About the Team & Your Impact
Our team is distributed across Germany and Poland, with the Polish hub steadily growing. We are a diverse mix of experts—from CTI analysts to tech-dedicated specialists and versatile "one-man armies". We leverage various sources of intelligence, including OSINT and other specialized feeds, and we are currently in an exciting phase of onboarding more AI solutions into our daily operations.
What makes this role stand out?
- Intelligence into Action: You won't just write reports. Your core focus is bringing threat intelligence into real, defensive actions. You will have a direct hand in developing tools, automating workflows, and directly contributing to the safety of our entire global organization.
- Meaningful Business Impact: Your work has a tangible, visible impact. By delivering precise intelligence, you help ensure a safe digital environment for Bosch colleagues worldwide, allowing you and them to thrive together.
- Structured, Non-Reactive Workflow: Unlike many highly exposed, purely reactive security roles, our work is regular, structured, and easy to manage within your standard working hours. This provides a sustainable environment where you can build deep expertise and take pride in the results.
Your main tasks will include:
- Monitoring the external landscape: Actively monitoring the global threat landscape using Open Source Intelligence (OSINT), commercial threat feeds, Dark Web forums, and underground communities to identify emerging threat actors and trends.
- Tracking targeted threats: Hunting for indicators of compromise (IoCs), leaked credentials, exposed infrastructure, or brand impersonation campaigns specifically targeting our organization, supply chain, or industry.
- Preparing proactive defenses: Translating external threat data into actionable defense strategies by working closely with our SOC and engineering teams to update firewall rules, prioritize vulnerability patching, and fine-tune detection mechanisms before an attack occurs.
- Profiling adversaries: Analyzing and mapping threat actor tactics, techniques, and procedures (TTPs) using frameworks like MITRE ATT&CK to understand who wants to target us and how.
- Delivering early warnings and reporting: Providing timely, high-fidelity threat briefings and alerts to both technical teams and executive leadership to drive informed, risk-based decisions.
- Developing and automating tools: Building and improving internal tools for threat analysis, collection, and monitoring (using Python, REST APIs, Git, Docker).