Headquartered in Pleasanton, California, Veeva is a leading provider of cloud-based software and services for the life sciences industry. As an employer, Veeva has wanted experienc
Cyber Threat Intelligence Analyst
Location
Worldwide
Posted
65 days ago
Salary
$75K - $125K / year
Seniority
Senior
Job Description
Cyber Threat Intelligence Analyst
Veeva
Title: Cyber Threat Intelligence Analyst Location: United States Job Description: Veeva Systems is a mission-driven organization and pioneer in industry cloud, helping life sciences companies bring therapies to patients faster. As one of the fastest-growing SaaS companies in history, we surpassed $3B in revenue in our last fiscal year with extensive growth potential ahead. At the heart of Veeva are our values: Do the Right Thing, Customer Success, Employee Success, and Speed. We're not just any public company – we made history in 2021 by becoming a public benefit corporation (PBC), legally bound to balancing the interests of customers, employees, society, and investors. As a Work Anywhere company, we support your flexibility to work from home or in the office, so you can thrive in your ideal environment. Join us in transforming the life sciences industry, committed to making a positive impact on its customers, employees, and communities. The Role This position is responsible for discovering, analyzing, and vetting relevant cyber threat information to produce detection and defensive mechanisms for the SOC. Additionally, the CTI Analyst will author reports to Senior Leadership and other stakeholders to maintain excellent company situational awareness of emerging threats relevant to Veeva. The analyst will also evaluate internal behavioral telemetry and potential risk indicators to identify and mitigate insider threats, ensuring a comprehensive view of the organization's risk profile. A repository of IOCs will be maintained to correlate attack patterns to further predict and defend against adversary personas. Finally, the CTI analyst will aid in the preparation and execution of proactive defense measures. What You'll Do - Leverage a Collection Management Framework (CMF) that organizes all threat intelligence feeds, both internal and external, by indicators and data that can be ascertained as well as the methods in how data is collected - Report on potential areas of compromise and areas of concern through information provided by threat intelligence sources - Apply the indicator lifecycle (revealed, matured, utilized) to validate incoming indicators and determine relevance to Veeva - Detect patterns of ongoing intrusion and intrusion attempts across Veeva and the industry to predict future IOCs and suggest implementations - Utilize CTI tools to detect/report on trends to drive decisions influencing defensive operations - Report actionable metrics related to adversarial behavior to drive prioritized defensive actions - Support incident responders with relevant IOCs and historical data during ongoing investigations - Author intelligence reports that address intelligence requirements and RFIs from across the company - Support engineers in the preparation, design, and execution of threat hunt missions - Research and analyze adversarial threat behaviors to prepare for emulation exercises to assess controls - Apply threat intelligence methodologies to internal log data and User and Entity Behavior Analytics (UEBA) to detect anomalies indicative of insider compromise or collusion Requirements - Good understanding of the Kill Chain and Diamond models, and means to merge them - Ability to leverage MITRE ATT&CK in support of CTI reporting - Good familiarity with some OSINT and proprietary CTI tools, examples as: DomainTools, MISP, YARA, ISAC/ISAO feeds, CyberChef, DataSploit, FireHOL, Maltego, Shodan, ThreatQuotient, Recorded Future Anomali, etc. - Good familiarity with modern threats, top delivery vectors, and methods of exploitation - Experience in organizing, processing, analyzing, and vetting indicators using sorting/processing tools to maintain a current, relevant threat database - Experience in leveraging existing threat intelligence to augment investigations during incident response - 1+ years of experience in a cyber threat intelligence-related field, or 3+ years of experience in a cybersecurity operations field - Experience analyzing behavioral telemetry and system logs (e.g., SIEM, EDR, UEBA) to identify technical indicators of insider risk - Strong familiarity with different levels of CTI products (Strategic, Operational, Tactical/Technical) - Good understanding of the different phases of the CTI lifecycle (Planning, Collection, Analysis, Production, and dissemination/feedback) Nice to Have - Threat Intelligence or Intrusion Detection-related certification, such as GCTI, GOSI, CTIA, GCDA, GCIA, CCTIA, CTIP, CPTIA, CRTIA, etc. - Experience in enriching data of the four atomic indicators (domains, strings, IP addresses, accounts) to deliver additional context to incident responders - Solid background in cloud security principles - Experience in creating and maintaining a prioritized list of critical assets and understanding the top threats against them - Experience with threat hunting development - Experience in threat emulation or use of deceptive technologies Perks & Benefits - Medical, dental, vision, and basic life insurance - Flexible PTO and company paid holidays - Retirement programs - 1% charitable giving program Compensation - Base pay: $75,000 - $125,000 - The salary