Principal Cyber Threat Intelligence
Barcelona, Spain·Competitive·Remote·Lead · 10+ years·English: Required
Need a visa?No sponsorship mentioned, and this kind of work is rarely sponsored in Spain. See which routes exist.
What you'll do
- Conduct intelligence collection, research, and analysis to identify emerging threats, adversary activity, vulnerabilities, and trends relevant to the organization.
- Produce finished intelligence reports and briefings based on independent research and in response to requests for information that clearly communicate cyber threats, business impact, and recommended actions.
- Lead targeted threat research projects synthesizing information from internal incident data and security telemetry to generate actionable insights that enable security teams, product owners, and business leaders to take effective risk reduction actions.
- Partner with cyber defense, vulnerability management, and engineering teams to integrate intelligence into threat hunting, detection engineering, security operations, and exposure reduction initiatives.
- Drive the development of AI-enabled and automated intelligence workflows that improve threat identification, analysis, reporting, prioritization, and escalation processes.
- Use Large Language Model (LLM) and Agentic AI tools to process and analyze data for quicker intelligence outcomes.
- Build strong relationships with security and business stakeholders to ensure intelligence and research activities align with organizational priorities, risk management objectives, and operational needs.
- Collaborate with industry peers, government partners, and trusted intelligence-sharing communities to enhance situational awareness, expand collection capabilities, and improve organizational resilience.
- Serve a diverse set of stakeholders ranging from executive leadership and business partners to security practitioners, tailoring intelligence products and recommendations to support strategic, operational, and tactical decision-making.
What we're looking for
- A minimum of a bachelor's degree or equivalent related experience is required.
- A minimum of 10 years of professional experience is required.
- Excellent threat intelligence writing and briefing skills are required.
- A solid grasp of the current threat landscape including the latest tactics, techniques, and procedures is required.
- Significant experience researching, acquiring, and implementing threat intelligence on nation state and criminal cyber threat actors is required.
- Strong knowledge of the intelligence lifecycle, intelligence analysis, and related methodologies is required.
- Experience with structured analysis techniques (e.g., Diamond Model, Cyber Kill Chain) as well as a proven understanding of the MITRE ATT&CK framework is required.
- Experience with the utilization of Open-Source Intelligence (OSINT) as well as closed intelligence sources (e.g., Google Threat Intel, Flashpoint, Silobreaker) is required.
- Experience analyzing internal incident data to perform enrichment (e.g. attribution) analysis and to identify trends that drive security improvements is required.
Nice to have
- A minimum of 7 years of cyber threat intelligence or threat research experience is preferred.
- Experience utilizing LLM and Agentic AI tools to facilitate intelligence analysis projects as well as time spent working with automation or data science teams to craft intel driven workflows is preferred.
- Experience analyzing raw data points from technical security controls, to include web proxy, firewalls, IPS, IDS, enterprise antivirus solutions, etc. is preferred.
- Experience with security detection and response technology (SOAR & SIEM) and Threat Intelligence Platform (TIP) products is preferred.
- Knowledge of geopolitics and its intersection with the cyber threat landscape is preferred.
- Security certifications such as CISSP, SANS GSEC, GCTI, and GCFA or similar industry-recognized credentials are preferred.
- Experience working with virtual, global teams - including diverse groups of people with multifaceted backgrounds and cultural experience is preferred.
Business Process Design, Crisis Management, Critical Thinking, Information Security Auditing, Information Security Management System (ISMS), Information Technology (IT) Security Assessments, Information Technology Strategies, Mentorship, Organizing, Presentation Design, Process Optimization, Root Cause Analysis (RCA), Security Architecture Design, Security Policies, Technical Credibility, Vulnerability Management
What you'll get
zł205,000.00 - zł354,200.00
In addition to base pay, we offer the following benefits*: an annual bonus with set target (% of pay) depending on pay grade / location, where the actual amount is based on the employees' and companies' performance of the previous calendar year, or sales commissions. Moreover, we offer vacation days, parental leave for a minimum of 12 weeks, bereavement leave, caregiver leave, volunteer leave, well-being reimbursement, programs for financial, physical and mental health. We also offer service anniversary and recognition awards, and subject to the terms of their respective plans, employees - and in some location's eligible dependents - can participate in several insurance plans. For more information, visit Employee benefits | Supporting well-being & career growth | Johnson & Johnson Careers.
*This is for informative purposes only. Amounts and actual benefits may vary by location and are subject to change.
About the company & team
Technology Enterprise Strategy & Security
Security & Controls
Scientific/Technology
Barcelona, Spain, Limerick, Ireland, Warsaw, Masovian, Poland
About the company
Johnson & Johnson
Pharma