX 2.1, ATT&CK, TAXII; advantage for OpenCTI/MISP; ontology alignment and validation. 
  • Python (pandas, notebooks, scikit-learn, networkx/igraph); Neo4j/Elasticsearch; Kafka/SQS/Redis; Docker/Kubernetes. 
  • Prompting/tool-use for extraction/normalization; agentic patterns with guardrails and sanity checks. 
  • Analytical writing; collaborative, version-controlled workflow (Git); documentation rigor. 
Never Stop Dreaming...

If you think this role doesn’t fully match your skills but are eager to grow and break glass ceilings, we’d love to hear from you!  

Skills Required

  • 4-7+ years in CTI/EASM/offensive research or adversary-infra analysis
  • Experience in DNS, BGP/ASNs, TLS/PKI & CT logs
  • Knowledge of STIX 2.1, ATT&CK, TAXII; advantage for OpenCTI/MISP
  • Proficient in Python (pandas, notebooks, scikit-learn)
  • Familiarity with Docker and Kubernetes
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
328 Employees

What We Do

Dream is a pioneering AI cybersecurity company delivering revolutionary defense through artificial intelligence. Our proprietary AI platform creates a unified security system safeguarding assets against existing and emerging generative cyber threats. Dream's advanced AI automates discovery, calculates risks, performs real-time threat detection, and plans an automated response. With a core focus on the "unknowns," our AI transforms data into clear threat narratives and actionable defense strategies. Dream's AI cybersecurity platform represents a paradigm shift in cyber defense, employing a novel, multi-layered approach across all organizational networks in real-time. At the core of our solution is Dream's proprietary Cyber Language Model, a groundbreaking innovation that provides real-time, contextualized intelligence for comprehensive, actionable insights into any cyber-related query or threat scenario.

Similar Jobs

CrowdStrike Logo CrowdStrike

Senior Software Engineer

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Hybrid
Tel Aviv, ISR
10000 Employees

Riskified Logo Riskified

Product Manager

Big Data • eCommerce • Fintech • Machine Learning • Payments • Software
Hybrid
Tel Aviv, ISR
680 Employees

Riskified Logo Riskified

Product Strategy Director

Big Data • eCommerce • Fintech • Machine Learning • Payments • Software
Hybrid
Tel Aviv, ISR
680 Employees

monday.com Logo monday.com

Head of GTM Service

Artificial Intelligence • Productivity • Sales • Software
Hybrid
Tel Aviv, ISR
3049 Employees

Similar Companies Hiring

Idler Thumbnail
Artificial Intelligence
San Francisco, California
6 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account