range listed here has been provided to comply with local regulations and represents a potential base salary range for this role. Please note that actual salaries may vary within the range above or below, depending on experience and location. We look at compensation for each individual and base our offer on your unique qualifications, experience, and expected contributions. This position may also be eligible for other types of compensation in addition to base salary, such as variable bonus and/or stock bonus. #LI-RemoteUS #LI-Associate Veeva’s headquarters is located in the San Francisco Bay Area with offices in more than 15 countries around the world. Veeva is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, sex, sexual orientation, gender identity or expression, religion, national origin or ancestry, age, disability, marital status, pregnancy, protected veteran status, protected genetic information, political affiliation, or any other characteristics protected by local laws, regulations, or ordinances
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
Analista de Segurança da Informação III – Resposta a Incidentes
Cooperativa Central AilosSeu talento em expansão.
• Experiência sólida em Resposta a Incidentes, SOC/CSIRT ou funções correlatas, com atuação em incidentes de média/alta criticidade. • Domínio do ciclo de IR (preparação, detecção/análise, contenção, erradicação, recuperação e pós-incidente), com foco em execução consistente e auditável. • Vivência com SIEM e EDR/XDR, análise de logs/eventos, investigação de alertas e correlação de evidências. • Conhecimento aprofundado de Windows, Linux e macOS, incluindo análise de artefatos relevantes para IR. • Sólidos fundamentos de redes e protocolos, arquitetura de segurança e análise de comunicações suspeitas. • Conhecimento e aplicação de frameworks/padrões (ex.: MITRE ATT&CK, NIST SP 800-61, SANS IR). • Experiência em investigações em ambientes cloud (ex.: IAM, trilhas de auditoria, logs nativos, postura e respostas). • Automação e scripting (Python/PowerShell/Bash) para acelerar coleta, triagem e análise. • Experiência com integração e uso de threat intelligence (feeds, IOCs, enriquecimento e priorização).
Sr Analyst, Governance, Risk & Compliance (GRC), Information Security
Mondelēz InternationalWe’re a house of incredible brands providing people with the right snack, for the right moment, made the right way.
Job Description Are You Ready to Make It Happen at Mondelēz International? Join our Mission to Lead the Future of Snacking. Make It Uniquely Yours. As an individual contributor, the successful candidate will be proficient at managing risk assessments of both third parties and internal technologies. In addition, the candidate will be performing compliance activities related to technology assurance areas around access management, vulnerability management and configuration management. Candidate will also demonstrate ability and experience in governance related activities including administrative management of risk and control registers as well as policies and standards. How you will contribute Risk Management Responsibilities - Execute risk assessment testing supporting the Risk Manager. - Document risk assessment results. - Support Risk Manager in drafting risk assessment reports. - Perform administrative management of risk register (additions/editions/deletions, etc). - Document risk acceptance/exemptions that have been approved per the program. - Manage quarterly/annual review of risk acceptance/exceptions. - Manage risk assessment results in relevant dashboards. - Document Issues and Remediation activities for all exceptions noted during risk assessments. Compliance Responsibilities - Perform quarterly compliance assurance testing. - Document compliance testing results. - Maintain Management Action Plan (MAP) catalog with due dates. - Manage monthly audit MAPs. Includes the timely communication of open MAPs an escalation as needed of risks to completing MAPs at their agreed delivery dates. - Perform administrative activities in GRC Solution for compliance related activities. - Provide administrative support for ad-hoc external audits. - Provide administrative support for internal audits. - Support compliance program reporting activities. Requirements - 3 years in Information Security field, with at least 2 years working in GRC. - Experience with GRC tools (e.g., Archer). - Knowledge of security concepts and methodologies such as risk assessments, risk & controls, policies & standards, enterprise security strategies, network, and cloud security. - Knowledge of security frameworks such as CIS and NIST. - Excellent written and verbal communications skills, including presentational skills and able to clearly communicate issues to management and other key stakeholders. No Relocation support available Business Unit Summary At Mondelēz International, our purpose is to empower people to snack right by offering the right snack, for the right moment, made the right way. That means delivering a broad range of delicious, high-quality snacks that nourish life's moments, made with sustainable ingredients and packaging that consumers can feel good about. We have a rich portfolio of strong brands globally and locally including many household names such as Oreo, belVita and LU biscuits; Cadbury Dairy Milk, Milka and Toblerone chocolate; Sour Patch Kids candy and Trident gum. We are proud to hold the top position globally in biscuits, chocolate and candy and the second top position in gum. Our 80,000 makers and bakers are located in more than 80 countries and we sell our products in over 150 countries around the world. Our people are energized for growth and critical to us living our purpose and values. We are a diverse community that can make things happen-and happen fast. Mondelēz International is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, gender, sexual orientation or preference, gender identity, national origin, disability status, protected veteran status, or any other characteristic protected by law. Job Type Regular Information Security Technology & Digital
