ZeroFox→
Intelligence Analyst at ZeroFox in Remote
Skills
Job Description
WHAT ZEROFOX WILL LOOK LIKE TO YOU
This role supports one of the world's most recognized consumer brands — a company with a global footprint, a high-profile executive population, and threat exposure that spans every timezone and threat landscape. You'll sit inside ZeroFox's Services and Analysis Team, producing intelligence that shapes real security decisions for a client whose brand is visible everywhere, all the time. This isn't background noise work. When something moves in a market or region your client operates in, you're the person connecting it to risk before it becomes an incident.
THE ROLE
You'll own the intelligence cycle for a strategic enterprise account — collecting, evaluating, and synthesizing information from open, deep, and dark web sources into products that actually help security and risk leaders act. That means daily and recurring deliverables: alerts, threat reports, trend assessments, and executive briefings. It also means being the analyst who picks up the phone when something breaks outside of business hours, because the adversary doesn't work a 9-to-5.
This isn't a passive monitoring role. You'll use ZeroFox's platform alongside your own research instincts to track threat actors, identify emerging patterns, and brief stakeholders who need clarity under pressure. You'll work alongside ZeroFox analysts and engage directly with your client's security team — which means your communication has to be as sharp as your analysis.
In your first 90 days, you'd be expected to get certified on ZeroFox's platform and methodology, take ownership of at least one recurring deliverable, and begin building the threat landscape context specific to your client's geography and risk profile.
THE REALITY
You'll thrive here if...
- You have genuine geopolitical instincts — you follow regional developments, understand how international dynamics translate to physical and reputational risk, and can map what's happening in the world to what it means for a specific organization.
- You've done real OSINT work — not just social media monitoring, but multi-source collection across surface, deep, and dark web environments — and you know how to turn raw findings into a coherent threat narrative.
- You've produced written intelligence products — reports, assessments, briefings — and can explain the BLUF model without Googling it.
- You speak a second language well enough to use it for research, not just to list it on a resume.
- Sitting with an incomplete investigation while you continue to develop it is normal to you — uncertainty is a phase, not a blocker.
This probably isn't for you if...
- You're looking for a well-defined alert queue to work through. This role requires you to drive your own research and draw your own conclusions with incomplete data.
- You prefer to hand off analysis to someone else for the "so what." Here, you write the assessment and brief the client on it.
- You need your client's environment explained to you every time. Brand-adjacent threat landscapes evolve fast, and staying current is your responsibility.
- You're uncomfortable briefing senior stakeholders or presenting findings when there's ambiguity in the data.
- The prospect of monitoring threats outside core business hours — occasionally and in support of actual incidents — isn't something you're willing to sign up for.