Oh oh! Awesome! Info! {$ msg.text $} ({$ msg.count $})

Threat Intelligence Reseacher

  • Application Deadline: Oct. 8, 2026
  • Helsinki
  • Yearly salary: starting from €61,000
  • Application Deadline: Oct. 8, 2026
  • Helsinki
  • Yearly salary: starting from €61,000

At WithSecure™, we protect businesses all over the world. Our SaaS solutions safeguard against modern cyber threats, and our innovative Co-security approach reflects our belief that true protection requires collaboration and shared expertise. No one can solve every cyber security problem alone. Our vision is to become Europe’s flagship in cyber security. Every day, our talented teams work to prevent cyber extortion, secure critical infrastructure, and prevent misuse of sensitive data. At WithSecure, it’s our people who make us exceptional – a diverse community that values passion, purpose, and a commitment to workplace well-being. If you’re ready to make an impact with a company that’s transforming cybersecurity, we’d love to hear from you.

What are we looking for?

We are looking for a Threat Intelligence Reseacher to join our Threat intelligence and response team and help improve our clients’ security posture and cyber resilience.


This is a hands-on specialist role focused on threat research, intelligence production, and translating complex threat activity into practical guidance. You will investigate threat actors, campaigns, intrusion techniques, malware, and significant cyber events, turning your findings into intelligence that customers and our internal teams can act on.


You will work directly with customers, presenting threat assessments and helping them understand how changes in the threat landscape relate to their industry, technology, and exposure. You will also develop and deliver internal training, strengthen our threat-intelligence capabilities, and share your expertise across the organization.


This is primarily a content and subject-matter-expert role. Customer communication is an important part of delivering that expertise, while account ownership and commercial relationship management remain with the relevant Customer Success and commercial teams.


What You’ll Do


Research threat actors, campaigns, malware, adversary infrastructure, vulnerabilities, intrusion techniques, and significant cyber events.

Produce sector threat landscapes, campaign assessments, threat-actor profiles, flash advisories, executive briefings, and technical intelligence reports.

Combine intelligence from open sources, incident-response investigations, MDR observations, security telemetry, and other relevant sources.

Assess which threats are genuinely relevant to customers based on their industry, geography, technology, and known exposure.

Translate technical findings into clear and actionable recommendations for security teams, CISOs, business leaders, and executive audiences.

Map adversary activity to MITRE ATT&CK techniques, attack paths, indicators of compromise, and detection opportunities.

Support threat-led detection engineering by identifying emerging techniques, telemetry requirements, detection gaps, and opportunities for proactive threat hunting.

Work closely with Incident Response, MDR, Exposure Management, Detection Engineering, and Consulting specialists.

Deliver customer briefings, workshops, and threat-intelligence sessions.

Design and deliver internal training for consultants, analysts, Customer Success teams, and other relevant stakeholders.

Maintain reusable intelligence content, research methodologies, and recommendation libraries.

Peer-review intelligence products and help maintain a consistently high analytical standard.

Contribute to blog posts, research publications, webinars, and other thought-leadership activities.


How the Role Can Develop


We want this role to provide a genuine path towards deeper and more visible threat research.

As you demonstrate strong analytical quality, initiative, and customer impact, you can take increasing ownership of:


Conducting original research into threat actors, campaigns, malware, and emerging attacker techniques.

Analyzing our exposure management service

Longer-term threat-research projects based on observations from our customer environments, MDR operations, and incident-response engagements.

Authoring detailed threat-intelligence reports and public research publications.

Developing new research methods and shaping the direction of our threat-intelligence capability.

Representing WithSecure through webinars, industry events, media briefings, and cyber security conferences.

Mentoring other analysts and helping develop the next generation of threat-intelligence specialists.

Conference presentations and public research would not be separate from the role—they would be a natural extension of high-quality work produced within it.


What We’re Expecting From You


At least three years of relevant professional experience in threat intelligence, threat research, incident response, malware analysis, threat hunting, detection engineering, SOC, or MDR environments.

Demonstrated experience investigating threat actors, campaigns, intrusion activity, or significant cyber events.

The ability to produce well-supported intelligence assessments rather than simply aggregate or summarize threat news.

A solid understanding of attacker tradecraft, intrusion lifecycles, common malware capabilities, command-and-control infrastructure, and adversary techniques.

Experience evaluating source reliability, distinguishing established facts from analytical judgments, and communicating confidence levels and intelligence gaps.

The ability to connect threat intelligence with customer-specific risk, exposure, and defensive priorities.

