# Threat Intelligence Specialist – EMEA

**Company:** [Kodex](https://hotfix.jobs/companies/kodex)
**Location:** Remote
**Role:** Security Engineering
**Experience:** 3+ years
**Skills:** Threat Intelligence, Identity Fraud Investigation, Osint, Passive Dns, Asn Attribution, Whois/Rdap, Certificate Transparency, Shodan, Censys, Virustotal, Mitre Att&Ck, Account Takeover, Digital Forensics, APIs
**Posted:** 2026-08-19

> The Threat Intelligence Specialist investigates identity fraud and threat actors, conducts pivot-based OSINT, and collaborates with law enforcement agencies across EMEA. The role requires at least three years of relevant analytical experience, strong communication skills, and the ability to work autonomously across time zones.

## Job Description

## Responsibilities
- Analyze data and information to identify confirmed relationships.
- Research and document threat actor tactics, including fake law enforcement personas and agencies, compromised legitimate agent accounts and credentials, and abuse of trusted access for fraud.
- Communicate with international government agencies across time zones by phone and email.
- Establish and maintain relationships with law enforcement agencies and personnel worldwide.
- Foster cross-departmental engagement and streamline workflows.
- Respond promptly and efficiently to user needs.
- Monitor industry and market trends.

## Requirements
- At least **3 years of hands-on experience** in threat intelligence, identity fraud investigation, or a related analytical discipline.
- Proficiency in pivot-based OSINT, including passive DNS, ASN attribution, WHOIS/RDAP, certificate transparency, and email infrastructure analysis.
- Fluency in English.
- Excellent verbal and written communication skills.
- Ability to work across multiple time zones.
- Self-directed and able to work autonomously.
- Strong interpersonal skills for engaging with varied management levels.

## Nice-to-haves
- Experience with account takeover, synthetic identity fraud, data theft/extortion, spearphishing, targeted intrusions, underground cybercrime ecosystems, and organizational impersonation.
- Expertise in network- and host-based security controls and in designing, using, and training others on proprietary and open-source tools such as Shodan, Censys, VirusTotal, and APIs.
- Operational experience with the MITRE ATT&CK framework.
- Law enforcement experience in cyber investigation, financial crimes, or digital forensics, or experience with subpoenas, EDRs, and court orders.
- FinTech, crypto, or identity verification experience where identity fraud is the primary threat vector.
- Fluency in Czech, French, and/or Arabic.

## Compensation and Benefits
- Competitive salary and meaningful equity.
- Occupational pension scheme with employer contributions.
- Statutory paid annual leave and public holidays.
- Annual offsites in various locations.
- Remote-first work within Ireland, with Dublin-based work preferred.
- Opportunities for professional growth and global impact.

## Similar jobs

- [Intermediate Security Engineer, Security Incident Response Team](https://hotfix.jobs/jobs/049f08fd-cd02-4592-90ca-58c56477f889) - GitLab - Remote
- [Abuse Investigator](https://hotfix.jobs/jobs/067a3725-8094-47e5-a3a6-ac821e7253c6) - Stripe - Dublin, Ireland
- [Abuse Investigator](https://hotfix.jobs/jobs/ba670c7e-d48c-495b-8f3e-648393a93ed7) - Stripe - Seattle, WA
- [Platform Security Engineer](https://hotfix.jobs/jobs/e556dd76-0f95-4dfa-9d3d-e476f24057c0) - Supabase - Remote
- [Security Engineer, Incident Response](https://hotfix.jobs/jobs/83eb71b2-95d7-4319-85af-294442d49213) - Twilio - Remote

**Apply:** https://hotfix.jobs/jobs/ba41592f-9f18-4e57-a7c7-144744386565
**Canonical:** https://hotfix.jobs/jobs/ba41592f-9f18-4e57-a7c7-144744386565