Skip to content
KodexKodex

Threat Intelligence Specialist – EMEA

The Threat Intelligence Specialist investigates identity fraud and threat actors, conducts pivot-based OSINT, and collaborates with law enforcement agencies across EMEA. The role requires at least three years of relevant analytical experience, strong communication skills, and the ability to work autonomously across time zones.

About the job

Responsibilities

  • Analyze data and information to identify confirmed relationships.
  • Research and document threat actor tactics, including fake law enforcement personas and agencies, compromised legitimate agent accounts and credentials, and abuse of trusted access for fraud.
  • Communicate with international government agencies across time zones by phone and email.
  • Establish and maintain relationships with law enforcement agencies and personnel worldwide.
  • Foster cross-departmental engagement and streamline workflows.
  • Respond promptly and efficiently to user needs.
  • Monitor industry and market trends.

Requirements

  • At least 3 years of hands-on experience in threat intelligence, identity fraud investigation, or a related analytical discipline.
  • Proficiency in pivot-based OSINT, including passive DNS, ASN attribution, WHOIS/RDAP, certificate transparency, and email infrastructure analysis.
  • Fluency in English.
  • Excellent verbal and written communication skills.
  • Ability to work across multiple time zones.
  • Self-directed and able to work autonomously.
  • Strong interpersonal skills for engaging with varied management levels.

Nice-to-haves

  • Experience with account takeover, synthetic identity fraud, data theft/extortion, spearphishing, targeted intrusions, underground cybercrime ecosystems, and organizational impersonation.
  • Expertise in network- and host-based security controls and in designing, using, and training others on proprietary and open-source tools such as Shodan, Censys, VirusTotal, and APIs.
  • Operational experience with the MITRE ATT&CK framework.
  • Law enforcement experience in cyber investigation, financial crimes, or digital forensics, or experience with subpoenas, EDRs, and court orders.
  • FinTech, crypto, or identity verification experience where identity fraud is the primary threat vector.
  • Fluency in Czech, French, and/or Arabic.

Compensation and Benefits

  • Competitive salary and meaningful equity.
  • Occupational pension scheme with employer contributions.
  • Statutory paid annual leave and public holidays.
  • Annual offsites in various locations.
  • Remote-first work within Ireland, with Dublin-based work preferred.
  • Opportunities for professional growth and global impact.

Skills

Threat Intelligence, Identity Fraud Investigation, Osint, Passive Dns, Asn Attribution, Whois/Rdap, Certificate Transparency, Shodan, Censys, Virustotal, Mitre Att&Ck, Account Takeover, Digital Forensics, APIs

GitLab

GitLab

Australia

Intermediate Security Engineer, Security Incident Response Team
No salary listedRemoteSecurity Engineering

This remote Security Incident Response Engineer detects, investigates, and resolves security incidents while improving automation, documentation, and detection capabilities. The role requires SIEM and cloud experience, Python skills or willingness to learn, and an interest in forensic investigations.

Stripe

Stripe

Dublin, Ireland

Abuse Investigator
No salary listedOn-site3+ YOESecurity Engineering

Investigates high-risk accounts and leads incident response for fraud and product-abuse events, using behavioral analysis and threat intelligence to identify root causes and improve detection. Requires 3+ years of incident response and fraud-data analysis experience, plus strong Python and SQL skills.

Stripe

Stripe

Seattle, WA
Abuse Investigator
No salary listedOn-site3+ YOESecurity Engineering

Investigates and leads response to high-risk fraud and product-abuse incidents, analyzes threat patterns, and drives root-cause and prevention improvements. Requires 3+ years of incident response and fraud-oriented data analysis, plus Python, SQL, and security investigation expertise.

Supabase

Supabase

Remote

Platform Security Engineer
No salary listedRemote5+ YOESecurity Engineering

Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.

Twilio

Twilio

United Kingdom
Security Engineer, Incident Response
No salary listedRemote3+ YOESecurity Engineering

Leads technical response to security events across cloud infrastructure, services, and applications, covering triage, containment, remediation, automation, and post-incident improvements. Requires 3+ years of cloud security incident response experience and expertise with SIEM, SOAR, and major cloud platforms.