Halcyon Logo

Halcyon

Ransomware Intelligence Analyst

Posted 17 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in USA
150K-180K
Senior level
Remote
Hiring Remotely in USA
150K-180K
Senior level
The Ransomware Intelligence Analyst will conduct research and intelligence analysis on ransomware threats, track actors, and collaborate to disrupt operations.
The summary above was generated by AI

What we do:
Halcyon is the industry’s first dedicated, adaptive security platform that combines multiple proprietary advanced prevention engines along with AI models focused specifically on stopping ransomware.

Who we are:
Halcyon was formed in 2021 by a team of cyber industry veterans after battling the scourge of ransomware (and advanced threats) for years at some of the largest global security vendors. Comprised of leaders from Cylance (now Blackberry), Accuvant (now Optiv), Fireye and ISS X-Force (now IBM), Halcyon is focused on building products and solutions for mid-market and enterprise customers.

As a remote-native, completely distributed global team, we recognize great talent can exist anywhere. We invite you to apply to a job you’re interested in and we'll work a plan to meet your needs.

The Role:

Our newly created Ransomware Research Center is looking for a curious and driven Ransomware Intelligence Analyst to conduct ransomware-focused intelligence and research efforts. In this role, you will track threat actors, understand their tradecraft, map affiliate operations, and analyze cryptocurrency transactions to produce intelligence that protects organizations from extortion, data theft, and operational disruption. This isn’t a role where you’ll be handed a playbook and told to color inside the lines. You’ll have the autonomy and trust to shape this position and deliverables for success. The role is ideal for an experienced intelligence or threat analyst who is ready to take ownership, bring bold ideas to the table, and see them through to real-world impact. 

Responsibilities:

  • Conduct proactive research on open-source, underground, technical data, and proprietary intelligence sources to track ransomware operations, leaks, and affiliate activity.
  • Drive strategic and operational intelligence analysis of ransomware groups, including actor motivations, affiliate networks, victim targeting, and revenue models.
  • Hunt for threat actor infrastructure, map evolving TTPs for high-impact ransomware families, and track shifts in tooling, access brokers, and extortion techniques.
  • Produce high-impact finished intelligence and deliver briefings for a wide variety of audiences, including executives, information security personnel, customers, media, and the general public.
  • Collaborate across security operations, incident response, and engineering teams to ensure effective integration of data and research into the Halcyon Anti-Ransomware Platform. 
  • Maintain working relationships with external partners, law enforcement, and intelligence-sharing alliances to support broader counter-ransomware efforts.
  • Identify opportunities to degrade or disrupt ransomware operations through exposure, disruption, or legal/policy collaboration.

Skills and Qualifications:

  • 5+ years of experience in cyber threat intelligence, cryptocurrency tracing, digital forensics, or a related role.
  • Bachelor’s degree in Computer Science, Cybersecurity, or Digital Forensics; or Intelligence Analysis, Data Analysis, Applied Math or Statistics, or related degrees with appropriate additional cyber coursework.
  • Deep familiarity with ransomware-as-a-service (RaaS) models, affiliate structures, and the evolution of extortion and data leak tactics.
  • Strong understanding of malware analysis workflows, underground forums, and ransomware payment infrastructure (e.g., crypto tracing, leak site activity). 
  • Proficiency with a scripting language (Python preferred) for data collection, transformation, and analysis.
  • Fluency with common open source intelligence (OSINT), cyber threat intelligence, and/or blockchain research tools. Understanding of enrichment sources (e.g., VirusTotal, Shodan, AbuseIPDB, etc.).
  • Proven ability to integrate intelligence (e.g., structure analytic techniques, Diamond Model) and tracking methodologies (e.g., Mitre ATT&CK, Cyber Kill Chain) to assess cyber threat activity. 
  • Strong research and writing skills with a track record of producing high-impact ransomware intelligence reports that connect patterns across technical and non-technical data and context.
  • Exceptional communication skills — both written and verbal — with the ability to brief leadership and influence decision-making.
  • Ability to research independently and then use that independent work to collaborate effectively with team members and external partners. 
  • Experience supporting or briefing law enforcement, government, or sector-wide ransomware initiatives.

Bonus Skills and Qualifications:

  • Familiarity with a Databricks environment, including notebooks, Delta tables, and job scheduling.
  • SQL proficiency for querying structured data with Databricks and other databases.
  • Experience with Pandas, NumPy, and other Python data analysis libraries.  
  • Comfort with Jupyter notebooks and data visualization libraries (Matplotlib, Seaborn, Plotly)
  • Proficiency in a high-priority foreign language like Russian, Mandarin Chinese, Portuguese, or Farsi.
Benefits:

 Halcyon offers the following benefits to eligible employees:

  • Comprehensive healthcare (medical, dental, and vision) with premiums paid in full for employees and dependents.

  • 401k plan with a generous employer contribution.

  • Short and long-term disability coverage, basic life and AD&D insurance plans.

  • Medical and dependent care FSA options.

  • Flexible PTO policy.

  • Parental leave.

  • Generous equity offering.

The Company reserves the right to modify or change these benefits programs at any time, with or without notice.​

Base Salary Range: $150,000 - $180,000

Bonus Target: 10%

In accordance with applicable state and federal laws, the range provided is Halcyon’s reasonable estimate of the base compensation for this role. The actual amount may differ based on non-discriminatory factors such as experience, knowledge, skills, abilities, and location. Base pay is one part of the total package that is provided to compensate and recognize employees for their work, and this role may be eligible for additional discretionary bonuses/incentives, and equity in the Company.

We understand it takes a diverse team of highly intelligent, passionate, curious, and creative people to develop the exceptional product we are building. Our dynamic team has incredible perspectives to share, just as we know you do, and we take great pride in being an equal opportunity employer.

Top Skills

Abuseipdb
Databricks
Matplotlib
Numpy
Pandas
Plotly
Python
Seaborn
Shodan
SQL
Virustotal

Similar Jobs

56 Minutes Ago
In-Office or Remote
Chicago, IL, USA
91K-111K Annually
Mid level
91K-111K Annually
Mid level
Fintech
The Software Engineer II will develop scalable applications and collaborate with teams, designing services, ensuring quality code, and driving innovation in a remote work environment.
Top Skills: .Net 6AzureC# 10DockerGitKubernetesMongoDBMs Sql ServerReact 16ReduxTypescript
57 Minutes Ago
In-Office or Remote
Chicago, IL, USA
91K-111K Annually
Senior level
91K-111K Annually
Senior level
Fintech
The Senior Quality Engineer drives performance testing and optimization, ensuring high-quality software delivery through automation, benchmarking, and collaboration with cross-functional teams.
Top Skills: .NetArtilleryAzure CloudAzure DevopsDatadogDockerJmeterJunitK6KubernetesLoadrunnerMongoDBMs Sql ServerMulesoftPlaywrightPythonRabbitMQReactSeleniumTerraformTestng
57 Minutes Ago
In-Office or Remote
Chicago, IL, USA
107K-137K Annually
Senior level
107K-137K Annually
Senior level
Fintech
This role focuses on optimizing developer experience by implementing tools, enhancing workflows, and ensuring seamless software development through automation and collaboration.
Top Skills: .NetAbacusAnsibleAzure CloudAzure DevopsDatadogDockerFresh ServiceKubernetesMongoDBMs CopilotMs Sql ServerMulesoftPythonRabbitMQReactSalesforceTerraform

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account