As a Snr. Data Analyst at KnowBe4's Threat Labs, you'll conduct hands-on analysis of real-world email-based cyber threats by investigating suspicious emails to identify phishing, malware, and social engineering attacks, extracting indicators of compromise (IOCs) like URLs, domains, and file hashes, tracking ongoing threat campaigns using OSINT tools and mapping them to MITRE ATT&CK frameworks, and contributing technical research blogs and intelligence documentation that helps protect users globally—all while working alongside experienced security researchers in a collaborative environment using industry-standard tools like VirusTotal, URLscan.io, and Python scripting to turn raw threat data into actionable cybersecurity intelligence
Responsibilities:
- Manual Threat Analysis: Investigate and classify suspicious emails to identify phishing, malware, spam, and benign attempts from real-world attack scenarios using our internal tooling.
- IOC Extraction: Extract and document Indicators of Compromise—URLs, domains, file hashes, sender information—from email headers, body content, and attachments.
- Campaign Tracking: Research and monitor ongoing email-based threat campaigns, mapping attacker tactics, techniques, and procedures (TTPs) to MITRE ATT&CK.
- Intelligence Contribution: Build and maintain internal threat intelligence datasets, detection patterns, and research documentation.
- Collaboration: Partner with senior researchers and participate in threat reviews to share observations and enhance detection quality.
- Growth: Keep learning! Share discoveries, explore new analysis techniques, and raise the bar for the team.
Requirements:
- Educational Background: A university degree is not required. We actively encourage applications from individuals with vocational IT training, technical diplomas, relevant certifications (e.g., CompTIA IT Fundamentals), or those returning to the workforce who possess strong digital literacy.
- 3 years experience in the field
- An understanding of common cybersecurity threats (e.g., domain spoofing, spear-phishing)
- Exceptional attention to detail and the stamina to maintain focus during highly repetitive analytical tasks
- Experience handling large datasets
Apply on company website São Paulo, Brazil On-site Full-time