hirly

Thales

Threat Intelligence Analyst

Leca do Balio

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Thales first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

hirly's read of this role

Seniority
Mid level
Country
PT
Work mode
On-site / unstated
First seen by hirly
29 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

Location: Leca do Balio, Portugal

Key Responsibilities

  • Support Digital Risk Protection (DRPS) activities, including monitoring leaks, external attack surfaces, fraud threats and digital risks.
  • Monitor, identify, and analyze emerging cyber threats, threat actors, campaigns, and attack techniques.
  • Produce tactical, operational, and strategic threat intelligence reports.
  • Conduct research on cybercriminal groups, ransomware operations, vulnerabilities, exploits, and threat trends.
  • Contribute to threat intelligence briefings, customer reports, executive and operational-level reports.
  • Analyze indicators of compromise (IOCs), tactics, techniques, and procedures (TTPs), and map findings to frameworks such as MITRE ATT&CK.
  • Enrich threat intelligence platforms and knowledge bases.
  • Collaborate with SOC, Incident Response, and other internal and external cybersecurity teams.
  • Participate in the continuous improvement of intelligence processes, methodologies, and automation initiatives.

Required Qualifications

  • Higher education degree or technical-professional qualification in Cybersecurity, Computer Engineering, Networks, or a related field.
  • Minimum of 3 years of experience in related roles.
  • Experience with Digital Risk Protection, brand monitoring and Fraud monitoring.
  • Experience with OSINT and SOCMINT techniques, dark web monitoring and intelligence gathering.
  • Knowledge on Cyber Threat Intelligence and Threat Exposure Management platforms such as Recorded Future, Sixgill, Flare, or similar.
  • Experience with Threat Intelligence Platforms (TIPs) such as OpenCTI, MISP, ThreatQ, or similar.
  • Understanding of cyber threat actors, malware, ransomware, phishing, and common attack vectors.
  • Familiarity with threat intelligence frameworks and methodologies.
  • Relevant certifications or training (e.g. CTIA, GCTI, CPTIA) will be considered an asset.
  • Strong analytical, research, and report-writing skills and ability to communicate technical findings to both technical and non-technical audiences.
  • Team-oriented mindset, organizational skills, sense of responsibility, and ability to work effectively in dynamic and collaborative environments.
  • Basic knowledge of malware analysis and network traffic analysis and familiarity with SIEM solutions and other security monitoring tools.
  • Basic scripting and programing skills will be appreciated (Python, PowerShell, Bash).
  • Good written communication skills and ability to understand technical English;
  • Native Portuguese speaker and professional proficiency in English (C1).

Location: Lisbon or Porto (hybrid working model)

Original posting on Thales's site ↗

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job