Information Technology

Cyber Threat Intelligence (CTI) analyst

What we offer

Our company culture is focused on helping our employees enable innovation by building breakthroughs together. How? We focus every day on building the foundation for tomorrow and creating a workplace that embraces differences, values flexibility, and is aligned to our purpose-driven and future-focused work. We offer a highly collaborative, caring team environment with a strong focus on learning and development, recognition for your individual contributions, and a variety of benefit options for you to choose from. Apply now!



Company description:

SAP started in 1972 as a team of five colleagues with a desire to do something new. Together, they changed enterprise software and reinvented how business was done. Today, as a market leader in enterprise application software, we remain true to our roots. That’s why we engineer solutions to fuel innovation, foster equality and spread opportunity for our employees and customers across borders and cultures.


SAP values the entrepreneurial spirit, fostering creativity and building lasting relationships with our employees. We know that a diverse and inclusive workforce keeps us competitive and provides opportunities for all. We believe that together we can transform industries, grow economics, lift up societies and sustain our environment. Because it’s the best-run businesses that make the world run better and improve people’s lives.


We are looking for a Cyber Threat Intelligence (CTI) analyst to join the SAP Cyber Defense & Design (CDD) organization to help defend our networks from sophisticated threats. Our Cyber Threat Intelligence analysts are responsible for identifying threats to the organization by collecting and analyzing internal and external data sets and operationalizing this data to inform our defensive posture.  Analysts must also be able to communicate effectively to organizational stakeholders to provide situational awareness and enable decision-making. This position also produces actionable intelligence reporting on cyber adversary TTPs to drive asymmetric threat hunting operations to detect malicious activity within SAP networks.


The Role:

In this role, you will be a member of SAP’s Cyber Threat Intelligence team and work closely with your Cyber Fusion Center peers located around the globe.  You will represent CTI interests as you collaborate daily with organizational peers in incident response, enterprise vulnerability management, Defensive Architecture, mergers and acquisition (M&A) teams, and various other Cyber Defense & Design related teams providing intelligence support and input.  This role will also be responsible for developing and maintaining a deep dark web intelligence and underground forum collection framework to identify threats to SAP emanating from that space.  Additionally, this role will leverage dark web accesses and collection to support strategic SAP business growth via the mergers and acquisitions (M&A) due diligence process.   This role will also work closely with SAP business units, both new and existing, to onboard their line-of-business(es) for our CTI/Hunt central services as a customer success advocate.  A strong candidate will be able to work independently and with peer security groups having an understanding of their functions as well as thrive in a dynamic work environment with rapidly changing priorities. This role is an exciting opportunity to join a new team that is defending a world-class multinational corporation against some of todays most advanced and persistent cyber threats.  


Role Requirements:

We are looking for an experienced and motivated Cyber Threat Intelligence analyst who has at least 3 years of experience working as one or a combination of the following: security analyst, cyber threat intelligence analyst, or cyber threat target analyst. The ideal candidate can work well as an individual as well as in a team construct. This individual should also be a self-starter who has experience taking initiative and translating loosely defined requirements into actionable, timely, and relevant intelligence.  This position is fully remote and provides opportunities for domestic and international travel.


You should also have the following technical skills and experience:



 (Deep Dark Web)


  • A Bachelor’s degree from an accredited institution in one of the following areas: Cybersecurity, Computer Science, Liberal Arts.
    • Candidates without college degrees will also be considered provided they have an equivalent amount of demonstrated work experience
  • Very strong report writing skills able to effectively communicate essential elements of information to a broad range of stakeholders.  Graphics/PPT skills are a plus to create or communicate to C-levels and other business information officers.
  • Demonstrable experience conducting deep dark web underground forum research and collection including the use of TOR and other anonymizers
  • Ability to create and maintain novel processes based on new intelligence collection requirements
  • Knowledge of cyber threat intelligence analytic frameworks including Diamond Model, Cyber Kill Chain, MITRE ATT&CK
  • Ability to enrich and pivot on technical indicators of compromise to enumerate additional indicators using publicly available tools (Virus Total Intel, RiskIQ, etc)
  • Understand the intent of priority intelligence requirements (PIRs) in relation to collection & reporting priorities
  • Security Certifications (e.g. Security+, GCIA, GCIH, GCFA, GCNA, CEH, CISSP, etc.)
  • Knowledge of Advanced Persistent Threat (APT) actors and associated tools, techniques, and procedures (TTPs)
  • Strong interpersonal skills with the ability to communicate technical issues to non-technical staff


Highly Desired Skills


  • Familiarity with Splunk or other SIEM platforms
  • Experience integrating automation/SOAR workflows into threat intelligence processes
  • Experience working in a SOC or CFC environment
  • Experience onboarding business units to threat intelligence services
  • Experience conducting dark web analysis and collection in support of CTI and wider business interests





We are SAP

SAP innovations help more than 400,000 customers worldwide work together more efficiently and use business insight more effectively. Originally known for leadership in enterprise resource planning (ERP) software, SAP has evolved to become a market leader in end-to-end business application software and related services for database, analytics, intelligent technologies, and experience management. As a cloud company with 200 million users and more than 100,000 employees worldwide, we are purpose-driven and future-focused, with a highly collaborative team ethic and commitment to personal development. Whether connecting global industries, people, or platforms, we help ensure every challenge gets the solution it deserves. At SAP, we build breakthroughs, together.


Our inclusion promise

SAP’s culture of inclusion, focus on health and well-being, and flexible working models help ensure that everyone – regardless of background – feels included and can run at their best. At SAP, we believe we are made stronger by the unique capabilities and qualities that each person brings to our company, and we invest in our employees to inspire confidence and help everyone realize their full potential. We ultimately believe in unleashing all talent and creating a better and more equitable world.


SAP is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to the values of Equal Employment Opportunity and provide accessibility accommodations to applicants with physical and/or mental disabilities. If you are interested in applying for employment with SAP and are in need of accommodation or special assistance to navigate our website or to complete your application, please send an e-mail with your request to Recruiting Operations Team: Americas: or, APJ:, EMEA:


EOE AA M/F/Vet/Disability:

Qualified applicants will receive consideration for employment without regard to their age, race, religion, national origin, ethnicity, age, gender (including pregnancy, childbirth, et al), sexual orientation, gender identity or expression, protected veteran status, or disability.

Requisition ID:326941 | Work Area: Information Technology | Expected Travel: 0 - 10% | Career Status: Professional | Employment Type: Regular Full Time  | Additional Locations: Virtual - USA

Requisition ID:  326941
Posted Date:  Jul 2, 2022
Work Area:  Information Technology
Career Status:  Professional
Employment Type:  Regular Full Time
Expected Travel:  0 - 10%

Bellevue, WA, US, 98004

Job alert

Nearest Major Market: Seattle
Nearest Secondary Market: Bellevue

Job Segment: ERP, M&A, Computer Science, Cloud, SAP, Technology, Management