Security Analyst
World Food ProgrammeThe World Food Programme is the world’s largest humanitarian organization saving lives in emergencies and using food assistance to build a pathway to peace, stability, and prosperity for people recovering from conflict, disasters, and the impact of climate change. At WFP, people are at the heart of everything we do and the vision of the future WFP workforce is one of diverse, committed, skilled, and high performing teams, selected on merit, operating in a healthy and inclusive work environment, living WFP's values (Integrity, Collaboration, Commitment, Humanity, and Inclusion) and working with partners to save and change the lives of those WFP serves. To learn more about WFP, visit our website: wfp.org and follow us on social media to keep up with our latest news: YouTube, LinkedIn, Instagram, Facebook, Twitter, TikTok.
DEADLINE FOR APPLICATIONS 29 May 2026-23:59-GMT+01:00 Central European Time (Rome) WFP celebrates and embraces diversity. It is committed to the principle of equal employment opportunity for all its employees and encourages qualified candidates to apply irrespective of race, colour, national origin, ethnic or social background, genetic information, gender, gender identity and/or expression, sexual orientation, religion or belief, HIV status or disability. ABOUT WFP The World Food Programme is the world’s largest humanitarian organization saving lives in emergencies and using food assistance to build a pathway to peace, stability and prosperity, for people recovering from conflict, disasters and the impact of climate change. At WFP, people are at the heart of everything we do and the vision of the future WFP workforce is one of diverse, committed, skilled, and high performing teams, selected on merit, operating in a healthy and inclusive work environment, living WFP's values (Integrity, Collaboration, Commitment, Humanity, and Inclusion) and working with partners to save and change the lives of those WFP serves. To learn more about WFP, visit our website: https://www.wfp.org and follow us on social media to keep up with our latest news: YouTube, LinkedIn, Instagram, Facebook, Twitter, TikTok. WHY JOIN WFP? - WFP is a 2020 Nobel Peace Prize Laureate. - WFP offers a highly inclusive, diverse, and multicultural working environment. - WFP invests in the personal & professional development of its employees through a range of training, accreditation, coaching, mentorship, and other programs as well as through internal mobility opportunities. - A career path in WFP provides an exciting opportunity to work across the various country, regional and global offices around the world, and with passionate colleagues who work tirelessly to ensure that effective humanitarian assistance reaches millions of people across the globe. - We offer an attractive compensation package (please refer to the Terms and Conditions section of this vacancy announcement). JOB TITLE: Security Analyst TYPE OF CONTRACT: Consultant (Regular) UNIT/DIVISION: SEC/Security Analysis DUTY STATION (City, Country): Paris - working remotely BACKGROUND AND PURPOSE OF THE ASSIGNMENT: Under the supervision of the Head of the Security Analysis, the Consultant conducts analysis and supports security information management by providing information products, based on the assessment of the security situation and its impact on WFP operations, staff and assets. The Consultant contributes to the WFP Security capacity to acquire, process and effectively communicate security threat information, supporting decision-making and ensuring increased visibility of the WFP Security function through adequate reflection of security-related information in corporate products. ACCOUNTABILITIES/RESPONSIBILITIES: - Provide security analysis, assessing implications for WFP personnel, assets and operations to support decisions on security risk management which enable WFP programme delivery, implementation of WFP access strategy, enhanced conflict-sensitive, gender-sensitive programming and protection-related efforts. - Contribute to the management of information relevant to security, including acquisition, examination, collation, analysis and dissemination, exercising good understanding of business requirements and supporting planning and decision-making at the operational level. - Conduct research on security threats and risks, identifying appropriate sources and validating acquired information to ensure its relevance, reliability and accuracy that contributes to comprehensive security analysis. - Prepare security updates, security analysis reports, statistics-and trend analysis; support other security reports with relevant information. - Monitor security incidents, daily and weekly situation reports, local media and other open sources to support security analysis, ensuring that it is based on a wide range of reliable sources. - Address