Strong analytical writing skills and the ability to produce clear, concise, and defensible reports.

Confidence presenting complex technical subjects to technical specialists, business leaders, and executive audiences.

The interpersonal skills to work directly with customers as a trusted subject-matter expert.

The ability and motivation to create training material, facilitate internal sessions, and mentor colleagues.

Intellectual curiosity and the persistence required to investigate incomplete or conflicting information.

Proficiency in English.

The ability to work independently while actively collaborating and sharing knowledge with others.

Being an awesome colleague!


Bonus Points For


Experience working with EDR, SIEM, MDR, threat-intelligence platforms, or large-scale security telemetry.

Practical experience in incident investigation, threat hunting, or detection development.

Experience with malware analysis, adversary infrastructure tracking, or advanced open-source intelligence techniques.

Familiarity with analytical frameworks such as MITRE ATT&CK, the Diamond Model, the Cyber Kill Chain, or structured analytical techniques.

Knowledge of cloud, identity, SaaS, and hybrid-environment threats.

Experience producing intelligence for industries such as finance, manufacturing, healthcare, energy, or the public sector.

Scripting or query-language skills that support research and analysis.

Previous experience publishing security research, writing technical reports, speaking at events, or contributing to the cyber security community.

Relevant certifications such as GCTI, GCFA, GREM, CISSP, or equivalent practical expertise.

Understanding of how threat intelligence supports NIS2, DORA, executive decision-making, and broader cyber-risk management.


Why You’ll Love Us


Meaningful research: You will investigate real threat activity and turn your findings into intelligence that directly improves customer security.

A path into original threat research: Strong performance can lead to ownership of research projects, authored reports, public publications, and conference presentations.

Frontline insight: You will collaborate with specialists working in MDR, Incident Response, Exposure Management, Detection Engineering, and other security disciplines.

Dedicated research time: You will have time to investigate topics that matter, develop original findings, and collaborate with experienced researchers.

Support for visibility: We will support you in writing research reports, publishing blog posts, developing presentations, and speaking at relevant industry events.

Continuous learning: We invest in relevant training, conferences, and certifications. You will also learn from colleagues through regular knowledge-sharing sessions.

Real customer impact: Your intelligence will help customers understand who may target them, how those attacks could happen, and what they should prioritize.

A top-notch team: You will work alongside experienced cyber security specialists who challenge one another, share their expertise, and continuously raise the bar.

If you enjoy uncovering the story behind cyber activity—and can turn that story into clear, defensible, and actionable intelligence—we would love to hear from you.


Ready to research the threats that matter and help customers prepare for them? Apply now and help us make the digital world safer.

Work with great people

Joni Vatjus-Anttila - Director, Customer Success Management
Joni Vatjus-Anttila
Director, Customer Success Management
"Being able to say that our job is to keep our customers safe is everything to me. It creates a sense of purpose."
Łukasz Kwieciński - Senior Manager, R&D
Łukasz Kwieciński
Senior Manager, R&D
"Working here has been a transformative experience — the sophisticated challenges drive rapid growth, while the friendly, supportive team makes even the toughest problems easier to tackle."

Great Place to Work

  • Over 900 amazing colleagues in 18 offices

  • Possibility to protect the world

  • Work with best of class experts who care

  • Relaxed, open and fun working environment

  • 70+ nationalities

  • Global with the spirit of a small company

About the company

Purpose – Why we exist
We are here to build and sustain trust in a digital society
We are here to build and sustain trust in a digital society — trust that is threatened by uncertainty, fear and worry caused by cyber attacks and crime.

Vision – Where we are heading
No one should experience a serious loss because of a cyber attack
We envision a future where no one should experience a serious loss or be put out of business because of cyber attack or crime. At least no one who puts their trust in us.

Mission – What we do
Accelerate transition to outcome-based security
Our mission is to research, innovate and build technologies, human expertise and delivery-business models that will accelerate our customers’ and partners’ transition to outcome-based security.

Diversity & Inclusion:

WithSecure is an equal opportunity employer and believe that employing a diverse workforce is central to our success. We are committed to ensuring all qualified applicants will receive consideration for employment without regard to nationality, colour, race, ethnic or national origin, sex, gender (including gender reassignment), sexual orientation, religion or belief, age, marital status or physical or mental disability.
We will do everything we can to support you during your application. If you need us to make any adjustments to our recruitment process, speak to our recruitment team who will be happy to support you!

Ari Lappalainen | Contact Person

I'm interested
WithSecure

Helsinki
Visit website