Skillhouse Internal Career Opportunity
Cyber Threat Intelligence (CTI) Lead
Position Title:
Cyber Threat Intelligence (CTI) Lead
Employment Type:
Permanent
Working Hours:
English Level - Advanced (TOEIC 860), Japanese Level - Advanced (JLPT Level 1)
Salary
Description
One of the world’s largest financial services companies is seeking a Cyber Threat Intelligence (CTI) Lead to lead the planning, analysis, and delivery of cyber threat intelligence that enables the organization to anticipate and respond effectively to the evolving cyber threat landscape.
In this role, you will analyze internal security telemetry, including logs and alerts, alongside external threat intelligence sources to identify significant threats, assess adversary behaviors, and evaluate potential business impact.
The purpose of this position is to enable the organization to make risk-based security decisions and respond to emerging threats rapidly and effectively.
Responsibilities:
- Serve as the Cyber Threat Intelligence (CTI) Lead for Japan
- Lead CTI activities across the company's Japan-based group companies, incorporating Japanese-language intelligence, region-specific threat actors, and regulatory considerations into analysis
- Enhance globally sourced threat intelligence by contextualizing it to the Japanese and regional environment
- Lead the collection and analysis of intelligence in local languages, including Japanese, and drive continuous tracking of Japan- and APAC-specific threat actors and campaigns
- Identify and clarify the cyber threat intelligence requirements of the CISO/Information Security Office (ISO) and business functions
- Deliver threat intelligence in a format that enables effective decision-making by stakeholders at all levels, from senior executives and business leaders to security and other technical teams
- Continuously incorporate feedback from intelligence consumers to improve relevance, communication, measurement of business impact, and overall intelligence quality
- Analyze a wide range of internal and external telemetry and intelligence sources to identify emerging threat indicators, adversary Tactics, Techniques, and Procedures (TTPs), and global and regional threat trends
- Produce high-quality intelligence reports that support strategic, operational, and tactical decision-making, clearly communicating risk assessments and recommended actions and translating intelligence into practical defensive measures
- Prioritizing and recommending improvements to detection rules
- Supporting hypothesis development for Threat Hunting activities
- Identifying gaps in existing security controls and opportunities to strengthen defenses
- Work closely with Threat Hunting, Detection Engineering, Incident Response, and Technology teams to plan and lead intelligence-driven defensive activities from strategy through execution
- Deliver clear and concise intelligence briefings to technical teams and senior leadership, ensuring key insights can be understood and acted upon quickly
- Establish and continuously enhance CTI processes and workflows to build a scalable, measurable, and business-relevant operating model
- Promote and utilize structured analytical frameworks such as MITRE ATT&CK and the Diamond Model, integrating insights from threat emulation, incident response, and other analytical activities
- Support defensive teams in prioritizing monitoring and response activities based on intelligence-driven assessments
- Build and maintain relationships with industry organizations such as FS-ISAC, security vendors, and regional intelligence communities to strengthen information-sharing capabilities
Required Skills:
- Cross-domain security telemetry analysis: Proven experience analyzing multiple security telemetry sources, including SIEM, XDR/EDR, network- and host-based detection systems, firewall logs, and system logs. Ability to go beyond event analysis to assess the intelligence significance of threats and translate findings into defensive priorities
- Strong understanding of SaaS and cloud environments: Deep knowledge of cloud platforms such as AWS, Azure, and GCP, as well as enterprise SaaS environments, including how adversaries exploit identities and authentication/authorization mechanisms, APIs, integrations, and misconfigurations
- Comprehensive understanding of the intelligence lifecycle: Strong understanding of intelligence requirements, collection, analysis, dissemination, and feedback. Practical experience applying structured analytical methodologies such as Analysis of Competing Hypotheses (ACH) and the Diamond Model, with the ability to produce evidence-based assessments and clearly communicate confidence levels
- Advanced knowledge and practical experience with MITRE frameworks, with the ability to apply them to actual defensive design and operations
- Cyber Resiliency Engineering Framework (CREF): Incorporating cyber resilience considerations into defensive strategies
- Priority Intelligence Requirements (PIR): Experience defining and managing PIRs based on stakeholder priorities and challenges, and continuously adjusting collection, analysis, and intelligence outputs in response to changes in the threat environment
- Agile / iterative working experience: Ability to prioritize intelligence activities, balance multiple competing requirements, and drive delivery of meaningful outcomes in a fast-paced environment
- Continuous learning and adaptability: Demonstrated ability to independently keep pace with changes in adversary behavior, emerging technologies, and attack techniques, and apply that knowledge to improve intelligence quality and strengthen defensive capabilities
- Strong collaboration and external engagement skills: Proven experience working with internal and external stakeholders, industry organizations, and external partners to increase the value and impact of cyber threat intelligence
Why should you apply:
- Apply your expertise in Cyber Threat Intelligence to influence security strategies across Japan and the global organization.
- Leverage MITRE ATT&CK and other intelligence frameworks to translate threat intelligence into practical, threat-informed defensive strategies.
- Work across Threat Analysis, Threat Hunting, Detection Engineering, and Incident Response to drive the continuous enhancement of the organization's defensive capabilities
Company Details:
Founded in 2008 and headquartered in the United States, the company is one of the world’s largest financial services institutions. As a global organization, it actively collaborates with international partners while providing IT infrastructure services to group companies across Japan.
Guided by the strong commitment of the Group to protect customers’ financial security and peace of mind, the company serves as a trusted partner supporting both technology and business. Its mission is to continue delivering stable, reliable, and trusted system infrastructure services.
Working Hours: 9:00 – 18:00
Work Style: Hybrid (1–2 days per week in the office; 0–2 weekend workdays per month)
Holidays: Saturdays, Sundays, public holidays, year-end and New Year holidays, paid leave, and special leave
Benefits: Full social insurance coverage, DC pension plan, transportation allowance, Skill House University, test payback system, and more