security information requirement by applying agreed approaches and methodologies in security analysis consistent with WFP and wider United Nations security information management policies, guidelines and procedures. - Contribute to research on specific threat factors to support activities of the Crisis Management Team, contributing to the effective response to specific security incidents. - Provide inputs for presentations and briefings to WFP personnel, donors and partners on security developments in specific countries/regions, as appropriate. - Participate in field missions within area of responsibility to know WFP programmes and gather first-hand information on security situation for comprehensive security analysis and developing source networks. - Contribute to the development of security information management guidelines and procedures to improve security reporting and analysis. - Create and provide training for field-based personnel on reporting and analysis. - Maintain effective mechanisms on security information exchanges within area of responsibility. - Maintain collaboration within and outside WFP for effective information sharing on security situation, threat and risk assessments, to comprehensive security analysis and cross functional interaction. - Take part in activities and events within the WFP security analysis function, contributing to its cohesion and enhanced interaction between WFP security analysts. - Provide support in operational security matters. - Perform other duties as required. DELIVERABLES AT THE END OF THE CONTRACT: Full completion of all tasks assigned within the contract period. QUALIFICATIONS & EXPERIENCE REQUIRED: Knowledge & Skills: - Knowledge and understanding of methodologies for information collection, collation and analysis. - Excellent analytical and English drafting skills. - Proven ability to conduct research projects and perform studies on security and political matters. ' - Proven ability to produce analytical reports on security and political issues, preferably in the international perspective. - Proven ability to communicate complex concept orally and in writing. - Ability to appreciate sources, resources and information in terms of relevance and credibility. - Ability to identify priority activities and assignments, effectively manage workload. - Ability to work under strict deadlines. - Ability to manage several tasks simultaneously. Languages: - Fluency in written and spoken English. Intermediate knowledge of al) other official UN language (Arabic, Spanish, French, Russian, Chinese or Portuguese) is essential. WFP LEADERSHIP FRAMEWORK WFP Leadership Framework guides to the common standards of behavior that guide HOW we work together to accomplish our mission. Click here to access WFP Leadership Framework REASONABLE ACCOMMODATION WFP is committed to supporting individuals with disabilities by providing reasonable accommodations throughout the recruitment process. If you require a reasonable accommodation, please contact: global.inclusion@wfp.org NO FEE DISCLAIMER The United Nations does not charge any application, processing, training, interviewing, testing or other fee in connection with the application or recruitment process. Should you receive a solicitation for the payment of a fee, please disregard it. Furthermore, please note that emblems, logos, names and addresses are easily copied and reproduced. Therefore, you are advised to apply particular care when submitting personal information on the web. REMINDERS BEFORE YOU SUBMIT YOUR APPLICATION - All applications must be submitted exclusively through our online recruiting system. We do not consider CVs or applications sent by email, LinkedIn, or any other channel. - We strongly recommend that your Workday profile is accurate and complete, and that all sections are filled in, including your employment history, academic qualifications, language skills, and UN grade (if applicable). Once your profile is completed, please apply, and submit your application. - If you experience technical issues while submitting your application, you may contact us at global.hrerecruitment@wfp.org. Please note that this email is only for technical issues with an application - unsolicited applications or documents sent to this inbox will not receive a reply. - At the application stage, the only required documents are your CV and Cover Letter. Additional documents (passport, certificates, recommendation letters, etc.) may be requested later in the process. - Only shortlisted candidates will be contacted and invited to proceed to the next stage of the recruitment process. All employment decisions are made on the basis of organizational needs, job requirements, merit, and individual qualifications. WFP is committed to providing an inclusive work environment free of sexual exploitation and abuse, all forms of discrimination, any kind of harassment, sexual harassment, and abuse of authority. Therefore, all selected candidates will undergo rigorous reference and background checks. No appointment under any kind of contract will be offered to members of the UN Advisory Committee on Administrative and Budgetary Questions (ACABQ), International Civil Service Commission (ICSC), FAO Finance Committee, WFP External Auditor, WFP Audit Committee, Joint Inspection Unit (JIU) and other similar bodies within the United Nations system with oversight responsibilities over WFP, both during their service and within three years of ceasing that service.
Sr Analyst, Governance, Risk & Compliance (GRC), Information Security
Mondelēz InternationalWe’re a house of incredible brands providing people with the right snack, for the right moment, made the right way.
Job Description Are You Ready to Make It Happen at Mondelēz International? Join our Mission to Lead the Future of Snacking. Make It Uniquely Yours. As an individual contributor, the successful candidate will be proficient at managing risk assessments of both third parties and internal technologies. In addition, the candidate will be performing compliance activities related to technology assurance areas around access management, vulnerability management and configuration management. Candidate will also demonstrate ability and experience in governance related activities including administrative management of risk and control registers as well as policies and standards. How you will contribute Risk Management Responsibilities - Execute risk assessment testing supporting the Risk Manager. - Document risk assessment results. - Support Risk Manager in drafting risk assessment reports. - Perform administrative management of risk register (additions/editions/deletions, etc). - Document risk acceptance/exemptions that have been approved per the program. - Manage quarterly/annual review of risk acceptance/exceptions. - Manage risk assessment results in relevant dashboards. - Document Issues and Remediation activities for all exceptions noted during risk assessments. Compliance Responsibilities - Perform quarterly compliance assurance testing. - Document compliance testing results. - Maintain Management Action Plan (MAP) catalog with due dates. - Manage monthly audit MAPs. Includes the timely communication of open MAPs an escalation as needed of risks to completing MAPs at their agreed delivery dates. - Perform administrative activities in GRC Solution for compliance related activities. - Provide administrative support for ad-hoc external audits. - Provide administrative support for internal audits. - Support compliance program reporting activities. Requirements - 3 years in Information Security field, with at least 2 years working in GRC. - Experience with GRC tools (e.g., Archer). - Knowledge of security concepts and methodologies such as risk assessments, risk & controls, policies & standards, enterprise security strategies, network, and cloud security. - Knowledge of security frameworks such as CIS and NIST. - Excellent written and verbal communications skills, including presentational skills and able to clearly communicate issues to management and other key stakeholders. No Relocation support available Business Unit Summary At Mondelēz International, our purpose is to empower people to snack right by offering the right snack, for the right moment, made the right way. That means delivering a broad range of delicious, high-quality snacks that nourish life's moments, made with sustainable ingredients and packaging that consumers can feel good about. We have a rich portfolio of strong brands globally and locally including many household names such as Oreo, belVita and LU biscuits; Cadbury Dairy Milk, Milka and Toblerone chocolate; Sour Patch Kids candy and Trident gum. We are proud to hold the top position globally in biscuits, chocolate and candy and the second top position in gum. Our 80,000 makers and bakers are located in more than 80 countries and we sell our products in over 150 countries around the world. Our people are energized for growth and critical to us living our purpose and values. We are a diverse community that can make things happen—and happen fast. Mondelēz International is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, gender, sexual orientation or preference, gender identity, national origin, disability status, protected veteran status, or any other characteristic protected by law. Job Type Regular Information Security Technology & Digital


